Critical Fastjson 1.x RCE Vulnerability Exploited Amid Lack of Patch

A serious vulnerability in Fastjson, Alibaba's JSON library for Java, is being actively exploited, with no patch currently available.

A serious vulnerability in Fastjson, Alibaba's JSON library for Java, is being actively exploited, with no patch currently available.

A researcher has published an exploit for a GitLab vulnerability that allows authenticated users to execute commands on self-managed servers. This flaw affects versions that have not been updated since June 10.

A critical vulnerability in WordPress, identified as wp2shell, enables unauthenticated attackers to execute code on affected sites. This flaw affects versions 6.9 and 7.0, with patches now available.

A serious vulnerability in Gogs, an open-source Git service, enables authenticated users to execute arbitrary code, raising significant security concerns.

Ivanti has released patches for two critical zero-day vulnerabilities in its Endpoint Manager Mobile (EPMM) product, which are currently being exploited. Organizations using this software are urged to take immediate action.