Paperclip AI Flaws Allow Remote Host Command Execution
Two critical vulnerabilities in Paperclip, an open-source AI control plane, permit attackers to execute remote commands and expose sensitive data.
Tag
11 results in the archive.
Two critical vulnerabilities in Paperclip, an open-source AI control plane, permit attackers to execute remote commands and expose sensitive data.
Adobe Campaign Classic includes a critical CVSS 10.0 vulnerability (CVE-2026-48449) that allows arbitrary code execution without user interaction.
JetBrains disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that enables remote code execution, posing significant risk to enterprise environments.
A critical vulnerability in the Ruflo open-source agent platform allows unauthenticated remote code execution and poisoning of AI memory, posing significant risks to AI model operations.
Attackers are exploiting a critical remote code execution vulnerability in Fastjson 1.x used in Spring Boot applications, enabling unauthenticated code execution with Java process privileges and no patch currently available.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
CISA has mandated U.S. federal agencies to urgently address a remote code execution vulnerability actively exploited in Langflow, posing critical risks to infrastructure security.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
A critical SQL injection vulnerability identified as CVE-2026-63030 affects WordPress Core and is actively exploited, allowing unauthenticated remote code execution.
F5 released patches for CVE-2026-42533, a critical nginx flaw allowing remote, unauthenticated attackers to trigger a heap buffer overflow that can crash workers or enable remote code execution.
CISA warns that remote code execution vulnerabilities are actively exploited in Joomla iCagenda and Balbooa Forms extensions through arbitrary file uploads, risking full compromise of affected sites.