Hugging Face Diffusers flaws bypass trust_remote_code
Hugging Face Diffusers vulnerabilities bypass trust_remote_code in three CVEs rated 8.8 and 7.5, enabling silent RCE from model repos. Patch now.
6 stories tagged rce.
Hugging Face Diffusers vulnerabilities bypass trust_remote_code in three CVEs rated 8.8 and 7.5, enabling silent RCE from model repos. Patch now.
Cl0p affiliates exploit unauthenticated RCE in internet-exposed PTC Windchill and FlexPLM to steal data. Patch, segment, and block external access now.
Fastjson 1.x RCE (CVE-2026-16723) is a critical CVSS 9.0 flaw actively exploited in Spring Boot apps with no official patch available. Block Fastjson 1.x endpoints, migrate to Jackson, and demand autotype safelists.
ServiceNow CVE-2026-6875 is a CVSS 9.5 pre-auth sandbox escape RCE in the AI Platform, now actively exploited. Patch self-hosted instances immediately.
wp2shell is a pre-authentication remote code execution chain in WordPress Core. Two CVEs let anonymous attackers run code on 6.9 and 7.0 sites with no plugins.
Langflow RCE is being used to mine Monero on exposed AI app endpoints. Patch, isolate, and treat public workflows as production attack surface.