Remote code execution vulnerabilities
Remote code execution lets an attacker run arbitrary code on the target system, usually over the network and in the worst cases without authentication. RCE is the most severe vulnerability class: a single unauthenticated RCE in an internet-facing product routinely leads to mass exploitation within days, and RCE entries dominate the CISA KEV catalog.
Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged remote code execution, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.
Latest remote code execution advisories
Cisco IOS XR Software Security Hardening Release: September 2026
[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen
[UPDATE] [mittel] vim: Mehrere Schwachstellen ermöglichen Codeausführung
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux (openCryptoki, hplip, 389-ds-base): Mehrere Schwachstellen
[UPDATE] [hoch] FreeRDP: Mehrere Schwachstellen
[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [mittel] Golang Go-Module (Net, Image, Crypto: Mehrere Schwachstellen
[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen
[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
[UPDATE] [mittel] GNU libc: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux und Satellite (satellite/iop-remediations-rhel9 container image): Mehrere Schwachstellen
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [mittel] Red Hat Enterprise Linux (389-ds-base): Schwachstelle ermöglicht Codeausführung und potenziell Denial of Service
[UPDATE] [hoch] Golang Go: Mehrere Schwachstellen
[UPDATE] [mittel] Golang Go: Mehrere Schwachstellen
[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
[UPDATE] [hoch] Apache HTTP Server: Mehrere Schwachstellen
[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellen
[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen
[UPDATE] [hoch] Redis: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux (mrtg, kbd, urwid): Mehrere Schwachstellen
[UPDATE] [mittel] GNU libc: Mehrere Schwachstellen
[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellen
[UPDATE] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux (nodejs:24): Mehrere Schwachstellen
[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen
[UPDATE] [hoch] GStreamer: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux (DBI, perl-GD): Mehrere Schwachstellen
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
[UPDATE] [mittel] Redis: Schwachstelle ermöglicht Codeausführung
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [mittel] vim: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, DOMPurify): Mehrere Schwachstellen
[UPDATE] [hoch] NGINX NGINX Plus: Mehrere Schwachstellen
[UPDATE] [hoch] Red Hat Enterprise Linux (389-ds-base): Mehrere Schwachstellen ermöglichen Codeausführung und DoS
[UPDATE] [mittel] Red Hat OpenShift Container Platform (protobufjs, fast-uri): Mehrere Schwachstellen
[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen ermöglichen Codeausführung und DoS
[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellen
[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
[UPDATE] [hoch] FreeRDP: Mehrere Schwachstellen
[UPDATE] [mittel] 7-Zip: Schwachstelle ermöglicht Codeausführung
[UPDATE] [mittel] GStreamer: Mehrere Schwachstellen
[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen
[UPDATE] [mittel] Red Hat Enterprise Linux (dracut): Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
[UPDATE] [hoch] QEMU: Schwachstelle ermöglicht Privilegieneskalation
[UPDATE] [kritisch] Kemp LoadMaster: Mehrere Schwachstellen
Other vulnerability classes
New remote code execution advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.