Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
5 results for “unauthenticated RCE”
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point disclosed two unauthenticated remote code execution vulnerabilities (CVSS 9.8) in its VPN certificate handling across Security Gateways and management products, patched without public disclosure of the specific exploitation conditions or technical details.
Sep 10, 2026
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
Attackers are actively exploiting two zero-day vulnerabilities in SonicWall's SMA 1000 series appliances to achieve unauthenticated remote code execution, following earlier zero-day exploits against the vendor's edge devices this summer.
Sep 3, 2026
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
A critical remote code execution vulnerability (CVE-2026-15748, CVSS 9.8) was disclosed in the Forminator WordPress plugin—used on over 600,000 active sites—allowing unauthenticated attackers to execute arbitrary PHP code via malicious file uploads.
Aug 18, 2026
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Security researchers disclosed a critical unauthenticated remote code execution vulnerability (CVE-2026-55040, CVSS 9.1) in multiple Microsoft SharePoint Server versions, with AI assistance playing a significant role in its discovery.
Aug 11, 2026
Unauthenticated RCE in Motorola's MR2600 Router
A security vulnerability allowing remote code execution without authentication was disclosed in Motorola's MR2600 router, posing risks to consumer network infrastructure.
Jul 12, 2026