Skip to content
Threat Feed

Tag

Arbitrary Code Execution

29 briefs RSS
high advisory

CVE-2026-48393: Out-of-Bounds Write Vulnerability in Adobe Bridge Leads to Arbitrary Code Execution

An out-of-bounds write vulnerability (CVE-2026-48393, CWE-787) in Adobe Bridge allows for arbitrary code execution in the context of the current user, requiring user interaction by opening a specially crafted malicious file.

Adobe Bridge +1 arbitrary-code-execution out-of-bounds-write user-interaction adobe
2t 1c
high advisory

JetBrains WebStorm Multiple Vulnerabilities Allow Code Execution

Multiple vulnerabilities in JetBrains WebStorm allow a local attacker to execute arbitrary program code, enabling attackers to compromise the integrity and confidentiality of the affected system.

WebStorm arbitrary-code-execution vulnerability development-environment
1t
high advisory

CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard

A critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.

odh-dashboard +1 cloud-security kubernetes authentication-bypass privilege-escalation arbitrary-code-execution red-hat
4t 1c
high advisory

FFmpeg Vulkan HEVC Stack Buffer Overflow (CVE-2026-64831)

A stack buffer overflow vulnerability exists in the Vulkan HEVC hardware decoder within FFmpeg versions 8.0 through 8.1.2, allowing remote attackers to achieve arbitrary code execution by crafting a malicious HEVC/H.265 bitstream with an oversized vps_num_hrd_parameters value that overwrites return addresses and adjacent stack frames in the vk_hevc_end_frame function.

FFmpeg vulnerability buffer-overflow media-processing arbitrary-code-execution
1t 1c
high advisory

FFmpeg VobSub Heap Buffer Overflow Vulnerability (CVE-2026-64830)

FFmpeg versions 2.1 through 8.1.2 contain a heap buffer overflow vulnerability (CVE-2026-64830) in the VobSub subtitle demuxer, allowing attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file, potentially leading to arbitrary code execution in applications using FFmpeg's VobSub demuxer.

FFmpeg 2.1 +1 vulnerability heap-overflow ffmpeg arbitrary-code-execution media
1t 1c
high advisory

CVE-2026-48373: Adobe Acrobat Reader Heap-based Buffer Overflow

A heap-based buffer overflow vulnerability, CVE-2026-48373, in Adobe Acrobat Reader could allow an attacker to achieve arbitrary code execution in the context of the current user when a victim opens a specially crafted malicious file.

Acrobat Reader +1 cve vulnerability adobe acrobat-reader arbitrary-code-execution heap-buffer-overflow
2t 1c
high advisory

Arbitrary Code Execution via JavaScript Frontmatter in Prompty TypeScript Loader

A high-severity vulnerability, CVE-2026-53597, in the Prompty TypeScript loader (`@prompty/core`) versions `>= 2.0.0-alpha.1 < 2.0.0-beta.3` allows arbitrary JavaScript code execution in the host Node.js process when parsing untrusted `.prompty` files due to improper handling of `gray-matter`'s executable frontmatter engines.

@prompty/core arbitrary-code-execution supply-chain vulnerability nodejs typescript
1t 1c
high advisory

ForgeCode AI Pair-Programming CLI Arbitrary Code Execution via Malicious .mcp.json

CVE-2026-57860 describes an arbitrary code execution vulnerability in ForgeCode, an AI pair-programming CLI tool, where it automatically loads and executes commands specified in a repository's `.mcp.json` file upon startup without user confirmation, allowing attackers to achieve initial access and persistence on developer machines when a user runs `forge` within an untrusted, cloned repository.

ForgeCode arbitrary-code-execution cli developer-tools supply-chain
1r 2t 1c
high advisory

CVE-2026-9046: Insecure Permissions in Lenovo Legion Zone and App Store Leads to Local Arbitrary Code Execution

CVE-2026-9046 describes an insecure permissions vulnerability in Lenovo's Legion Zone and Lenovo App Store Windows applications, distributed exclusively in the Chinese market, which, when installed on a non-system partition, allows a local low-privileged user to execute arbitrary code, leading to high impact on confidentiality, integrity, and availability.

Legion Zone +1 insecure-permissions local-privilege-escalation windows arbitrary-code-execution
2t 1c
high advisory

Multiple Out-of-Bounds Write Vulnerabilities in Rockwell Automation Arena

Multiple out-of-bounds write vulnerabilities (CVE-2026-8085, CVE-2026-8312, CVE-2026-8313, CVE-2026-8314) in Rockwell Automation Arena versions prior to V17.00.01 could allow an attacker to execute arbitrary code by convincing a user to open a malicious file.

Rockwell Automation Arena <=V17.00.00 +1 vulnerability ics ot memory-corruption out-of-bounds-write arbitrary-code-execution critical-manufacturing
1r 3t 4c updated
high advisory

PipeWire Vulnerability CVE-2026-5674 Allows Sandbox Escape and Arbitrary Code Execution

A critical vulnerability, CVE-2026-5674, exists in PipeWire, a multimedia server, enabling an attacker to escape sandboxed applications like Flatpak by exploiting its PulseAudio compatibility layer to load a malicious library, leading to arbitrary code execution outside the sandbox and potential system compromise.

PipeWire +2 sandbox-escape privilege-escalation arbitrary-code-execution linux flatpak
4t 1c
high advisory

CAI Content Credentials Server-Side Request Forgery Leads to Arbitrary Code Execution

CAI Content Credentials is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, CVE-2026-48290, which an attacker can exploit to achieve arbitrary code execution and potentially gain elevated access by injecting malicious scripts into a web page, requiring user interaction to succeed.

Content Credentials server-side-request-forgery ssrf arbitrary-code-execution web-vulnerability cve
2t 1c
high advisory

Adobe Creative Cloud Desktop Vulnerability Allows Arbitrary Code Execution via Uncontrolled Search Path

An Uncontrolled Search Path Element vulnerability (CVE-2026-48272) in Adobe Creative Cloud Desktop versions up to 6.9.1.1 could allow arbitrary code execution in the context of the current user, requiring no user interaction but dependent on conditions beyond the attacker's full control.

Creative Cloud Desktop arbitrary-code-execution vulnerability adobe windows macos
1t 1c
high advisory

DENX U-Boot: Multiple Vulnerabilities Enable Arbitrary Code Execution and Denial of Service

An attacker with physical access can exploit multiple unspecified vulnerabilities in DENX U-Boot to execute arbitrary code with service privileges, leading to system compromise and potentially causing a denial-of-service condition.

U-Boot physical-access bootloader embedded-systems arbitrary-code-execution denial-of-service
2t
high advisory

Multiple High-Severity Vulnerabilities in EDK2 NetworkPkg IP Stack Implementation

Multiple high-severity vulnerabilities exist within the EDK2 NetworkPkg IP stack implementation, allowing an attacker, either from an adjacent network or remotely and anonymously, to achieve arbitrary code execution, disclose confidential information, and trigger a denial of service condition, impacting the low-level networking capabilities and security of systems utilizing this firmware component.

EDK2 NetworkPkg IP stack implementation firmware-vulnerability arbitrary-code-execution denial-of-service data-exfiltration edk2
4t
critical advisory

Flowise 3.1.3 Arbitrary Code Execution Exploit Published

A critical arbitrary code execution vulnerability in Flowise version 3.1.3 and earlier has been publicly disclosed on Exploit-DB, enabling unauthenticated attackers to execute arbitrary commands on unpatched web application instances, leading to full system compromise.

Flowise webapps arbitrary-code-execution exploit-db
2t
high advisory

CVE-2025-71372: Picklescan Deserialization Vulnerability (Numpy Gadget)

CVE-2025-71372 describes a critical vulnerability in Picklescan versions prior to 0.0.33, where the tool fails to detect a specific numpy gadget in pickle `__reduce__` methods, allowing attackers to craft malicious pickle files that execute arbitrary Python code when loaded, bypassing safety checks and enabling supply-chain poisoning of shared model files.

Picklescan < 0.0.33 vulnerability deserialization python supply-chain numpy arbitrary-code-execution
2t 1c 2i
high advisory

CVE-2025-71362 — picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functio...

picklescan versions prior to 0.0.33 are vulnerable to unsafe deserialization via CVE-2025-71362, allowing attackers to embed malicious code in pickle files that executes due to `numpy.f2py.crackfortran` calling `eval` on arbitrary strings when loaded from untrusted sources, leading to arbitrary code execution.

picklescan cve deserialization python arbitrary-code-execution vulnerability
2t 1c
high advisory

CVE-2025-71347: Picklescan Bypass Leads to Arbitrary Code Execution via Malicious Pickle Files

A critical vulnerability (CVE-2025-71347) exists in picklescan prior to version 0.0.33, allowing remote attackers to bypass security checks by failing to detect malicious pickle files leveraging the numpy.f2py.crackfortran.param_eval function, leading to arbitrary code execution upon deserialization of untrusted data.

picklescan < 0.0.33 deserialization python arbitrary-code-execution vulnerability cve defense-evasion
2t 1c 2i
high threat

Kirby CMS Arbitrary Method Call Vulnerability via REST API

Kirby CMS is vulnerable to arbitrary method call via REST API search and collection query endpoints, allowing attackers to execute sensitive methods like password disclosure or privilege escalation, patched in versions 4.9.1 and 5.4.1.

cms +1 arbitrary-code-execution privilege-escalation web-application
2r 1t
critical advisory

Multiple Vulnerabilities in vm2

Multiple vulnerabilities in vm2 allow a remote, anonymous attacker to execute arbitrary code, bypass security measures, manipulate data, and disclose sensitive information.

vm2 sandbox-escape arbitrary-code-execution
2r 5t
high advisory

CVE-2026-34644: Adobe After Effects Integer Overflow Vulnerability

Adobe After Effects versions 26.0, 25.6.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user if a victim opens a malicious file.

After Effects +1 integer overflow arbitrary code execution user interaction
2r 1t 1c
high advisory

CVE-2026-34642: Adobe After Effects Heap-based Buffer Overflow Vulnerability

Adobe After Effects versions 26.0, 25.6.4 and earlier are vulnerable to a heap-based buffer overflow (CVE-2026-34642) that could lead to arbitrary code execution when a user opens a malicious file.

After Effects +1 cve-2026-34642 heap-based buffer overflow arbitrary code execution adobe after effects exploitation
2r 1t 1c
high advisory

CVE-2026-34638: Adobe Premiere Pro Use-After-Free Vulnerability Leading to Arbitrary Code Execution

Adobe Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability (CVE-2026-34638) that could lead to arbitrary code execution in the context of the current user if a malicious file is opened.

Premiere Pro cve-2026-34638 use-after-free arbitrary code execution adobe premiere pro file parsing
2r 1t 1c
high advisory

Babel Plugin Vulnerability Leads to Arbitrary Code Execution via Malicious Input

A maliciously crafted input to Babel's `@babel/plugin-transform-modules-systemjs` or `@babel/preset-env` with `modules: 'systemjs'` can cause the tool to generate arbitrary code execution.

@babel/plugin-transform-modules-systemjs +1 code-generation arbitrary-code-execution babel
2r 1t
high advisory

NI LabVIEW Out-of-Bounds Read Vulnerability (CVE-2026-32863)

A memory corruption vulnerability due to an out-of-bounds read in NI LabVIEW's `sentry_transaction_context_set_operation()` function could lead to information disclosure or arbitrary code execution by opening a specially crafted VI file.

cve-2026-32863 labview out-of-bounds read memory corruption arbitrary code execution information disclosure
2r 5t 1c
critical advisory

Firefox and Thunderbird Memory Safety Vulnerability (CVE-2026-4720)

A memory safety vulnerability (CVE-2026-4720) in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 could lead to memory corruption and potential arbitrary code execution if successfully exploited.

cve-2026-4720 firefox thunderbird memory-corruption arbitrary-code-execution
2r 2t
high advisory

Multiple Vulnerabilities in Grub Bootloader

Multiple vulnerabilities in the Grub bootloader allow attackers to execute arbitrary code and cause denial-of-service conditions.

bootloader grub2 vulnerability denial-of-service arbitrary-code-execution
2r 2t
critical advisory

CODESYS Multiple Vulnerabilities Allow Arbitrary Code Execution and DoS

Multiple vulnerabilities in CODESYS allow a remote attacker to execute arbitrary program code and conduct a denial-of-service attack.

codesys vulnerability arbitrary-code-execution denial-of-service ics
2r 2t