Skip to content
Threat Feed

Tag

Command Execution

17 briefs RSS
critical advisory

Unauthenticated MCP Servers Expose Cloud Data and Enable Command Execution

Unauthenticated Model Context Protocol (MCP) servers, particularly those running protocol version 2024-11-05, are widely exposed across cloud environments, enabling significant security risks by allowing attackers to bypass authentication, gain initial access, execute arbitrary commands on backend systems, obtain sensitive cloud credentials (including temporary ones via Server-Side Request Forgery against cloud metadata endpoints), discover internal systems and data, and collect/exfiltrate sensitive information like PII, business records, and security findings.

Model Context Protocol cloud-security AI unauthenticated-access data-exposure command-execution
10t
medium advisory

Exim: Multiple Vulnerabilities Allow Local Command Execution and Privilege Escalation

Multiple vulnerabilities in Exim allow a local attacker to execute arbitrary commands and escalate privileges on the affected system, enabling a local adversary to gain higher control over the mail transfer agent and potentially the underlying operating system.

Exim vulnerability privilege-escalation command-execution
2t
high advisory

Unusual Command Execution via Linux Web Server Processes

This brief details how attackers exploit vulnerable web applications or deploy webshells on Linux systems to achieve persistence by executing unusual shell commands from web server processes, potentially leading to payload downloads, reverse shells, or cron-like task implants.

Apache HTTP Server +40 linux-threat persistence web-exploitation webshell command-execution detection-rule elastic-security
1r 4t
high advisory

CVE-2025-71380: Authenticated Remote Code Execution in n8n via Execute Command Node

CVE-2025-71380 is an improper access control vulnerability (CWE-284) in n8n versions up to and including 1.114.4 that allows authenticated users to execute arbitrary commands on the underlying host system where n8n runs, potentially leading to data exfiltration, service disruption, or complete system compromise.

n8n <= 1.114.4 RCE vulnerability n8n workflow-automation command-execution improper-access-control
2r 6t 1c
high advisory

Web Server Potential SQL Injection Attempt Detection

This brief details the detection of potential SQL injection (SQLi) attempts against web servers by identifying common SQLi patterns in URLs and query strings, used by threat actors for reconnaissance, data exfiltration, or command execution, aiming for sensitive information disclosure or system compromise.

Apache +5 sql-injection web-attack reconnaissance initial-access data-exfiltration command-execution persistence cross-platform
1r 6t
low advisory

Unusual Command Execution from Web Server Parent Process on Linux

This rule detects potential command execution from a web server parent process on a Linux host, indicating a possible web shell attack where adversaries exploit web server vulnerabilities to execute arbitrary commands.

Elastic Defend +2 web-shell command-execution persistence linux
2r 3t
high advisory

Cisco Privileged Account Creation Followed by HTTP Command Execution

Attackers create privileged accounts on Cisco IOS devices and then execute commands remotely via HTTP to gain privileged access.

IOS +1 cisco network privilege escalation command execution
1r 3t
high advisory

CVE-2026-47114 - IINA Command Execution Vulnerability via Custom URL Scheme

IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler.

IINA command execution custom url scheme macos CVE-2026-47114
2r 1t 1c
high advisory

CVE-2026-32643: F5 BIG-IP and BIG-IQ Authenticated Command Execution

CVE-2026-32643 describes a vulnerability in F5 BIG-IP and BIG-IQ systems that allows a highly privileged, authenticated attacker with the Certificate Manager role to modify configuration objects, leading to arbitrary command execution.

BIG-IP +1 cve command execution privilege escalation f5
2r 1t 1c
high advisory

CyberPanel 2.1 Authenticated Remote Command Execution via Symlink Exploitation (CVE-2021-47949)

CyberPanel version 2.1 is vulnerable to command execution (CVE-2021-47949) where an authenticated attacker can exploit symlink attacks via the filemanager controller endpoint by manipulating the completeStartingPath parameter in POST requests, leading to sensitive file access and arbitrary shell command execution.

CyberPanel cve command execution symlink linux
2r 1t 1c
high advisory

JupyterLab Command Execution via Crafted HTML Content

JupyterLab's HTML sanitizer allows execution of arbitrary commands via specially crafted HTML content in notebooks or Markdown files due to improper handling of `data-commandlinker-command` and `data-commandlinker-args` attributes.

jupyterlab +1 command-execution html-injection
2r 1t
high advisory

Cisco IoT Field Network Director Multiple Vulnerabilities

Multiple vulnerabilities in Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial-of-service (DoS) conditions on managed routers.

IoT Field Network Director Software cisco iot vulnerability dos command-execution file-access
3r 4t
critical threat

IBM Langflow Desktop Vulnerable to Remote Command Execution (CVE-2026-6543)

IBM Langflow Desktop versions 1.0.0 through 1.8.4 are vulnerable to remote command execution, allowing an attacker to execute arbitrary commands with the privileges of the Langflow process, potentially leading to sensitive data exposure and lateral movement.

Langflow Desktop cve-2026-6543 command execution code injection ibm langflow
3r 1t 1c
critical advisory

Rclone Unauthenticated options/set Allows Runtime Auth Bypass

Rclone is vulnerable to an unauthenticated options/set vulnerability that allows runtime authentication bypass, potentially leading to sensitive operations and command execution by setting `rc.NoAuth=true` on reachable RC servers started without global HTTP authentication.

rclone auth-bypass rc-api CVE-2026-41176 command-execution
2r 3t
high advisory

Windows Shell Execution from IIS Installation Directory

Detection of command-line tools executing from the IIS installation directory on Windows systems, potentially indicating exploitation of IIS-reliant software like Microsoft Exchange.

Exchange Server +3 iis web-shell command-execution windows
2r 2t
high advisory

Potential Command Shell via NetCat Execution

The rule identifies potential attempts to execute a reverse shell using the netcat utility to execute Windows commands via Cmd.exe or Powershell.

Elastic Defend reverse shell netcat command execution windows
2r 3t
medium advisory

Suspicious Command Execution via SolarWinds Process

This brief covers the detection of suspicious command execution, specifically Cmd.exe or PowerShell.exe, as child processes of legitimate SolarWinds executables, indicative of potential supply chain compromise and unauthorized command execution on Windows systems.

SolarWinds Orion supply-chain solarwinds command-execution powershell cmd
2r 3t