RCE
Coverage of RCE in the Nexus archive.
- Belgium's eID Authentication Opens Citizen Accounts to RCE
Belgium's eID Authentication system was compromised, opening citizen accounts to RCE vulnerabilities. The incident revealed that the underlying trust framework for the electronic ID system was fully breached by severe flaws found in a key browser extension, which highlights broader problems with extensions generally.
- Rails patches critical Active Storage flaw with RCE potential
A critical vulnerability in the Active Storage framework allows unauthenticated attackers to read arbitrary files from a Rails application, potentially escalating to remote code execution (RCE). The flaw has been patched by Rails.
- Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool
Google addressed a critical remote code execution (RCE) vulnerability in its AI-based Antigravity Tool. The flaw, a prompt injection vulnerability in an agentic AI product for filesystem operations, stemmed from a sanitization issue enabling sandbox escape and arbitrary code execution.
- F5 BIG-IP Vulnerability Reclassified as RCE, Under Exploitation
CVE-2025-53521 was initially reported as a high-severity denial-of-service flaw but has been reclassified as a more dangerous RCE (Remote Code Execution) vulnerability. The security issue is currently under active exploitation.