Every story tagged Command Injection, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
6 stories · open in the command center
CVE-2026-18787 is a critical command injection vulnerability (CVSS 8.8-9.0) in GL.iNet AX1800 routers up to version 4.8.3 that allows authenticated remote attackers to execute arbitrary commands through the RPC endpoint, with a public exploit already available. This poses significant risk to organizations using these devices for network infrastructure, requiring immediate firmware updates and network segmentation to mitigate potential lateral movement and system compromise. IT leaders must assess their inventory of GL.iNet AX1800 devices and prioritize patching, as the vulnerability requires only low-privilege access and has minimal attack complexity.
A critical remote command injection vulnerability (CVSS 9.8-10.0) has been discovered in GL.iNet GL-MT3000 routers up to firmware version 4.4.5, allowing unauthenticated attackers to execute arbitrary commands with no user interaction required; the exploit is publicly available and actively exploitable. This vulnerability poses significant risk to organizations using these devices for network infrastructure, potentially compromising network security, data integrity, and availability across connected systems. IT organizations must immediately identify affected devices in their inventory, prioritize firmware updates to patched versions, and implement network segmentation or access controls to limit exposure.
CVE-2026-18686 is a critical remote command injection vulnerability (CVSS 9.8-10.0) affecting GL.iNet GL-MT3000 routers up to version 4.4.5, with public exploits already available and no authentication required for exploitation. This poses significant risk to organizations using these devices for network access or IoT infrastructure, as attackers can achieve complete system compromise. IT leaders must immediately inventory affected devices, prioritize patching or device replacement, and implement network segmentation to isolate vulnerable GL-MT3000 units until remediation is complete.
CVE-2026-67323 is a critical command injection vulnerability (CVSS 8.6) in GitPython versions before 3.1.51 that allows arbitrary code execution when applications pass untrusted user input to Git operations like archive(), ls_remote(), iter_commits(), and blame(). This poses severe risk to any organization using GitPython in web applications, CI/CD pipelines, or tools that process user-controlled Git repository parameters. IT organizations must immediately inventory GitPython deployments and prioritize patching to version 3.1.51 or later to prevent potential system compromise and data loss.
A critical command injection vulnerability (CVE-2026-67323) in GitPython versions before 3.1.51 allows attackers to execute arbitrary commands through unguarded Git options, posing significant risk to any organization using this library for version control operations or CI/CD pipelines. This high-severity vulnerability (CVSS 8.6) could enable unauthorized code execution, data exfiltration, or supply chain attacks if exploited against development infrastructure. IT organizations must immediately assess their software dependencies and development toolchains for exposure to this vulnerability.
A critical vulnerability in iTerm2's SSH integration feature allows malicious content in plain text files to execute arbitrary code when viewed with 'cat', exploiting the terminal's trust model by impersonating legitimate remote conductor protocol messages. This represents a fundamental class of supply chain and social engineering risk where simply viewing documentation, log files, or server responses can compromise systems. The vulnerability demonstrates how modern terminal features that enhance productivity can inadvertently expand the attack surface beyond traditional command execution vectors.