Tag
high
advisory
Authenticated Remote Code Execution in TP-Link Archer BE800
1 TTP 1 CVEAn authenticated remote code execution vulnerability (CVE-2026-16348) in the TP-Link Archer BE800 management interface allows attackers with administrator privileges to execute arbitrary commands via shell injection in the VPN key field.
Archer BE800
rce
shell-injection
router
network-appliance
1t
1c
critical
advisory
Langflow GitHub Actions Shell Injection Vulnerability
2 rules 2 TTPs 1 IOCUnauthenticated remote shell injection vulnerability exists in Langflow GitHub Actions workflows prior to version 1.9.0, enabling attackers to execute arbitrary shell commands via malicious branch names or pull request titles due to unsanitized GitHub context variable interpolation, leading to potential secret exfiltration and supply chain compromise.
shell-injection
github-actions
supply-chain
2r
2t
1i