code execution
Coverage of code execution in the Nexus archive.
- New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
A new vulnerability in 7-Zip (CVE-2026-14266) allows code execution when processing crafted XZ archives due to a heap-based buffer overflow. Trend Micro's Zero Day Initiative disclosed the flaw on July 15, and a fix was released in 7-Zip 26.02 on June 25.
- F5 issues out-of-band patches for critical NGINX vulnerabilities
Cybersecurity company F5 has released out-of-band security updates to address multiple NGINX web server vulnerabilities. The updates include fixes for two critical-severity flaws that could allow attackers to execute code on vulnerable systems.
- Max severity Ivanti Sentry vulnerability now exploited in attacks
Attackers are exploiting a recently patched maximum-severity vulnerability in Ivanti Sentry, allowing code execution with root privileges on Internet-exposed secure mobile gateways.
- Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
Google patched a vulnerability in its Antigravity IDE that allowed code execution via prompt injection. The flaw exploited file-creation capabilities and insufficient input sanitization in the IDE's find_by_name tool to bypass security restrictions.