Tag
#rce
8 posts tagged #rce.
-
Analysis · Jun 22, 2026 · Colten Anderson
CVE-2026-45657: 'Exploitation Less Likely' Is Not a Patch Window
Microsoft's June kernel use-after-free is wormable, CVSS 9.8, and sitting in researchers' hands. The hazard rating says 'Exploitation Less Likely.' Your patch cycle shouldn't read that as wait.
-
Analysis · Jun 21, 2026 · Colten Anderson
The CUPS chain needed a print job. The DDoS didn't.
Three CVEs in CUPS produced 20 months of scanning probes and zero attributed RCE exploitation. The constraint that stopped mass exploitation is also the reason cups-browsed still needs to go.
-
Analysis · Jun 20, 2026 · Colten Anderson
ShinyHunters had 13 days inside PeopleSoft before Oracle said anything
CVE-2026-35273 is a CVSS 9.8 unauthenticated RCE in PeopleTools 8.61-8.62 that ShinyHunters exploited as a zero-day against 100+ organizations. The June 10 advisory arrived after the data was already on the leak site.
-
Analysis · Jun 20, 2026 · Colten Anderson
Splunk Enterprise 10 shipped an unauthenticated database endpoint on port 8000
CVE-2026-20253 (CVSS 9.8) exposes a PostgreSQL sidecar service introduced in Splunk Enterprise 10 with no HTTP-layer authentication, reachable through the same port as the login page. A published exploit chain reaches code execution in minutes. Exploitation is confirmed. The 'disable the sidecar' workaround breaks SPL2 and Edge Processor.
-
Analysis · Jun 20, 2026 · Colten Anderson
GeoServer CVE-2024-36401: The Map Nobody Owned
A CVSS 9.8 unauthenticated RCE in GeoServer sat unpatched at thousands of agencies for weeks. The bug was the easy part. The reason nobody patched it is the real story.
-
Analysis · Jun 19, 2026 · Colten Anderson
If you patched OFBiz to 18.12.15 in August, you were exposed again by September
Apache shipped four OFBiz releases in five months, each closing a different endpoint with the same root cause behind it. Patching the version number was never the same as fixing the bug.
-
Analysis · Jun 19, 2026 · Colten Anderson
Your vuln scanner is looking for OpenSSH. The exploited bug is in Erlang.
CVE-2025-32433 is a CVSS 10.0 pre-auth RCE in Erlang/OTP's SSH server, and it's exploited in the wild against OT firewalls. The reason it slips past your scans is the whole point.
-
Analysis · Jun 17, 2026 · Colten Anderson
regreSSHion proved 'hard to exploit' is not a patch window
CVE-2024-6387 got filed under 'low priority' because it's slow on 64-bit. The CVSS score measured exploit difficulty, not what a root RCE in sshd actually puts at risk.