Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
8 results for “arbitrary code execution”
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe released security patches for three critical vulnerabilities (CVSS 10.0) in ColdFusion and Campaign Classic that could enable arbitrary code execution and privilege escalation.
Aug 12, 2026
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP released patches for a critical unauthenticated remote code execution vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud's Data Hub Adapter due to insufficient authorization checks and input validation.
Aug 12, 2026
Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe patched a critical CVSS 10.0 vulnerability (CVE-2026-48449) in Campaign Classic that allowed unauthenticated, no-interaction remote code execution due to incorrect authorization logic.
Aug 1, 2026
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Researchers at Nebula Security demonstrated that a patched Firefox JIT vulnerability (CVE-2026-10702) enabled arbitrary code execution in the renderer process with zero user interaction, and was weaponized to compromise Tor Browser.
Jul 29, 2026
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains disclosed a critical remote code execution vulnerability (CVE-2026-63077, CVSS 9.8) in all on-premises TeamCity versions that allows unauthenticated attackers to execute OS commands, prompting urgent patching.
Jul 28, 2026
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A critical command injection vulnerability (CVE-2026-16812, CVSS 10.0) in Arista’s on-premises VeloCloud Orchestrator is being actively exploited, enabling remote arbitrary code execution.
Jul 28, 2026
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions
Zimbra has disclosed an unpatched, critical stored XSS vulnerability in its Classic Web Client that enables arbitrary code execution via malicious emails, with no CVE assigned and no public exploit details released.
Jul 11, 2026
Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws
A security researcher disclosed three high-severity vulnerabilities in the OpenClaw personal AI assistant—now patched—that could enable credential theft, privilege escalation, and arbitrary code execution on the host system.
Jul 10, 2026