Product
high
advisory
Exploitation of N-able N-central via CVE-2024-27429
3 TTPs 1 CVEThreat actors are exploiting a remote code execution vulnerability (CVE-2024-27429) in N-able N-central to gain unauthorized access and deploy RMM payloads on managed systems.
N-central
remote-code-execution
rmm
supply-chain
3t
1c
critical
advisory
IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)
1 rule 3 TTPs 11 CVEs 2 IOCsUnauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.
Langflow OSS +10
remote-code-execution
api-exploitation
unauthenticated-access
code-injection
web-vulnerability
ai-llm
1r
3t
11c
2i
updated