LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release

command injection

6 stories
CVE-2026-73570critical

U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalog

CISA has added a critical vulnerability in Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-73570, allows unauthenticated remote code execution and is being actively exploited by threat actors. Zimbra released a patch for the vulnerability less than a month before exploitation was confirmed.

snowflakehigh

Snowflake GitHub Actions Flaw Allows Command Injection

Researchers have identified a vulnerability in Snowflake's GitHub Actions workflows, specifically within the snowflakedb/snowflake-connector-net repository. A specially crafted GitHub issue could exploit this flaw to execute commands within a workflow, potentially exposing internal Jira credentials.

CVE-2026-20147high

Cisco Identity Services Engine Vulnerable to Command Injection

A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

CVE-2026-8037critical

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. CISA has added a critical command injection vulnerability in Progress Kemp LoadMaster to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-8037, the flaw allows unauthenticated attackers to execute arbitrary code on affected devices. This addition follows reports of active exploitation attempts, with over 792 observed in the past 41 days.

CVE-2026-50746critical

Ubiquiti Patches Critical UniFi OS Flaws Allowing Command Injection and Privilege Escalation

Ubiquiti has released security updates to address seven vulnerabilities in its UniFi OS, including several critical flaws. One critical vulnerability, CVE-2026-50746, allows for command injection in the UniFi Connect Application, impacting systems that manage building infrastructure like smart lighting and EV chargers. Other patched issues include SQL injection, improper input validation, and SSRF vulnerabilities across various UniFi applications, potentially leading to privilege escalation.

ubiquiticritical

Ubiquiti warns of new max severity UniFi OS vulnerability

Ubiquiti has issued updates to address seven critical vulnerabilities within its UniFi OS. Among these patched flaws is a command injection vulnerability rated at maximum severity.