[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#Unauthenticated RCE

articleHIGH 8.8

SolarWinds Access Rights Manager Hard-Coded Key Flaw Enables Unauthenticated RCE

A high-severity vulnerability, CVE-2026-28326, with a CVSS score of 8.8, was discovered in SolarWinds Access Rights Manager (ARM). The flaw allows for unauthenticated remote code execution and affects all versions of ARM 2026.2 and prior. SolarWinds has released security updates to address this vulnerability. Organizations are urged to apply the patches immediately to prevent potential exploitation.

Sep 20, 20261 source
articleCRITICAL 10.0

CVE-2026-61962: Unauthenticated Arbitrary Code Execution in WP BASE Booking Plugin

A critical vulnerability (CVE-2026-61962) with a CVSS score of 10 has been discovered in the WP BASE Booking plugin (versions <= 6.3.0). This unauthenticated arbitrary code execution vulnerability allows attackers to execute code remotely without authentication, posing a significant risk to WordPress installations using this plugin. Immediate patching is recommended to prevent potential exploitation.

Aug 14, 20261 source