rce
Safeguard articles tagged "rce" — guides, analysis, and best practices for software supply chain and application security.
89 articles
Shellshock (CVE-2014-6271): The Bash Vulnerability That Hit CGI Scripts and Embedded Devices
A factual retrospective on Shellshock, the September 2014 Bash vulnerability that allowed remote code execution through crafted environment variables, affecting web servers and countless embedded devices.
Log4Shell (CVE-2021-44228): The Log4j RCE and Its Supply Chain Lesson
A factual look at Log4Shell, the critical remote code execution vulnerability in Apache Log4j disclosed in December 2021, and why it became a defining supply chain security event.
ThreatSonar, Control Web Panel, and XWiki: When Under-the-Radar Software Gets Popped
An unauthenticated eval injection in XWiki, a known-username command injection in Control Web Panel, and a file-upload RCE in an anti-ransomware tool itself — three vendors, one lesson.
Langflow and Marimo: When the AI Platform's Core Feature Is the Vulnerability
Three confirmed-exploited CVEs across Langflow and Marimo show what happens when a code-execution-by-design platform ships an authentication gap on the endpoint meant to guard it.
The Same Code Injection Bug Hit Ivanti's Mobile Manager Twice in Two Months
Two nearly identical unauthenticated RCE vulnerabilities in Ivanti Endpoint Manager Mobile, plus a perfect-10 in Sentry and a credential-leaking bypass in Endpoint Manager.
Zimbra's Optional SNMP Monitoring Feature Became a Remote Code Execution Path
CVE-2026-73570 requires the optional zimbra-snmp package and SNMP notifications enabled — exactly the configuration a more security-conscious mail admin was likely to have set up.
Adobe ColdFusion's Path Traversal Bug Reached Full Code Execution
CVE-2026-48282, CVSS 10.0, is a path traversal vulnerability in Adobe ColdFusion that leads directly to arbitrary code execution — the platform's latest entry in a long history of critical CVEs.
Two TrueConf Server CVEs, Same Port, Same Day
TrueConf Server's on-premises videoconferencing had two vulnerabilities confirmed exploited on the same day in August 2026, both reachable through a single named TCP port.
Five SharePoint CVEs in Five Weeks: The Deserialization Habit Continues
Microsoft SharePoint had five vulnerabilities confirmed exploited between July and August 2026, three of them the same root cause: deserialization of untrusted data. One carries CISA's confirmed ransomware flag.
Apache Shiro remember-me cookie deserialization RCE (CVE-2016-4437)
Apache Shiro's default rememberMe cipher key enables unauthenticated Java deserialization RCE. Here's how CVE-2016-4437 works and how to fix it.
vLLM CVE-2025-66448: Auto-Map RCE via Model Configs
A critical RCE in vLLM allows malicious model configs to bypass trust_remote_code=False. We analyze the bug, the patch, and what every vLLM operator should do.
Inside the Qinglong Scheduler RCE: How Two Auth Bugs Became a Cryptomining Campaign
Two chainable auth-bypass bugs in the Qinglong task scheduler let attackers skip login entirely and mine crypto on victim CPUs — in the wild before a patch existed.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.