The Hacker News reports that Anthropic's Claude Code has been impacted by a trio of now-addressed security flaws, which could have been harnessed to enable remote code execution and API credential compromise.
The vulnerability is an operating system command injection flaw (CWE-78) that allows an authenticated user to execute arbitrary commands via specially crafted HTTP requests.
SolarWinds has issued fixes for four critical vulnerabilities impacting its Serv-U self-hosted Windows and Linux file transfer software, which could be weaponized to enable remote code execution, according to The Register.