<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>We continuously map, monitor, and test your external attack surface — just like a real attacker would.</description><link>https://bsky.app/profile/rcesecurity.com</link><title>@rcesecurity.com - RCE Security</title><item><link>https://bsky.app/profile/rcesecurity.com/post/3mhssy6a3tc2r</link><description>Turning an encrypted backup into Remote Code Execution in Stackfield’s desktop app (CVE-2026-28373).&#xA;&#xA;#security&#xA;https://www.rcesecurity.com/2026/03/stackfield-desktop-app-rce-via-path-traversal-and-arbitrary-file-write-cve-2026-28373/</description><pubDate>24 Mar 2026 14:47 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3mhssy6a3tc2r</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3meyvft2hvs2u</link><description>Pwning TRUfusion Enterprise again: chaining a pre-auth SSRF (CVE-2025-32355), a default password, and a path traversal (CVE-2025-59793) to gain RCE.&#xA;&#xA;#security&#xA;&#xA;https://www.rcesecurity.com/2026/02/when-audits-fail-from-pre-auth-ssrf-to-rce-in-trufusion-enterprise/</description><pubDate>16 Feb 2026 20:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3meyvft2hvs2u</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3m5yrx7pbfs22</link><description>We took WPScan&#39;s one-liner #security advisory for CVE-2025-9501 affecting the W3 Total Cache plugin for #WordPress, analysed its cache parsing internals and built a pre-auth RCE exploit for it 😎&#xA;&#xA;https://www.rcesecurity.com/2025/11/exploiting-a-pre-auth-rce-in-w3-total-cache-for-wordpress-cve-2025-9501/&#xA;&#xA;#infosec</description><pubDate>19 Nov 2025 17:33 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3m5yrx7pbfs22</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3m4ntpzukyk2s</link><description>Our friends @hashicorp.com released a new version of Consul fixing our reported Denial of Service vulnerabilities (CVE-2025-11374 and CVE-2025-11375). &#xA;&#xA;See our official advisories for the details and remediation steps: https://www.rcesecurity.com/security-advisories/&#xA;&#xA;#security</description><pubDate>02 Nov 2025 15:40 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3m4ntpzukyk2s</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3m22ui2mis22w</link><description>Another day, another Remote Code Execution (and its 3 friends).&#xA;&#xA;Pre-auth path traversal, hard-coded crypto key allowing cookie forgery, arbitrary file write, and PII disclosure in TRUfusion Enterprise (CVE-2025-27222 to CVE-2025-27225) #security&#xA;&#xA;https://www.rcesecurity.com/2025/09/when-audits-fail-four-critical-pre-auth-vulnerabilities-in-trufusion-enterprise/</description><pubDate>30 Sep 2025 15:43 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3m22ui2mis22w</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3lt2ytb5zbc2o</link><description>We&#39;ve just updated our latest blog post about CVE-2025-47812 to include another disclosure that went a little under the radar but could be used to leak a user&#39;s password: CVE-2025-27889.&#xA;&#xA;#security #BugBounty&#xA;&#xA;https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/</description><pubDate>03 Jul 2025 15:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3lt2ytb5zbc2o</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3lstwe5shl225</link><description>During a customer pentest, we went from anonymous Read-Only FTP access to full root-level remote code execution by abusing a string parsing discrepancy in Wing FTP&#39;s username handling.&#xA;&#xA;#security #BugBounty&#xA;&#xA;https://www.rcesecurity.com/2025/06/what-the-null-wing-ftp-server-rce-cve-2025-47812/</description><pubDate>30 Jun 2025 19:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3lstwe5shl225</guid></item><item><link>https://bsky.app/profile/rcesecurity.com/post/3lmhqxxcio22b</link><description>Here&#39;s a short write-up about CVE-2023-6542 a #security vulnerability affecting the SAP Emarsys SDK for Android allowing attackers to leak sensitive data from an app&#39;s private data directory and also load remote contents into an app overlay.&#xA;&#xA;https://www.rcesecurity.com/2025/04/sap-emarsys-sdk-for-android-sensitive-data-leak-cve-2023-6542/</description><pubDate>10 Apr 2025 14:52 +0000</pubDate><guid isPermaLink="false">at://did:plc:qmt56ayzedk3ndf4a2j2fyoq/app.bsky.feed.post/3lmhqxxcio22b</guid></item></channel></rss>