Security Risk Category

Remote Code Execution Security Risks — Page 6

Published vulnerability pages connected to Remote Code Execution. Each page keeps one canonical URL and focused remediation guidance.

303 published Remote Code Execution risks

Remote Code Execution risks

Showing 181–216 of 303 published risks.

highEPSS 0.002

CVE-2026-14400 in Google Chrome ANGLE

Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14400browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14401 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14401browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14403 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14403browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14405 in Google Chrome V8

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14405browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14407 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14407browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14409 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14409browserremote-code-executioninput-validation

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14411 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14411browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14412 in Google Chrome ANGLE

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14412browserremote-code-executioninput-validation

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14413 in Google Chrome ANGLE

Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14413browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14415 in Google Chrome V8

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14415browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14416 in Google Chrome Dawn

Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

CVE-2026-14416browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14417 in Google Chrome Dawn

Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14417browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14419 in Google Chrome Skia

Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14419browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.003

CVE-2026-14420 in Google Chrome Dawn

Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14420browserremote-code-executioninformation-disclosurememory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14423 in Google Chrome Tint

Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14423browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14424 in Google Chrome Dawn

Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14424browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.002

CVE-2026-14425 in Google Chrome ANGLE

Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14425browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14426 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14426browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14427 in Google Chrome Skia

Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-14427browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14430 in Google Chrome V8

Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14430browserremote-code-executioninput-validationmemory-corruption

Updated Jul 14, 2026

highEPSS 0.003

CVE-2026-14431 in Google Chrome V8

Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVE-2026-14431browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

highEPSS 0.002

CVE-2026-14432 in Google Chrome V8

Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

CVE-2026-14432browserremote-code-executionmemory-corruption

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50746 in UniFi Connect Application

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.

CVE-2026-50746network-securityremote-code-executionauthorization-bypass

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-50748 in UniFi Access Application

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

CVE-2026-50748network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

criticalEPSS 0.009

CVE-2026-54402 in UniFi OS Server

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.

CVE-2026-54402network-securityremote-code-executioninput-validationprivilege-escalation

Updated Jul 14, 2026

highEPSS 0.001

CVE-2026-38972 Notepad3 Vulnerability

Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.

CVE-2026-38972windowssupply-chainremote-code-executionpath-traversal

Updated Jul 14, 2026

high

CVE-2026-12413 Libreswan Vulnerability

An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote code execution is possible. Any configuration that allows IKEv2 connections that do not set fragmentation=no are vulnerable. IKEv1 is not affected.

CVE-2026-12413network-securityremote-code-executiondenial-of-service

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-50721 Libreswan Vulnerability

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of remote IKE peers are not affected.

CVE-2026-50721network-securityremote-code-executiondenial-of-servicecryptography

Updated Jul 14, 2026

highEPSS 0.004

CVE-2026-50722 Libreswan Vulnerability

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

CVE-2026-50722network-securityremote-code-executiondenial-of-servicecryptography

Updated Jul 14, 2026

high

CVE-2026-13053 WatchGuard Fireware Vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS's CLI could allow an authenticated privileged user to execute arbitrary code via a specially crafted CLI command. This vulnerability affects Fireware OS 11.0 up to and including 11.12.4_Update1, 12.0 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13053network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

high

CVE-2026-13383 fireware vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13383network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

high

CVE-2026-13384 fireware vulnerability

An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.

CVE-2026-13384network-securityremote-code-executionmemory-corruption

Updated Jul 14, 2026

mediumEPSS 0.011

CVE-2026-26355 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special Elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to command execution.

CVE-2026-26355network-securityremote-code-execution

Updated Jul 14, 2026

mediumEPSS 0.001

CVE-2026-46730 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an incorrect authorization vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to unauthorized command execution.

CVE-2026-46730network-securityremote-code-executionauthorization-bypass

Updated Jul 14, 2026

mediumEPSS 0.005

CVE-2026-54483 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.

CVE-2026-54483network-securityremote-code-execution

Updated Jul 14, 2026

mediumEPSS 0.005

CVE-2026-49813 data domain operating system vulnerability

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution.

CVE-2026-49813network-securityremote-code-execution

Updated Jul 14, 2026