Articles

14 articles

CVE-2026-64633: Veeam ONE Agent RCE Needs No Password

8 min read

A CVSS 10.0 code-injection vulnerability in Veeam ONE allows a remote, unauthenticated attacker to execute code on the agent host. No active exploitation is known, but affected systems should be upgraded to 13.1.0.7034 immediately.

CVE-2026-68771: ComfyUI Pickled Its Way to Unauthenticated RCE

6 min read

An unsafe PyTorch deserialization path in ComfyUI allows unauthenticated attackers to execute arbitrary commands using a malicious pickle shard. CVSS 9.3; no public PoC or confirmed successful exploitation, although exploitation attempts are reportedly being tracked.