#vulnerability
5 posts
SharePoint deserialisation RCE: CVE-2026-45659
A plain Site Member account is enough to run code on a SharePoint server. Microsoft rated exploitation unlikely, and CISA put it in the KEV catalogue with three days to remediate.
n8n unauthenticated RCE (Ni8mare): CVE-2026-21858
The form node skips Content-Type validation, so one application/json request makes it read an arbitrary file. The key inside the config forges an admin JWT, and a sandbox bypass turns that into RCE.
Cisco FMC unauthenticated Java deserialisation RCE: CVE-2026-20131
CVSS 10.0, no authentication, code execution as root, and 36 days of use as a zero-day by a ransomware crew. Breaking the firewall management hub hands over every policy and log with it.
Next.js incremental cache path traversal to RCE: CVE-2026-75604
One unescaped backslash turns the incremental cache into arbitrary file read and write on Windows, and the leaked Server Action encryption key forges a request that walks a React Flight property chain to Function.
React Router prototype pollution chained into RCE: CVE-2026-42211
turbo-stream v2 calls a constructor while rehydrating the TYPE_ERROR branch without checking where it came from. If the app already has a prototype pollution bug, that path reaches Function and two moderate flaws become RCE.
