“Arbitrary code execution” — 56 distilled results

Critical vulnerabilities discovered in infrastructure software

Between 2026-09-22 and 2026-09-24, multiple remote code execution vulnerabilities were disclosed in Android Telecom (CVE-2026-49881), Check Point Management (CVE-2026-93616), Check Point VPN (CVE-2026-85102), ManageEngine OpManager (CVE-2026-19599), GitLab (CVE-2026-89078), and Luxion KeyShot (CVE-2026-92202). Several are actively exploited in the wild.

CVE-2022-37969 - Changed to Known Ransomware Status Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common L

CVE-2022-37969 - Changed to Known Ransomware Status Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation VulnerabilityVendor: MicrosoftProduct: WindowsMicrosoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows f

Six critical software vulnerabilities disclosed in September 2026

Between 2026-09-07 and 2026-09-09, security researchers disclosed six critical vulnerabilities across enterprise and network products with CVSS scores of 9.1–10.0, including unauthenticated remote code execution in JetBrains Hub, D-Link routers, Google Cloud ADK, SAP CAP, and Check Point Quantum Security Gateway, plus credential theft in a payment processing module. No patches were available as of the latest report date.

🔹 SecurityWeek Rockwell Patches Code Execution Flaws in Arena Simulation Software A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. Th

🔹 SecurityWeek Rockwell Patches Code Execution Flaws in Arena Simulation Software A researcher has explained how an attacker could exploit these vulnerabilities to target industrial organizations. The post Rockwell Patches Code Execution Flaws in Arena Simulation Software appeared first on SecurityWeek.

IBM AIX and PowerVM VIOS hit by multiple critical vulnerabilities

Five CVEs affecting IBM AIX 7.2/7.3 and PowerVM VIOS 4.1 were disclosed between August 19–21, 2026, exposing private keys, enabling authentication bypass, command injection, and other critical attacks. CVE-2026-15065, CVE-2026-16656, CVE-2026-16816, CVE-2026-17040, and CVE-2026-17118 collectively present severe risks to enterprise systems running these platforms.