A long-lived Redis memory-corruption flaw dubbed RediShell (CVE-2025-49844) was reported as a use-after-free bug that can lead to remote code execution under certain conditions. Although exploitation requires authentication, research noted that tens of thousands of Redis instances have historically been exposed to the internet without authentication enabled, increasing real-world risk; the issue was discovered by Wiz and demonstrated at Pwn2Own Berlin prior to public disclosure.
Separately, IceWarp disclosed a critical unauthenticated RCE (CVE-2025-14500) caused by OS command injection in handling of the X-File-Operation HTTP header, impacting both Windows and Linux deployments and enabling arbitrary command execution as SYSTEM/root. The flaw was reported in September 2025 and fixed in October 2025 across supported product lines, but Shadowserver reported more than 1,200 internet-facing on-prem instances still unpatched and said it is notifying affected owners to upgrade.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
On March 5, 2026, CSO Online published a roundup of long-lived software flaws, including the Redis use-after-free bug CVE-2025-49844, LionWiki path traversal issues, a sudo host logic flaw, HashiCorp Vault and CyberArk Conjur logic bugs disclosed at Black Hat USA 2025, GRUB2 Secure Boot-related flaws, and the recently fixed Telnet bypass. The article summarizes previously disclosed technical findings rather than introducing a new incident.
By early March 2026, the Shadowserver Foundation reported more than 1,200 internet-facing IceWarp instances remained vulnerable to CVE-2025-14500 and said it was notifying owners to update. IceWarp support urged prompt upgrades and backups before patching, while CCB warned patching would not undo any prior compromise.
A Telnet authentication bypass vulnerability, CVE-2026-24061, that had existed since May 2017 was fixed in January 2026. The bug could enable remote compromise when the service is exposed to the internet.
In October 2025, IceWarp fixed CVE-2025-14500 across multiple supported product generations and versions. The Centre for Cybersecurity Belgium later described the issue as insufficient validation of user-supplied data before it is passed to a system call.
The critical unauthenticated OS command injection vulnerability CVE-2025-14500 in IceWarp was reported in September 2025. The flaw affects handling of the X-File-Operation header and can allow arbitrary command execution as SYSTEM on Windows or root on Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.