Dell Wyse Management Suite RCE Child Process Spawn (CVE-2026-41120)
Detects the spawning of administrative command-line utilities (cmd.exe, powershell.exe, wscript.exe, certutil.exe, mshta.exe) from processes related to Wyse Management Suite (WMS), Tomcat, or Java. This pattern is often indicative of exploitation of web applications or management services to gain command-line access on the underlying system.
Splunk (SPL)

