
Today's Top Cybersecurity News – February 05, 2026 1. Critical Metro4Shell RCE Vulnerability Actively Exploited in React Native CLI The Metro4Shell vulnerability (CVE-2025-11953) in the React Native Metro Development Server is being actively exploited by threat actors to execute arbitrary code remotely. This flaw allows attackers to deliver malicious payloads targeting developer systems on Windows and Linux, posing a significant risk to development environments. Sources: Bleepingcomputer, Crowdstrike, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Krebsonsecurity, Securityaffairs, Securityweek https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html 2. CVE-2026-1341: Critical Missing Authentication in Avation Light Engine Pro Avation Light Engine Pro's configuration and control interface lacks any authentication or access control, allowing unauthorized users to potentially manipulate critical settings. This vulnerability poses a severe risk of unauthorized access and control over affected systems. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-1341 3. Multiple Critical Vulnerabilities in n8n Workflow Automation Platform Allow RCE and Data Exposure Several severe vulnerabilities have been identified in the n8n open source workflow automation platform, including sandbox escapes, arbitrary file write and read, OS command injection, and stored XSS. These flaws allow authenticated users with workflow modification permissions to execute remote code, read sensitive files, and perform cross-site scripting attacks, potentially leading to full system compromise. Patches addressing these issues have been released in recent versions. Sources: Bleepingcomputer, Cvefeed, Feedburner, Infosecurity-Magazine https://cvefeed.io/vuln/detail/CVE-2026-25115 4. Multiple Critical Vulnerabilities Disclosed in Wireless Access Points Including ELECOM and Hikvision Several critical vulnerabilities have been disclosed affecting wireless access points from ELECOM, Hikvision, and WRC models. These include a stack-based buffer overflow, authenticated command execution, and OS command injection, potentially allowing arbitrary code or command execution by attackers. Immediate mitigation and patching are recommended to prevent exploitation. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-24465 5. Critical XXE Vulnerability in Apache Syncope Console Enables Session Hijacking A critical XML External Entity (XXE) vulnerability (CVE-2026-23795) in Apache Syncope's Console component allows authenticated administrators to execute attacks that can extract sensitive data and hijack active user sessions. This flaw affects multiple versions and poses significant risks to identity and access management systems. Sources: Cvefeed, Gbhackers https://gbhackers.com/apache-syncope-vulnerability/ Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats
Post summary
The roundup reports several critical CVEs, notes that Metro4Shell is being actively exploited, and includes patch or mitigation information for multiple affected products.



