Fastjson 1.2.x Remote Code Execution Without Gadget Vulnerability Notice

Overview Recently, NSFOCUS CERT detected that a Fastjson 1.2.x remote code execution vulnerability without gadget was disclosed online; Due to the defects in the internal type parsing logic of Fastjson deserialization, unauthenticated attackers can construct specially crafted malicious JSON data to bypass the traditional autoType black and white list protection...

WordPress Remote Code Execution Vulnerability (CVE-2026-63030/CVE-2026-60137) Notice

Overview Recently, NSFOCUS CERT detected that WordPress issued a security bulletin to fix the WordPress remote code execution vulnerability (CVE-2026-63030/CVE-2026-60137), known as wp2shell; Unauthenticated attackers can bypass authentication through REST API batch requests, use SQL injection to obtain administrator password hashes, and use plug-in installation functions to implant WebShell to...

Microsoft’s Security Update in June of High-Risk Vulnerability Notice for Multiple Products

Overview On June 9, NSFOCUS CERT detected that Microsoft released a security update patch for June, fixing 206 security issues involving widely used products such as Windows, Microsoft Office, Microsoft Exchange Server, Visual Studio Code, Azure, etc., including remote code execution vulnerabilities, High-risk vulnerability types such as information leakage vulnerabilities...

Nginx Remote Code Execution Vulnerability (CVE-2026-42945) Notice

Overview Recently, NSFOCUS CERT detected that Nginx and F5 issued security bulletins to fix the Nginx remote code execution vulnerability (CVE-2026-42945); because the ngx_http_rewrite_module module contains question marks in processing (? ) has a defect in the calculation logic when replacing strings with rewrite. Under certain configuration conditions, an unauthenticated...

NSFOCUS
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.