A firewall's login page takes a request it was never built to parse, and a minute later someone else owns the box. That is the whole story behind the bugs that get patched on a three-day clock. This post explains what remote code execution is, how an RCE bug turns into a takeover, and why it goes to the front of the patch queue.
What Is Remote Code Execution?
Remote code execution (RCE) is a class of vulnerability where an attacker sends input to a system over a network and gets that system to run code of the attacker's choosing. No physical access, and in the worst cases no login either. The attacker talks to a service that is already listening, and the service does the rest.
The word "remote" describes the delivery. The word "code" describes the payload: a shell command, a script, a binary, or a snippet the application's own interpreter evaluates. The result is the same in every case. Whatever the vulnerable service is allowed to do, the attacker can now do too.
RCE is one outcome of an exploit, not a synonym for it. An exploit in cybersecurity is any technique that uses a flaw; the flaw might leak data, crash a service, or hand over control. RCE is the hand-over-control case, which is why it dominates the severity tables.
Security teams also say "arbitrary code execution" (ACE). ACE describes what the attacker gets: code of their choosing runs. RCE describes how they got there: over the network. A local privilege escalation bug can give ACE without being remote. When both words apply, the CVE says "unauthenticated remote code execution," and that is the phrase that empties a Slack channel.
How an RCE Bug Turns Into a Takeover
Every RCE follows the same five beats, whatever the product. First, the attacker can reach a listener: a VPN portal, a web app, an API, a management interface. Second, they send input shaped to hit a weak spot. Third, the service treats that input as code or as a command instead of as data. Fourth, the code runs with the service's privileges. Fifth, the attacker uses that foothold to stay: a web shell, stolen credentials, a new admin account, a jump to the next machine.
The third beat is where the bug lives, and MITRE's weakness catalog names the common shapes. CWE-94 covers code injection, where the product "constructs all or part of a code segment using externally-influenced input" and fails to neutralize it. CWE-77 covers command injection, where input reaches the operating system shell. CWE-502 covers unsafe deserialization, where a service rebuilds an object from a request and runs whatever the object tells it to. Memory corruption bugs get there by a longer road: overwrite the right bytes and the processor jumps to attacker-controlled instructions.
Two details decide how bad a given RCE is. Whether it needs a login: a pre-authentication RCE on an internet-facing service means anyone on the internet is a candidate attacker. And what account the service runs as: code execution as a locked-down web user is a bad day; code execution as root on the firewall is a rebuild.
Three RCEs From the Last Two Years
Definitions are easier to hold onto with names attached. These three are all in CISA's Known Exploited Vulnerabilities (KEV) catalog, which lists flaws with evidence of active exploitation.
PAN-OS GlobalProtect, CVE-2024-3400. Published 12 April 2024 with a CVSS 3.1 score of 10.0. The National Vulnerability Database describes a command injection reached through arbitrary file creation in the GlobalProtect feature, letting "an unauthenticated attacker execute arbitrary code with root privileges on the firewall." CISA added it to KEV the same day it was published and flagged known ransomware use. The target was the device that guards everything else.
React Server Components, CVE-2025-55182. Published 3 December 2025, also CVSS 10.0. The vulnerable code "unsafely deserializes payloads from HTTP requests to Server Function endpoints," so a pre-auth request to a Next.js or React app could run code on the server. CISA added it to KEV two days later, with known ransomware use. This one landed on developers who had never thought of their marketing site as an attack surface.
Gitea, CVE-2026-60004. Published 26 August 2026, CVSS 9.8, filed under CWE-94 code injection: Gitea before 1.27.1 "allows remote code execution via the diffpatch API through Git hook installation." CISA added it to KEV on 25 August with a due date of 28 August. Self-hosted Git servers are exactly the kind of thing that sits on a public IP because someone needed it to.
One Next.js operator wrote up what the React bug looked like from the inside. The attack landed within 24 hours of the CVE going public, and the forensic pass found five malware families deployed through the one hole, from a remote access tool with process hiding to a crypto miner that never got to run:
Why RCE Sits at the Top of the Patch Queue
Not every critical CVE deserves an emergency change. RCE on an exposed service does, and the numbers behind that rule are public.
CISA's KEV catalog held 1,729 entries as of 29 September 2026. Of the 245 entries added during 2026, 94 describe code execution, command execution or code injection in their own summary, by our count of the published feed. Verizon's 2025 Data Breach Investigations Report, published in April 2025, found exploitation of vulnerabilities as an initial access vector rose 34% year over year, with the growth concentrated on perimeter devices and VPNs. Those are the boxes where an RCE means the attacker is already inside.
The CVSS vector tells you which RCEs to fear. AV:N means reachable over the network, PR:N means no privileges needed, UI:N means no user has to click anything. All three CVEs above carry that exact combination. Reading the vector takes ten seconds and beats sorting by the base score alone, a point the NVD and CVSS guide makes at length.
The US federal patch clock shows where the standard is heading. CISA's Binding Operational Directive 22-01, issued in November 2021, gave agencies two weeks for a newly listed KEV. Its replacement, BOD 26-04 from 10 June 2026, sorts by exposure, KEV status, whether the exploit can be automated, and technical impact. A publicly exposed asset with a KEV-listed, automatable, total-impact flaw gets three days plus forensic triage. The Gitea entry above already ran on that clock. Nobody is holding a 30-person business to a federal directive, but it is a clean statement of what "urgent" means for an RCE now.
How to Reduce RCE Exposure
The fix for any single RCE is the vendor's patch. The fix for RCE as a category is knowing what you expose and shortening the time between a KEV entry and your patch.
Start with the listeners. Every service reachable from the internet is an RCE candidate, and the ones people forget are the dangerous ones: the VPN appliance's management port, a Git server for two contractors, a monitoring dashboard opened "for now." Mapping your attack surface is the first control, because you cannot patch on a three-day clock what you do not know is there.
Then fix the order. Patch by KEV status and exposure first, CVSS second. A CVSS 7.5 in KEV on a public box outranks a CVSS 9.8 nobody has exploited on an internal server. A patch management process that can run an out-of-band change without a committee meeting is the difference between three days and three weeks.
Reduce what a successful exploit gets. Services run as the least privileged account that works. Admin interfaces sit behind a VPN or an identity-aware proxy, never on a public IP. Segment the box that must be exposed so a foothold on it does not reach the file server. That homelab thread about the Gitea bug turned into an argument about exactly this: whether a public Git server belongs behind a login gate, and what to do when it has to stay public.
Watch for the aftermath, because some patches arrive after the exploit did. A web server process spawning a shell, a new scheduled task on a firewall, outbound connections from a box that only ever answered inbound requests: those are the signs of an RCE that already worked, and they only show up if the logs are collected somewhere the attacker cannot delete. Across a client fleet, OpenFrame can run a script on every device to list listening services and their versions, with the output collected in one place.
A short walkthrough of the same idea, from listener to shell, in about 90 seconds:
The Short Version
RCE means an attacker turns a request into code running on your machine. Pre-auth RCE on an internet-facing service is the worst version, and it is the version that fills the KEV catalog. Patch those first, on days rather than cycles, and know every listener you expose before the advisory lands.
For the broader picture, the exploit explainer covers how bugs become weapons, and the incident response plan covers what to do in the hour after you find a web shell.
Content Marketing Lead
Ohayo! I run content, SEO, social, and community at Flamingo. Before IT, I worked as a correspondent for Ukraine's Public Broadcasting Company and have a Master's in journalism.
