<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Remote-Code-Execution on CuraSec</title><link>https://curasec.metacog.co.kr/tags/remote-code-execution/</link><description>Recent content in Remote-Code-Execution on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/remote-code-execution/index.xml" rel="self" type="application/rss+xml"/><item><title>8,300+ Gitea servers exposed to active RCE exploitation</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-over-8-300-gitea-servers-vulnerable-to-code-execution-attack/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-over-8-300-gitea-servers-vulnerable-to-code-execution-attack/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you self-host Gitea, check your version immediately and patch to the latest release — Shadowserver confirms ongoing RCE exploitation against exposed instances, meaning unpatched servers are actively being targeted now.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Audit your estate for internet-exposed Gitea instances and hunt for signs of RCE compromise (unexpected processes, new admin accounts, modified repos) since exploitation is described as active; a compromised source-code platform carries serious supply-chain risk.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Confirm with engineering whether your organization runs self-hosted Gitea and verify patching status this week; a compromised internal code repository would pose a supply-chain risk worth flagging to leadership if exposure is confirmed.&lt;/li>
&lt;/ul></description></item><item><title>PaperCut Chained RCE Flaws Actively Exploited, Emergency Patch Released</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-attackers-chain-two-papercut-flaws-to-execute-code-without-a/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-attackers-chain-two-papercut-flaws-to-execute-code-without-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Unauthenticated RCE via chained flaws in PaperCut NG/MF is being actively exploited; apply the emergency patch immediately and audit PaperCut server logs for unexpected Java process execution or outbound connections predating the patch.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of PaperCut print servers means assumed-breach posture is warranted — hunt for anomalous Java child processes or unusual network activity originating from PaperCut hosts since before the emergency patch date, and check EDR telemetry on any print-management systems.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> PaperCut NG/MF is common in enterprise and education environments; confirm with engineering that all instances are patched this week and verify no lateral movement occurred from print servers — prior PaperCut exploits (2023) drew board attention, so have a status update ready if asked.&lt;/li>
&lt;/ul></description></item><item><title>Elementor Pro Unauthenticated File Upload Enables RCE (CVE-2026-32475)</title><link>https://curasec.metacog.co.kr/insights/2026-08-20-elementor-pro-flaw-could-let-unauthenticated-attackers-uploa/</link><pubDate>Thu, 20 Aug 2026 11:39:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-20-elementor-pro-flaw-could-let-unauthenticated-attackers-uploa/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CVSS 9.0 with a public PoC on GitHub means opportunistic exploitation is imminent; update Elementor Pro to the latest patched release immediately and audit WordPress upload directories for any unexpected PHP files already dropped via the Forms module.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> A public PoC for unauthenticated RCE means mass scanning is likely underway; hunt for unauthorized PHP files in WordPress upload paths and review web server and WAF logs for suspicious POST requests targeting the Elementor Pro Forms endpoint since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-32475 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>