RCE in Marimo CVE-2026-39987: exploit in 9 hours https://sudonull.com/rce-in-marimo-cve-2026-39987-exploit-in-9-hours
Critical pre-auth RCE in Marimo up to 0.23.0 gives root-shell via WebSocket. Sysdig: attack 9 hours after advisory. Update, rotate secrets, protect AI toolchain. Detailed analysis and measures.
RCE in MCPJam Inspector: HTB Kobold walkthrough https://sudonull.com/rce-in-mcpjam-inspector-htb-kobold-walkthrough
Full HTB Kobold walkthrough: RCE via MCPJam v1.4.2, Docker LFI, credential reuse to root. For devsecops — code, commands, GHSA-232v-j27c-5pp6 vulnerabilities.
MCP Vulnerability from Anthropic: RCE and Double Standards https://sudonull.com/mcp-vulnerability-from-anthropic-rce-and-double-standards
Critical RCE vulnerability in the MCP protocol from Anthropic is ignored by the company despite responsible disclosure. Analysis of attack vectors and recommendations for developers.
LFI RCE in WP Umbrella CVE-2024-12209 https://sudonull.com/lfi-rce-in-wp-umbrella-cve-2024-12209
Analysis of critical LFI in WP Umbrella (CVSS 9.8) with PoC for RCE. Attack vectors, exploit via EXIF, protection for WordPress. Study the vulnerability for site audits.
Top CVE March 2026: RCE in Cisco and Langflow https://sudonull.com/top-cve-march-2026-rce-in-cisco-and-langflow
Critical vulnerabilities March 2026: Cisco FMC deserialization, Langflow RCE, Chrome zero-day, Trivy supply chain. Patches, exploits, mitigation for DevSecOps. Update systems now.