appsec.fyi

Remote Code Execution (RCE) Resources

Post Share

A curated AppSec resource library covering XSS, SQLi, SSRF, IDOR, RCE, XXE, OSINT, and more.

Remote Code Execution (RCE)

Remote Code Execution (RCE) is the ability for an attacker to execute arbitrary commands or code on a target machine or process. RCE vulnerabilities represent the most critical class of security bugs — they give an attacker the same level of control as a system administrator.

RCE can manifest through many different attack vectors. Command injection occurs when user input is passed unsanitized to system shell commands. Deserialization attacks exploit unsafe object reconstruction in languages like Java, PHP, Python, and .NET. Server-Side Template Injection (SSTI) allows code execution through template engines like Jinja2, Twig, or Freemarker. File upload vulnerabilities can lead to RCE when executable files bypass upload filters and are served by the web server.

In modern applications, RCE often appears in less obvious places: expression language injection in Java frameworks, prototype pollution leading to code execution in Node.js, unsafe use of eval() or dynamic code loading, and vulnerabilities in PDF generators, image processors, and other libraries that shell out to system commands.

RCE bugs consistently command the highest payouts in bug bounty programs because the impact is total system compromise. Chaining lower-severity bugs into RCE — such as SSRF to cloud metadata to code execution — is a common and highly rewarded approach.

This page collects RCE techniques, exploitation writeups, and research across all major platforms and languages.

From Wikipedia

Remote code execution is usually the end of a chain, not a bug you find

Direct, unauthenticated command injection on a modern target is rare enough to be newsworthy. What produces most real RCE is composition: a file upload that permits an unexpected extension, plus a directory the web server will execute from. A template field intended for personalization, in an engine that exposes object attributes. A deserialization endpoint, plus a library on the classpath with a usable gadget. An SSRF into an internal service that has an administrative API. The individual pieces are often rated low on their own, which is precisely why they survive to be chained.

That shapes how the material here is best read. Grouping it by language or by product is less useful than grouping it by primitive, because the primitive is what transfers. Command concatenation, unsafe deserialization, template injection, expression-language evaluation, unrestricted upload, path traversal into a writable executable location, prototype pollution reaching a sink, and memory-safety bugs in native components each recur across ecosystems with the same structure and different syntax.

Deserialization deserves particular emphasis because its severity is structural. In Java, .NET, PHP, Python and Ruby, reconstructing an object can invoke code during reconstruction; the attacker does not need to find a vulnerable function, only a chain of ordinary classes that together do something useful. The consequence is that the fix is architectural — do not deserialize untrusted data, and if you must, use a format that does not carry type information and an explicit allowlist. Blocklisting gadget classes has failed repeatedly and will continue to.

On impact and process: RCE reports pay the most and are also where responsible testing matters most, because proving execution and doing damage are separated by a very short distance. The good writeups below are careful about that boundary — a benign callback or a controlled identifier command establishes the finding without touching data. Read them for methodology as much as for technique.

Start here: the RCE learning pathAn ordered route through this library — orientation, then methodology, then research. Read the RCE guideA long-form, source-cited deep dive synthesized from every resource below. The comprehensive RCE guide on chs.usA hand-written, in-depth practitioner guide — attacks, testing, and prevention.
Date Added Link Excerpt
2026-10-10 NEW 2026A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline intermediateThis post details a vulnerability discovered in Discourse's image processing pipeline. The bug involves a race condition and a bypass of security checks, allowing an attacker to upload and execute arbitrary code by manipulating specially crafted JPEG files. The vulnerability could lead to remote code execution on the Discourse server. → slcyber.io
2026-10-10 NEW 2026MXC - a sandboxed code execution system beginnerMXC is a sandboxed code execution system. It allows for the safe execution of potentially untrusted code in an isolated environment. This isolation is crucial for preventing malicious code from impacting the host system or other processes. MXC's design aims to provide a secure platform for running code that might otherwise pose a security risk.
2026-10-10 NEW 2026Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) advancedWatchTowr identified a critical pre-authentication Remote Code Execution (RCE) vulnerability chain in PaperCut. This chain exploited multiple vulnerabilities (WT-2026-0141-0144, CVE-2026-82077, CVE-2026-82078, CVE-2026-81578) that allowed attackers to execute code without any prior authentication. The complexity arises from PaperCut assigning single CVE IDs to bundled vulnerabilities and subsequent patch bypasses for those same vulnerabilities. No specific bounty payout amount was mentioned in the provided text. → labs.watchtowr.com
2026-10-09 NEW 2026How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483) news 8 min read Bug BountyWriteup detailing CVE-2026-47483, a high-severity vulnerability in NVIDIA DCGM Exporter that enables unauthenticated attackers to cause denial of service and information disclosure by triggering uncontrolled resource consumption. Researchers discovered over 2,000 exposed GPU servers online, revealing significant NVIDIA hardware like Blackwell, H100s, and consumer RTX cards, often hosted by neocloud providers. NVIDIA released a security bulletin for CVE-2026-47483, which has a CVSS score of 8.2.
2026-10-09 NEW 2026A Single POST Freezes Any Next.js Server news 4 min read Bug BountyWriteup of CVE-2026-23870 detailing a Denial of Service vulnerability in React Server Components. This vulnerability, found in React versions prior to 19.0.6, 19.1.7, and 19.2.6, allows an attacker to freeze a Next.js server by crafting a single POST request with numerous nested form data pointers. The issue stems from React's inefficient parsing of nested form data, causing excessive CPU usage and making the server unresponsive to legitimate requests. The fix involves optimizing the form data parsing to scan fields only once per request, preventing the exponential complexity.
2026-10-08 NEW 2026CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE advanced 3 min read AuthNWriteup of CVE-2026-102489 detailing a session hijack vulnerability in Zammad. This vulnerability, when triggered by a crafted WebSocket request, leaks session cookies from error messages, allowing attackers to obtain valid admin session cookies. These cookies can then be used to write arbitrary files to the application directory, specifically by overwriting the password reset email template, leading to remote code execution as the `zammad` user through Ruby's ERB rendering.
2026-10-07 NEW 2026You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) news 9 min read API SecWriteup on CVE-2026-21589, an arbitrary file read vulnerability affecting Atlassian Jira, Confluence, and Bitbucket. The vulnerability stems from the `atlassian-plugins-webresource*.jar` library, which mishandles path traversal attempts using double colons (`::`) as a substitute for slashes. This allows unauthenticated attackers to read arbitrary files on affected systems by exploiting the `Router.unescapeSlashes` and `ResourceFactory.createResourceWithRelativePath` functions. → labs.watchtowr.com
2026-10-06 NEW 2026Wordpress libheif RCE intermediateThis content describes a Remote Code Execution (RCE) vulnerability in WordPress related to the libheif library. The specific details and impact of the vulnerability are not provided, nor is any information regarding a bug bounty payout.
2026-10-06 NEW 2026Open Build Service, one year later: command execution through Mercurial argument injection intermediate 7 min readTool identifying CVE-2026-56004, a command execution vulnerability in Open Build Service's `obs_scm` service. The flaw arises from Mercurial argument injection when the `revision` parameter is improperly handled, allowing attackers to exploit Mercurial's `--config` option to execute arbitrary shell commands on the build server, posing a significant risk to software supply chains.
2026-10-04 NEW 2026RCE and bad crypto in Internxt's 'post-quantum' cloud storage advanced 13 min readWriteup detailing critical vulnerabilities in Internxt's cloud storage, including remote code execution via protocol handlers and session/key leakage through unauthenticated public key sharing and insecure redirection. The analysis highlights architectural flaws in their cryptographic implementation, such as a flat key hierarchy and weak password hashing (MD5 with 3 iterations), rendering their "post-quantum" security claims unreliable and enabling potential data interception by Internxt or malicious third parties.
2026-10-03 NEW 20268 out of 10 Banks HATE This One Weird 3SKey RCE intermediate 8 min readLibrary for authentication with hardware signing tokens like 3SKeys, SConnect (v2.16.0.0), had a critical remote code execution vulnerability (CVE-2026-18397) due to a hand-rolled RSA-2048 token validation implementation. This flaw allowed any site or iframe to silently download and execute a DLL by exploiting an uninitialized memory validation bypass, enabling the loading of "plugins" and impacting systems used by banks and national authentication services.
2026-10-03 NEW 2026Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972) advanced 2 min readAdvisory for CVE-2026-71972 details an unbounded RLE8 splash image vulnerability in U-Boot. A crafted RLE8 BMP image, loaded from attacker-writable storage before boot stage authentication, can write past the framebuffer's bounds, corrupting adjacent memory and enabling secure boot bypass. Affected versions include U-Boot through 2026.10-rc5, with a fix available in commit 5201e83342d64c2f438ea35158575f28225e752e.
2026-10-02 2026How to Spot a Compromised MikroTik Router beginner 16 min readReference detailing techniques for detecting compromised MikroTik routers, focusing on identifying attacker configurations. It covers SSH port forwarding (`forwarding-enabled`), built-in SOCKS proxies (`/ip socks`), and the web proxy (`/ip proxy`), highlighting specific artifacts like `forwarding-enabled: local` and `redirect-to` rules. The document explains how these features, when improperly configured or exposed to the WAN, can facilitate pivoting and traffic manipulation, referencing historical abuse via CVE-2018-14847.
2026-10-02 2026Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files intermediate 10 min readWriteup on WordPress plugin vulnerabilities arising from overreliance on `.htaccess` files. When plugins installed on non-Apache servers, such as Nginx, ignore `.htaccess` directives, sensitive files like backup `.procstat` files in Everest Backup or database backup manifests in BackWPUp can be exposed to unauthenticated attackers. This research highlights security risks when plugin security relies solely on server-specific configurations.
2026-10-02 2026One Port to Root: Weaponizing Check Point Management CVE-2026-93616 advanced 13 min readTool for weaponizing Check Point Management CVE-2026-93616, an unauthenticated remote code execution vulnerability. The flaw allows an attacker to write arbitrary files as root via directory traversal and file upload on TCP 19009, leading to root code execution by planting a cron job. Bishop Fox validated the exploit chain against R81.10 and R82.10 servers and developed a detection tool to check patch state externally. → bishopfox.com
2026-10-01 2026How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail advanced 17 min read AuthZWriteup of CVE-2025-39964, a Linux AF_ALG privilege escalation vulnerability discovered by Muhammad Alifa Ramdhan. This vulnerability, found in the Linux kernel's cryptographic API, allows an ordinary user to gain root privileges and escape Docker containers. The article details the interaction with AF_ALG sockets, the `sendmsg()` system call, and the internal handling of user data via scatterlists, explaining the race condition in shared socket contexts that leads to out-of-bounds access.
2026-09-30 2026Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed news 10 min read AuthZWriteup detailing an unauthenticated to RCE exploit chain affecting HashiCorp Vault and OpenBao, combining vulnerabilities GHSA-j6wc-jpvg-xfxq, GHSA-x8fg-h69x-p28f, GHSA-mjch-vcw3-hhmf, and GHSA-fg5x-7whg-6c28. The exploit leverages ACME validation bypass and non-canonical URL access to escalate privileges, cross namespace boundaries, and ultimately achieve RCE via snapshot restore.
2026-09-30 2026Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) news 11 min readWriteup of CVE-2026-88772, a pre-authentication DTLS memory overflow in Citrix NetScaler. This vulnerability, exploited in the wild, allows an attacker to craft malicious DTLS records that cause an oversized data copy into a fixed-size buffer, leading to a crash or potential code execution. The analysis details the DTLS packet structure, NetScaler buffer handling, and the patch that introduces size checks before copying fragmented data, preventing the overflow. → labs.watchtowr.com
2026-09-30 2026Zilliz / Attu | 2.6.5 news 16 min read AuthZWriteup on Zilliz Attu 2.6.5 detailing two vulnerabilities: missing authentication in the Playground feature, allowing arbitrary HTTP/HTTPS request proxying to public URLs, and insecure input validation, enabling requests to private IP addresses normally blocked. Bishop Fox researchers demonstrated that these could be combined to gain administrative access to the Kubernetes namespace in cloud deployments. Updating to Attu version 3.0.0 is recommended. → bishopfox.com
2026-09-29 2026CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack newsCVE-2026-32740 is a critical Remote Code Execution (RCE) vulnerability impacting Next.js applications that utilize the `sharp` and `libheif` libraries, particularly when compiled as Position-Independent Executables (PIE). This flaw allows attackers to execute arbitrary code on vulnerable systems, posing a significant security risk. Further details on mitigation and patching are recommended. No specific bounty payout amount is mentioned in the provided content.
2026-09-29 2026RCE in OpenCode (GHSA-632h-h47v-g4x4) news 7 min readWriteup detailing GHSA-632h-h47v-g4x4, a remote code execution vulnerability in the OpenCode AI coding agent. The flaw stems from a content-type confusion in the `/global/upgrade` API endpoint, allowing exploitation via a malicious npm package tarball and a specially crafted webpage. This enables an attacker to achieve code injection by tricking OpenCode into installing a tarball containing malicious preinstall scripts, leading to arbitrary code execution on the victim's machine. OpenCode 1.18.22 addresses this vulnerability. → securitylabs.datadoghq.com
2026-09-29 2026Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) news 11 min readWriteup detailing the pre-authentication command injection vulnerability in Citrix NetScaler, identified as CVE-2026-88771. This analysis dissects the exploitation of improper input validation within the NetScaler ADC and Gateway appliances, highlighting its zero-day status and active exploitation in the wild. The writeup examines the specific code changes involving `grep`, `sed`, and `awk` within the `ns_monuploadd_err.pl` script that contributed to the vulnerability, offering a technical deep-dive into the flaw's root cause. → labs.watchtowr.com
2026-09-28 2026EDR Evasion: Process Injection Without WriteProcessMemory advanced 5 min readLibrary for EDR evasion techniques, demonstrating process injection without the traditional `WriteProcessMemory` or `VirtualAllocEx` APIs. This method leverages named pipes for console programs like `nslookup.exe` or `netsh.exe`, writing payloads directly into the target process's memory. Detection should shift focus from API calls to monitoring `VirtualProtectEx` usage and named pipe read/write operations. The associated GitHub repository, `InjectSetConsole`, provides the proof-of-concept code.
2026-09-28 2026How one Twitch chat message became code execution on a streamer’s PC intermediate 6 min readTool for exploiting OBS Browser Sources, this writeup details how a Twitch chat message can lead to code execution on a streamer's PC. The attack leverages an unsandboxed Chromium renderer within OBS, combined with CVE-2024-7971, a type confusion vulnerability in V8, to achieve arbitrary code execution on the host machine. The exploit chain begins with an XSS vulnerability in a chat overlay, which then utilizes the V8 bug to bypass OBS's disabled sandbox.
2026-09-26 2026Compromising OBS Studio with a Twitch chat message. intermediate 6 min readWriteup detailing how CVE-2024-7971, a V8 type confusion vulnerability, was exploited to achieve code execution on an OBS Studio streamer's PC via a single Twitch chat message. This attack leveraged an unsandboxed Chromium renderer within OBS's browser source, chaining a cross-site scripting (XSS) vulnerability in a Twitch chat overlay with the V8 exploit. The exploit achieved native code execution without requiring sandbox escape, directly compromising the streamer's machine.
2026-09-26 2026Master Key Included: Detecting SolarWinds ARM CVE-2026-28326 intermediate 11 min read DeserLibrary for detecting CVE-2026-28326, an unauthenticated RCE in SolarWinds Access Rights Manager. This vulnerability stems from a hardcoded, static client-authentication secret used with a .NET deserialization sink over gRPC on TCP 55555. The flaw allows attackers with network reach to port 55555 to execute code as NT AUTHORITY\SYSTEM. Patching to version 2026.2.1.7 or later is recommended, along with restricting access to TCP 55555. → bishopfox.com
2026-09-25 2026Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories. intermediate 14 min read AuthZLibrary documenting privilege escalation techniques within AWS CodePipeline and SageMaker Studio when using CodeConnections. The "Full clone" artifact format enables CodeBuild jobs to enumerate, clone, push, and delete repositories accessible by the CodeConnection, leveraging an undocumented CodeBuild endpoint. This bypasses intended security controls if IAM permissions are not strictly restricted, potentially allowing attackers to compromise source code providers.
2026-09-25 2026Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL advanced 10 min read MobileLibrary for exploiting two vulnerabilities in OnePlus devices, specifically the AtlasService's `setEvent` and the OLC2 HAL's `doShell`, allowing an untrusted app to achieve root privileges. The AtlasService vulnerability enables an app to set an audio debug property, leading to the execution of arbitrary commands as the `dumpstate` user via `/system_ext/bin/audioDumpInfo`. Subsequently, the `dumpstate` user can leverage the OLC2 HAL's `doShell` to execute commands as root within the `vendor_qti_init_shell` SELinux domain, which possesses all Linux capabilities.
2026-09-24 2026Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee intermediate 3 min read AITool for bypassing EDR using an uncensored AI model. This tool demonstrates how AI can be leveraged to create executables for sensitive operations, such as dumping LSASS process memory, that evade EDR detection. The process involves using an uncensored Qwen 3.8 27B model to modify an existing LSASS dumper, applying techniques like altered process spawning, reduced access masks, random sleeps during minidump creation, modified output paths, and scrubbed embedded strings to achieve stealth.
2026-09-24 2026Breaking the Superuser Guardrails of managed-PostgreSQL Providers intermediate 17 min read SQLiAnalysis of vulnerabilities in managed PostgreSQL provider security hardening extensions, detailing how these extensions temporarily grant superuser privileges to authorized users. This research identifies risks associated with extensions like Supabase's `supautils`, Azure's `azure.so`, and Aiven's `aiven_extras`, highlighting 76 reported vulnerabilities that could allow attackers to bypass protections and gain unauthorized access, potentially leading to cross-tenant compromises and direct operating system interaction via features like `COPY TO/FROM PROGRAM`.
2026-09-24 2026Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) news 9 min read AuthNWriteup on CVE-2026-94127, an F5 BIG-IP heap overflow vulnerability, detailing how an overly large "Authorization" header can lead to Remote Code Execution. The analysis reveals the vulnerability stems from insufficient size validation before copying the header's content into a heap buffer within the TMOS operating system, a flaw previously exploitable and now patched. The writeup traces the vulnerability's discovery through patch diffing and explains its trigger mechanism via the OAuth profile's `/f5-oauth2/v1/userinfo` endpoint. → labs.watchtowr.com
2026-09-24 2026Send GitLab an email, push to main intermediate 8 min read Supply ChainLibrary for analyzing GitLab's incoming email feature, which embeds a persistent, account-wide token instead of a project-specific credential. This token, disguised as an issue-creation email address, can be exploited to push code to protected branches, run CI/CD jobs, access secrets, and exfiltrate data from any accessible project, even bypassing IP restrictions. The analysis details how attackers can leverage the `-merge-request@` suffix and a `.patch` attachment to execute malicious code via `.gitlab-ci.yml`. → aikido.dev
2026-09-23 2026ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam intermediate 28 min readWriteup of a pre-authentication RCE vulnerability (CVE-pending) in the legacy `tac_plus` daemon for TACACS+, discovered in the same code base as older vulnerabilities. The writeup details the TACACS+ protocol, its history, and previous research, followed by the proof of concept, a PSK oracle enabling practical exploitation, and the disclosure process. It highlights the ongoing relevance of TACACS+ in enterprise environments, the challenges of maintaining aging software, and the potential for exploitation via network device login forms, even without prior network access. → elttam.com
2026-09-23 2026vCenter pre-auth RCE: CVE-2026-59309/59310 news 23 min readLibrary for analyzing VMware vCenter vulnerabilities, including CVE-2026-59309 and CVE-2026-59310. This resource details a method to reconstruct security patch information by diffing RPM packages and file hashes, enabling the identification of critical pre-authentication remote code execution flaws. It specifically outlines the path traversal vulnerability (CWE-22) within the syslog receiver, allowing arbitrary file writes that can escalate to RCE by manipulating syslog message headers.
2026-09-23 2026WordPress: Unauthenticated path traversal leading to conditional RCE intermediateLibrary for identifying and mitigating an unauthenticated path traversal vulnerability in WordPress's page-template resolution, potentially leading to conditional RCE. Exploitation requires specific theme configurations (e.g., `page-templates` directory in themes like Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney) and a readable `.php` file, such as `pearcmd.php`, especially when `register_argc_argv` is enabled. This affects WordPress versions prior to 7.1.2, with patches backported to 4.7.
2026-09-22 2026Inside BambooToken’s Linux implant: shell and file control over MQTT intermediate 7 min readAnalysis of BambooToken’s Linux implant reveals a backdoor that leverages MQTT for command and control, featuring a shell worker for executing commands via `/bin/sh -c` and a file worker for managing files with operations like `dir`, `download`, and `upload`. The implant uses a repeating XOR key for message obfuscation and encodes MQTT topics into lowercase hexadecimal strings. Black Lotus Labs has identified this implant, listing its SHA-256 hash in their collection of indicators of compromise.
2026-09-22 2026Three memory-safety bugs in Godot's untrusted-file parsers intermediate 7 min readWriteup detailing three memory-safety bugs in Godot 4.7, discovered with an LLM agent. The vulnerabilities, affecting untrusted file parsers for .hdr images, .res binary resources, and translation files, stem from missing bounds checking and can lead to buffer overflows. These issues are present in long-standing codebases, dating back to 2014 and 2017. The author reported the bugs to the Godot security team, highlighting potential exploitation in exported games that load external files, drawing parallels to past CVEs like CVE-2021-26825 and CVE-2021-26826.
2026-09-22 2026Windows Exploitation Techniques: Dangling COM Object Registrations intermediate 7 min readLibrary for abusing dangling COM object registrations on Windows, leveraging CVE-2026-66804. This technique involves exploiting a missing server DLL for a system-wide COM object and using custom COM marshaling, specifically through the IMarshal interface, to load a malicious DLL into a privileged process like `dllhost.exe` running as SYSTEM. The exploit targets COM services that do not have custom marshaling mitigations enabled, such as the Shell Create Object Handler. → projectzero.google
2026-09-20 2026CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes) news 3 min readWriteup of CVE-2026-77179, a Docker sandbox escape affecting Docker Desktop and Docker Sandboxes. This vulnerability allows a container to gain complete read and write access to the host filesystem by exploiting the virtio-fs implementation within Docker's VMM. The exploit involves manipulating symbolic links and file handles to trick the host's file server into resolving paths outside the intended container mount. Patches are available in Docker Sandboxes 0.42.0 and Docker Desktop 4.88.0.
2026-09-18 2026The skb that wasn't freed - the Fragnesia primitive via Open vSwitch advanced 19 min read AuthZLibrary for exploiting the Fragnesia privilege escalation primitive, CVE-2026-90049, affecting Open vSwitch. This library details how Open vSwitch strips the SKBFL_SHARED_FRAG marker from packets, reintroducing a local privilege escalation vulnerability previously addressed by fixes for Copy Fail, Dirty Frag, and Fragnesia itself. The exploit bypasses security measures by leveraging OVS's generic netlink interface and its autoloadable module, enabling unprivileged users within namespaces to overwrite read-only memory. → blog.doyensec.com
2026-09-18 2026MikroTrick: Inside the RouterOS Takeover Chain advanced 9 min read ReconWriteup detailing the "MikroTrick" takeover chain affecting MikroTik RouterOS. This chain exploits CVE-2026-67279, allowing unauthenticated connections to reach post-login functionality, and CVE-2026-86060, which tricks the login helper into treating attacker-controlled data as a trusted administrative identity. Successful exploitation results in full administrative control of vulnerable RouterOS versions. → bishopfox.com
2026-09-16 2026UANIA OS: Authenticated Remote Code Execution news 11 min readWriteup detailing an authenticated remote code execution vulnerability in UANIA OS. The analysis begins with an examination of the web interface and an attempt to exploit the packet capture feature. While the filter field was properly sanitized, the download functionality allowed for arbitrary file reads by manipulating the `path` parameter, including accessing `/etc/passwd`. Further investigation revealed the underlying platform to be OpenWrt, leveraging its UBUS message bus exposed via rpcd.
2026-09-16 2026Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution news 5 min readWriteup detailing multiple vulnerabilities in Frappe LMS, including CVE-2026-39405, a path traversal flaw in SCORM package uploads that allows for remote code execution. This vulnerability, when chained with CVE-2026-34606, a stored XSS flaw in profile bios exploitably by BeautifulSoup's get_text() function, enables a student user to achieve server-side RCE. The research demonstrates a manual exploitation path by replacing core API files and leverages XSS to trigger the RCE chain.
2026-09-16 2026James Kettle’s ‘autonomous research cascade’, CRLF-powered desync attacks, RCE on humanoid robots – ethical hacker news roundup news AIThis ethical hacker news roundup highlights several significant security developments. James Kettle's "autonomous research cascade" is a notable achievement in automated vulnerability discovery. The piece also details CRLF-powered desync attacks, a class of vulnerabilities that can disrupt communication protocols. Finally, it reports on the alarming discovery of remote code execution (RCE) capabilities on humanoid robots, raising serious concerns about the security of emerging AI and robotics technologies. → yeswehack.com
2026-09-15 2026IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR intermediate 18 min readWriteup detailing a pre-authentication remote code execution vulnerability in IBM Db2 Mirror for i. The exploit chain bypasses authentication by leveraging servlet path parameter manipulation, then utilizes a `skipVald` parameter to disable input validation, ultimately leading to arbitrary Java/JSP execution within the Liberty application server and potential QSECOFR access on the IBM i system.
2026-09-14 2026A revisit of remote Spectre attacks on Cloudflare Workers advanced 14 min readAnalysis of Spectre attacks against Cloudflare Workers, revisiting techniques discovered in 2021 and building an updated proof-of-concept on the production environment. This research uncovered a limitation in Cloudflare's Dynamic Process Isolation (DyPrIs) defense, successfully demonstrating a remote Spectre attack that leaked up to 12 bit/s with 99% accuracy. The attack leveraged speculative type confusion and out-of-bounds memory accesses to infer cache states. Improvements to DyPrIs, integration of the V8 Sandbox, and an in-process isolation mechanism have since been implemented to mitigate these memory disclosure risks. → blog.cloudflare.com
2026-09-13 2026Magento StyleSmuggler RCE: Report Poisoning to Code Execution intermediateThis document details a Remote Code Execution (RCE) vulnerability in Magento, dubbed "StyleSmuggler." The exploit leverages a report poisoning technique to achieve code execution. Attackers can manipulate report generation to inject malicious code, ultimately leading to a full compromise of the Magento instance. The severity of this vulnerability makes it a critical concern for Magento users.
2026-09-13 2026Beltdown2: Escaping the Cursor CLI sandbox intermediate 6 min readLibrary for escaping the Cursor CLI's macOS Seatbelt sandbox by leveraging a vulnerable `core.fsmonitor` hook in Git. This technique bypasses the sandbox by exploiting the fact that Cursor's internal `git` process runs unsandboxed and honors repository-supplied hooks, allowing arbitrary code execution outside the confined workspace. The provided writeup details the exploit chain and demonstrates a proof-of-concept that writes to `$HOME` despite sandbox restrictions, contrasting it with a blocked sandboxed shell command, and notes that Cursor has since implemented universal Git hardening to address this vulnerability class.
2026-09-12 2026CVE-2026-82329: Unauthenticated Administrative Access in JFrog Artifactory via an Empty Cluster Join Key news 7 min read AuthNWriteup of CVE-2026-82329, an unauthenticated administrative access vulnerability in JFrog Artifactory. This flaw, rated CVSS 9.8, allows any attacker with network access to obtain administrator privileges by exploiting an empty cluster join key in JFrog Access. Exploitation chains a forged join request to an unauthenticated endpoint, resulting in an admin-scoped token. The vulnerability affects multiple self-managed Artifactory versions prior to the patched releases: 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20. CISA has added this critical CVE to its Known Exploited Vulnerabilities catalog due to in-the-wild exploitation. → bishopfox.com
2026-09-11 2026🕵️‍♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance advanced 19 min read SSRFLibrary for analyzing CVE-2026-15409, a critical SSRF vulnerability affecting SonicWall SMA1000 appliances. This library demonstrates the exploitation chain, including reaching Erlang services for RCE and subsequent use of Impacket's secretsdump for Active Directory credential theft, leading to DCSync attacks. It details the process of extracting LDAP configurations and decrypting stored passwords, revealing opportunistic targeting across multiple countries and sectors.
Browse all 789 Remote Code Execution (RCE) resources →

Frequently Asked Questions

What is remote code execution?
Remote Code Execution (RCE) is a vulnerability that allows an attacker to run arbitrary commands or code on a target system. It is the most critical class of security vulnerability because it gives the attacker the same level of access as the application or server process, often leading to complete system compromise.
What are common RCE attack vectors?
Common vectors include command injection (unsanitized input passed to shell commands), unsafe deserialization (Java, PHP, Python, .NET), Server-Side Template Injection (Jinja2, Twig, Freemarker), file upload bypasses that execute uploaded code, expression language injection in Java frameworks, and prototype pollution in Node.js leading to code execution.
Why does RCE pay the highest bug bounties?
RCE represents total system compromise — an attacker can read all data, modify the application, pivot to internal networks, and potentially access cloud infrastructure. The impact is maximum, so bounty programs consistently pay their highest rewards for RCE findings, often ranging from $10,000 to $100,000+ depending on the target.

Weekly AppSec Digest

Get new resources delivered every Monday.