
Hugging Face Diffusers flaws bypass trust_remote_code
Hugging Face Diffusers vulnerabilities bypass trust_remote_code in three CVEs rated 8.8 and 7.5, enabling silent RCE from model repos. Patch now.
High-severity vulnerabilities worth immediate patch decisions, with CVSS context, affected software, and practical mitigation steps.

Hugging Face Diffusers vulnerabilities bypass trust_remote_code in three CVEs rated 8.8 and 7.5, enabling silent RCE from model repos. Patch now.
Fastjson 1.x RCE (CVE-2026-16723) is a critical CVSS 9.0 flaw actively exploited in Spring Boot apps with no official patch available. Block Fastjson 1.x endpoints, migrate to Jackson, and demand autotype safelists.
Check Point SmartConsole CVE-2026-16232 is a critical authentication bypass with a CVSS of 9.3, actively exploited and listed in CISA KEV. Patch your Security Management servers now.
CVE-2026-50522 is a critical SharePoint RCE flaw with CVSS 9.8 that attackers exploit to steal machine keys for persistence after patching.
ServiceNow CVE-2026-6875 is a CVSS 9.5 pre-auth sandbox escape RCE in the AI Platform, now actively exploited. Patch self-hosted instances immediately.
LegacyHive is a public Windows zero-day that escalates standard users to admin on patched systems. No CVE or patch yet, but MDE detection queries exist.
wp2shell is a pre-authentication remote code execution chain in WordPress Core. Two CVEs let anonymous attackers run code on 6.9 and 7.0 sites with no plugins.
Two SonicWall SMA 1000 zero-day vulnerabilities including a CVSS 10.0 SSRF are under active exploitation. CISA KEV-listed with a July 17 patch deadline.
A critical Gitea Docker auth bypass, CVE-2026-20896, lets attackers impersonate any user with one HTTP header. Over 6,200 instances are exposed online.
Bad Epoll (CVE-2026-46242) is a Linux epoll use-after-free giving unprivileged users root on v6.4+ kernels and Android. No workaround exists. Apply patch a6dc643c6931 now.
SharePoint CVE-2026-45659 is an actively exploited RCE risk in CISA KEV. Patch exposed servers and check compromise now.
SimpleHelp CVE-2026-48558 is an actively exploited auth bypass. Patch 5.5.16 or 6.0 RC2, then hunt for TaskWeaver and Djinn.
Cisco Unified CM CVE is now a patch-or-isolate job: CISA set a June 28 deadline after active exploitation of CVE-2026-20230.
CISA KEV vulnerabilities are a live patch queue: four exploited Lantronix and UniFi OS bugs now demand edge inventory and compromise checks.
Splunk CVE-2026-20253 is an actively exploited critical flaw. Patch exposed Enterprise 10.0 and 10.2 nodes by June 21.
Splunk Enterprise flaw CVE-2026-20253 is under active exploitation. Patch by June 21 or disable the PostgreSQL sidecar safely.