24h | 7d | 30d

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
18 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
8.95%

KEV

Description

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Statistics

  • 15 Posts
  • 38 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

  • 15
  • 2
  • 0
  • 9h ago
Profile picture fallback

📰 Critical Unauthenticated RCE Flaw Found in WordPress Core

Critical unauthenticated RCE vulnerability (CVE-2026-63030) found in WordPress Core. Affects versions 6.9.x and 7.0.x. Allows full site takeover via REST API. Update to 6.9.5 or 7.0.2 now! #WordPress #CVE #RCE #PatchNow

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

  • 7
  • 3
  • 0
  • 10h ago
Profile picture fallback

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

  • 4
  • 1
  • 1
  • 10h ago
Profile picture fallback

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
WordPress Exploitation Underway (CVE-2026-63030) https://isc.sans.edu/diary/33168
  • 1
  • 2
  • 0
  • Last hour
Profile picture fallback
On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030, a critical unauthenticated remote code execution vulnerability affecting WordPress Core.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-63030, CVE-2026-60137) #WordPress Core Unauthenticated RCE via wp2shell". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 1
  • 0
  • 0
  • 14h ago
Profile picture fallback
In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
夜行性インコさんのまとめ。即対応ですなこれは:WordPress Coreの脆弱性 CVE-2026-63030 / CVE-2026-60137 (通称「wp2shell」)についてまとめてみた - piyolog piyolog.hatenadiary.jp/entry/2026/0...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Critical WordPress core flaws, CVE-2026-60137 and CVE-2026-63030, can be chained for unauthenticated access, SQL injection, and possible RCE. CERT-AGID reports suspicious API activity and new admin accounts. #WordPress #CERTAGID #Italy
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
WP2Shell flaws CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild. Chaining them can enable unauthenticated remote code execution on stock WordPress installs. #WordPress #Cloudflare #CVE-2026-60137
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Checkpoint~ Microsoft, WordPress, SonicWall patch actively exploited CVEs; Jscrambler npm supply chain attack steals credentials. - IOCs: CVE-2026-56164, CVE-2026-63030, CVE-2026-15409 - #Ransomware #ThreatIntel #Vuln
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 10 Posts
  • 8 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Faille dans 7-Zip : pourquoi vous devriez installer la version 26.02 sans attendre it-connect.fr/7-zip-26-02-fail #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 4
  • 3
  • 0
  • 10h ago
Profile picture fallback

Remember to update your 7-Zip to 26.02 to fix a possible RCE!
#CVE-2026-14266

  • 0
  • 0
  • 2
  • 16h ago
Profile picture fallback

A critical heap-based buffer overflow vulnerability has been discovered in 7-Zip that could allow remote code execution when processing crafted XZ archives. CVE-2026-14266 affects how the archiver han
thehackernews.com/2026/07/new-
#cybersecurity #vulnerability #7zip

  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback

En las últimas 24 horas, se detectaron vulnerabilidades críticas en WordPress, 7-Zip, Foxit PDF Reader y NGINX que permiten ejecución remota de código y escalada de privilegios, mientras una avanzada campaña rusa con el RAT Starland intensifica amenazas; la actualización inmediata y la vigilancia continua son esenciales. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 20/07/26 📆 |====

🔓 EXPLOIT BROKERS PAGAN $500,000 POR UNA RCE EN WORDPRESS

Se ha detectado una vulnerabilidad crítica que permite la ejecución remota de código (RCE) en WordPress. La publicación se retrasó estratégicamente para que los administradores pudieran actualizar sus sistemas sin riesgo durante el fin de semana. Si utilizas WordPress, es vital que verifiques la seguridad de tu instancia con la herramienta disponible en wp2shell.com/. Mantente alerta para proteger tu sitio frente a posibles ataques. Más detalles y cómo verificar tu seguridad aquí 👉 djar.co/YsbS

🛡️ NUEVA VULNERABILIDAD EN 7-ZIP PUEDE EJECUTAR CÓDIGO AL EXTRAER ARCHIVOS XZ MANIPULADOS

Se ha identificado CVE-2026-14266, un desbordamiento de pila de alta gravedad en el decodificador XZ de 7-Zip que permite la ejecución remota de código al abrir archivos comprimidos maliciosos. La versión 26.02 ya incluye el parche que corrige esta falla crítica. Recomendamos actualizar inmediatamente para evitar compromisos de seguridad. Infórmate y actualízate aquí 👉 djar.co/QRKdfM

⚠️ ESCALADA DE PRIVILEGIOS EN FOXIT PDF READER PERMITE CONTROL TOTAL DEL SISTEMA

Un grave fallo de seguridad (CVE-2026–57239) en Foxit PDF Reader permite a usuarios sin privilegios elevar permisos hasta NT AUTHORITY\SYSTEM, otorgando control total sobre el sistema afectado. Esta vulnerabilidad pone en riesgo entornos corporativos y personales, por lo que actualizar y revisar las políticas de seguridad es urgente. Conoce cómo protegerte aquí 👉 djar.co/r0Zuj

🔥 CVE-2026-42533: FALLA CRÍTICA EN NGINX PERMITE EJECUCIÓN REMOTA DE CÓDIGO

F5 ha publicado un parche para corregir un bug muy serio en NGINX que puede provocar caídas del servidor y, en casos extremos, ejecución remota de código mediante solicitudes HTTP manipuladas. Los administradores de sistemas deben aplicar esta actualización cuanto antes para evitar intrusiones y mantener la integridad de sus servicios web. Descubre los pasos para mitigar el riesgo aquí 👉 djar.co/g35e9

🚨 UAT-11795: NUEVO RAT STARLAND Y C2 PERSONALIZADO EN CAMPAÑA FINANCIADA POR UN ADVERSARIO RUSO

Cisco Talos alerta sobre UAT-11795, una campaña avanzada que utiliza el RAT Starland junto a un comando y control (C2) exclusivo, dirigida contra objetivos en EE. UU. y Europa desde junio de 2025. Este adversario sofisticado refuerza la necesidad de fortalecer la detección y respuesta ante amenazas con vigilancia continua y soluciones actualizadas. Obtén detalles para proteger tu entorno aquí 👉 djar.co/zqN7

📅 RESUMEN SEMANAL DE CIBERSEGURIDAD 13/07/26 - 19/07/26: DFIR Y TALLERES PRÁCTICOS EN INCIBE

La semana pasada, Lorenzo Martínez destacó en el CyberSecurity Bootcamp 2026 organizado por INCIBE con su taller práctico sobre DFIR (Digital Forensics and Incident Response), mostrando herramientas y artefactos esenciales para la respuesta ante incidentes. Este tipo de eventos fortalecen la comunidad y aumentan la preparación frente a amenazas emergentes. Conoce más sobre el evento y recursos clave aquí 👉 djar.co/qAu7M

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
CVE-2026-14266 is a high-severity heap overflow in 7-Zip’s XZ decoder that could run code when a user opens a crafted archive. Version 26.02 fixes it.
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
Faille dans 7-Zip : pourquoi vous devriez installer la version 26.02 sans attendre ⚠️ Une faille de sécurité importante estampillée CVE-2026-14266 a été patchée. Plus d'infos par ici : - www.it-connect.fr/7-zip-26-02-... #7zip #infosec #cybersecurity
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
A critical heap-based buffer overflow vulnerability, tracked as CVE-2026-14266, was discovered in 7-Zip’s XZ archive handler. An attacker could achieve […]
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
7-Zip CVE-2026-14266 is a high-severity heap overflow in XZ handling that could allow code execution when a crafted archive is opened. Fixed in 7-Zip 26.02. #7Zip #CVE2026 #XZ
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • F5
  • NGINX Plus

15 Jul 2026
Published
16 Jul 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.83%

KEV

Description

A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions. An unauthenticated attacker along with conditions beyond their control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Impact: This vulnerability may allow remote attackers to cause a denial-of-service (DoS) on the NGINX system or to possibly trigger a code execution. There is no control plane exposure; this is a data plane issue only.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 8 Posts
  • 5 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Postei no BR-Linux to avisando, e é sobre hora do upgrade.

FALHA CRÍTICA NO NGINX PODE TIRAR O SERVIDOR DO AR E ESTÁ NO CÓDIGO HÁ 15 ANOS

A vulnerabilidade CVE-2026-42533 no NGINX pode permitir que um invasor remoto e não autenticado sobrecarregue um buffer, levando a uma negação de serviço (DoS) e, teoricamente, à possibilidade de execução remota de código.

br-linux.org/2026/01/falha-cri

  • 2
  • 1
  • 0
  • 3h ago
Profile picture fallback

15-Year-Old NGINX Vulnerability Lets Attackers Crash Workers and May Enable Remote Code Execution

NGINX has long been regarded as one of the most reliable and high-performance web servers on the Internet, powering millions of websites, APIs, reverse proxies, Kubernetes ingress controllers, and cloud-native applications. That reputation makes the disclosure of CVE-2026-42533 particularly significant. Rather than affecting a recently introduced feature, the flaw traces back to March 2011, when regular expression support was added to the map directive. For over 15 years, a subtle bug inside […]

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

En las últimas 24 horas, se detectaron vulnerabilidades críticas en WordPress, 7-Zip, Foxit PDF Reader y NGINX que permiten ejecución remota de código y escalada de privilegios, mientras una avanzada campaña rusa con el RAT Starland intensifica amenazas; la actualización inmediata y la vigilancia continua son esenciales. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 20/07/26 📆 |====

🔓 EXPLOIT BROKERS PAGAN $500,000 POR UNA RCE EN WORDPRESS

Se ha detectado una vulnerabilidad crítica que permite la ejecución remota de código (RCE) en WordPress. La publicación se retrasó estratégicamente para que los administradores pudieran actualizar sus sistemas sin riesgo durante el fin de semana. Si utilizas WordPress, es vital que verifiques la seguridad de tu instancia con la herramienta disponible en wp2shell.com/. Mantente alerta para proteger tu sitio frente a posibles ataques. Más detalles y cómo verificar tu seguridad aquí 👉 djar.co/YsbS

🛡️ NUEVA VULNERABILIDAD EN 7-ZIP PUEDE EJECUTAR CÓDIGO AL EXTRAER ARCHIVOS XZ MANIPULADOS

Se ha identificado CVE-2026-14266, un desbordamiento de pila de alta gravedad en el decodificador XZ de 7-Zip que permite la ejecución remota de código al abrir archivos comprimidos maliciosos. La versión 26.02 ya incluye el parche que corrige esta falla crítica. Recomendamos actualizar inmediatamente para evitar compromisos de seguridad. Infórmate y actualízate aquí 👉 djar.co/QRKdfM

⚠️ ESCALADA DE PRIVILEGIOS EN FOXIT PDF READER PERMITE CONTROL TOTAL DEL SISTEMA

Un grave fallo de seguridad (CVE-2026–57239) en Foxit PDF Reader permite a usuarios sin privilegios elevar permisos hasta NT AUTHORITY\SYSTEM, otorgando control total sobre el sistema afectado. Esta vulnerabilidad pone en riesgo entornos corporativos y personales, por lo que actualizar y revisar las políticas de seguridad es urgente. Conoce cómo protegerte aquí 👉 djar.co/r0Zuj

🔥 CVE-2026-42533: FALLA CRÍTICA EN NGINX PERMITE EJECUCIÓN REMOTA DE CÓDIGO

F5 ha publicado un parche para corregir un bug muy serio en NGINX que puede provocar caídas del servidor y, en casos extremos, ejecución remota de código mediante solicitudes HTTP manipuladas. Los administradores de sistemas deben aplicar esta actualización cuanto antes para evitar intrusiones y mantener la integridad de sus servicios web. Descubre los pasos para mitigar el riesgo aquí 👉 djar.co/g35e9

🚨 UAT-11795: NUEVO RAT STARLAND Y C2 PERSONALIZADO EN CAMPAÑA FINANCIADA POR UN ADVERSARIO RUSO

Cisco Talos alerta sobre UAT-11795, una campaña avanzada que utiliza el RAT Starland junto a un comando y control (C2) exclusivo, dirigida contra objetivos en EE. UU. y Europa desde junio de 2025. Este adversario sofisticado refuerza la necesidad de fortalecer la detección y respuesta ante amenazas con vigilancia continua y soluciones actualizadas. Obtén detalles para proteger tu entorno aquí 👉 djar.co/zqN7

📅 RESUMEN SEMANAL DE CIBERSEGURIDAD 13/07/26 - 19/07/26: DFIR Y TALLERES PRÁCTICOS EN INCIBE

La semana pasada, Lorenzo Martínez destacó en el CyberSecurity Bootcamp 2026 organizado por INCIBE con su taller práctico sobre DFIR (Digital Forensics and Incident Response), mostrando herramientas y artefactos esenciales para la respuesta ante incidentes. Este tipo de eventos fortalecen la comunidad y aumentan la preparación frente a amenazas emergentes. Conoce más sobre el evento y recursos clave aquí 👉 djar.co/qAu7M

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
F5 patches CVE-2026-42533, a regex map heap overflow that crashes nginx workers and may allow RCE in specific configurations.
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Une faille vieille de 15 ans découverte dans NGINX -> CVE-2026-42533 Cette faille de sécurité critique expose les serveurs Web à un déni de service, et elle pourrait même permettre une exécution de code à distance. Plus d'infos👇 - www.it-connect.fr/nginx-cve-20... #nginx #infosec
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
F5 patched a critical nginx heap buffer overflow (CVE-2026-42533) rated 9.2 on CVSS v4, affecting versions since 2011. The flaw […]
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
F5 shipped fixes for CVE-2026-42533, a configuration-dependent nginx heap buffer overflow enabling remote DoS and possible RCE under certain ASLR conditions.
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • WordPress
  • WordPress

17 Jul 2026
Published
18 Jul 2026
Updated

CVSS v3.1
MEDIUM (5.9)
EPSS
4.03%

KEV

Description

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

Statistics

  • 11 Posts
  • 34 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

⚠️ 📢 #Sicherheitswarnung: WordPress – Schwachstellen erlauben "Remote Code Execution"

Am 17. Juli 2026 wurde seitens #Wordpress eine Aktualisierung bekannt gegeben, die zwei #Schwachstellen in der Wordpress-Software behebt.

❗️ Die beiden Schwachstellen CVE-2026-60137 und CVE-2026-63030 ermöglichen einem nicht authentifizierten, entfernten Angreifer Code zur Ausführung zu bringen.

Mehr dazu hier: 👉️ bsi.bund.de/dok/1203360

@certbund

  • 15
  • 2
  • 0
  • 9h ago
Profile picture fallback

⚠️ Si vous administrez un site WordPress ou si vous connaissez quelqu’un qui en gère un faites passer l’information.

Une vulnérabilité critique baptisée WP2Shell touche directement le cœur de WordPress.

Cette fois, il ne s’agit pas d’un plugin abandonné ou d’un thème douteux : une installation standard peut être attaquée à distance, sans compte utilisateur, sans mot de passe et sans authentification préalable.

WP2Shell combine deux failles, CVE-2026-60137 et CVE-2026-63030, permettant à un attaquant d’exécuter du code sur le serveur et donc, potentiellement, de prendre le contrôle du site.

-> Des tentatives d’exploitation et des compromissions ont déjà été observées dans la nature.

Sont notamment concernées les versions :

➡️ WordPress 6.9.0 à 6.9.4
➡️ WordPress 7.0.0 à 7.0.1

Les correctifs sont disponibles dans les versions 6.9.5 et 7.0.2. WordPress a activé des mises à jour automatiques forcées en raison de la gravité de la faille, mais il ne faut pas supposer qu’elles ont forcément fonctionné : elles peuvent avoir été désactivées, bloquées par l’hébergeur ou empêchées par une configuration particulière.

À faire rapidement:

✅ vérifier la version réellement installée ;
✅ mettre WordPress à jour vers 6.9.5 ou 7.0.2 au minimum ;
✅ confirmer que la mise à jour s’est correctement terminée ;
✅ vérifier les comptes administrateurs, les fichiers récemment modifiés et les journaux du serveur ;
✅ rechercher d’éventuels fichiers PHP, plugins ou utilisateurs inconnus ;
✅ s’assurer que des sauvegardes propres et récentes sont disponibles.

En attendant la mise à jour, l’accès anonyme aux routes REST suivantes peut également être bloqué au niveau du WAF ou du serveur web :

/wp-json/batch/v1
?rest_route=/batch/v1

Point important : installer le correctif empêche une nouvelle exploitation, mais ne supprime pas une éventuelle compromission déjà présente. Si le site est resté exposé, une vérification minimale est donc nécessaire, même après la mise à jour.

Un site WordPress « qui fonctionne encore » n’est pas nécessairement un site sain : les attaquants cherchent souvent à rester discrets pour installer une porte dérobée, détourner le trafic, diffuser du spam ou préparer d’autres attaques...

🔍 wp2shell.com , pour vérifier si votre site est vulnérable.

Dans les news:
"WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin"
👇
korben.info/wp2shell-exploits-

💬
⬇️
infosec.pub/post/49724018

  • 7
  • 3
  • 0
  • 10h ago
Profile picture fallback

⚠️Alerte CERT-FR⚠️

Les vulnérabilités CVE-2026-60137 et CVE-2026-63030 affectent WordPress et permettent une exécution de code arbitraire à distance non authentifiée.
Une preuve de concept est disponible.

cert.ssi.gouv.fr/alerte/CERTFR

  • 4
  • 1
  • 1
  • 10h ago
Profile picture fallback

wp2shell (CVE-2026-63030, CVE-2026-60137) allows unauth RCE in WordPress core (HIGH severity). Active exploitation reported. Patch to 6.9.5, 7.0.2, or 6.8.6. Block REST API batch endpoint if needed. Details: radar.offseq.com/threat/wp2she

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-63030, CVE-2026-60137) #WordPress Core Unauthenticated RCE via wp2shell". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 1
  • 0
  • 0
  • 14h ago
Profile picture fallback
In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
夜行性インコさんのまとめ。即対応ですなこれは:WordPress Coreの脆弱性 CVE-2026-63030 / CVE-2026-60137 (通称「wp2shell」)についてまとめてみた - piyolog piyolog.hatenadiary.jp/entry/2026/0...
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
Critical WordPress core flaws, CVE-2026-60137 and CVE-2026-63030, can be chained for unauthenticated access, SQL injection, and possible RCE. CERT-AGID reports suspicious API activity and new admin accounts. #WordPress #CERTAGID #Italy
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
WP2Shell flaws CVE-2026-60137 and CVE-2026-63030 are being exploited in the wild. Chaining them can enable unauthenticated remote code execution on stock WordPress installs. #WordPress #Cloudflare #CVE-2026-60137
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • ServiceNow
  • ServiceNow AI Platform

13 Jul 2026
Published
14 Jul 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
0.51%

KEV

Description

ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow platform. ServiceNow addressed this vulnerability by deploying a security update to hosted instances. Relevant security updates have also been provided to ServiceNow self-hosted customers and partners. Further, the vulnerability is addressed in the listed patches and family releases, which have been made available to hosted and self-hosted customers, as well as partners. We are not currently aware of exploitation against ServiceNow instances. We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.

Statistics

  • 5 Posts
  • 8 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Una vulnerabilidad crítica en la ejecución del código de ServiceNow ahora se explota en ataques.

Según la empresa de inteligencia sobre amenazas Defused, los atacantes han comenzado a explotar una vulnerabilidad crítica (CVE-2026-6875) en la plataforma de IA de ServiceNow.

bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback

Attackers are actively exploiting a critical pre-auth RCE vulnerability in ServiceNow AI Platform this week.
helpnetsecurity.com/2026/07/20
#cybersecurity #servicenow #vulnerability

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
  • 3
  • 5
  • 0
  • 10h ago
Profile picture fallback
⚠️ CVE-2026-6875 (Critical): pre-auth sandbox-escape RCE in ServiceNow AI Platform lets unauthenticated attackers run code. Patched July 13; reports of in-the-wild exploitation. Update now, prioritise self-hosted. Query: technology="ServiceNow"
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Critical ServiceNow AI Platform flaw CVE-2026-6875 is being actively exploited, enabling pre-auth sandbox escape and remote code execution. Patches are available for hosted and self-hosted instances. #ServiceNow #CVE20266875 #SearchlightCyber
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • SonicWall
  • SMA1000

14 Jul 2026
Published
16 Jul 2026
Updated

CVSS
Pending
EPSS
1.27%

Description

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

Statistics

  • 5 Posts
  • 7 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

RE: social.bund.de/@bsi/1169235087

Update: Das IT-Sicherheitsunternehmen Rapid7 hat weitere Details zu den #Schwachstellen und beobachteten Angriffen auf SMA1000 Appliances veröffentlicht.

Neben den technischen Details wurde auch ein Proof-of-Concept Exploit veröffentlicht, welches die Schwachstelle CVE-2026-15409 ausnutzt, um ohne Authentifizierung Code auf verwundbaren SMA1000 Appliances auszuführen. Eine Ausnutzung durch weitere Akteure ist durch das öffentliche Proof-of-Concept wahrscheinlich.

👉 bsi.bund.de/dok/1203248

  • 4
  • 2
  • 0
  • 5h ago
Profile picture fallback

📰 SonicWall Warns of Two Zero-Days in SMA 1000 Under Active Exploit

SonicWall urges immediate patching for two actively exploited zero-days (CVE-2026-15409, CVE-2026-15410) in SMA 1000 series appliances. Flaws are chained for unauthenticated RCE. Both added to CISA KEV. #ZeroDay #SonicWall #InfoSec

🌐 cyber[.]netsecops[.]io

🔗 cyber.netsecops.io/articles/so

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
SonicWall SMA1000にゼロデイ 脆弱性既にサイバー攻撃へ悪用(CVE-2026-15409, CVE-2026 ... 合同会社ロケットボーイズ ... ランサムウェア 感染の可能性 店舗とオンラインストアは通常営業. 株式会社ファイブフォックスは2026年7月14日、本社サーバーの一部がランサムウェアに感染し ... rocket-boys.co.jp/security-mea...
  • 0
  • 1
  • 0
  • 6h ago
Profile picture fallback
SonicWall SMA1000にゼロデイ 脆弱性既にサイバー攻撃へ悪用(CVE-2026-15409, CVE-2026-15410) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #脆弱性
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
~Checkpoint~ Microsoft, WordPress, SonicWall patch actively exploited CVEs; Jscrambler npm supply chain attack steals credentials. - IOCs: CVE-2026-56164, CVE-2026-63030, CVE-2026-15409 - #Ransomware #ThreatIntel #Vuln
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • meshtastic
  • firmware

19 Jul 2026
Published
19 Jul 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.28%

KEV

Description

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a malformed character encoding can render other radios unusable over BLE when managed through the iOS app. The malformed name does not need to be maliciously crafted — it can arise from ordinary buffer truncation and has been observed occurring naturally in the wild. At least one code path could place a null terminator in the middle of a multibyte sequence, leaving a malformed User.long_name in the node database. The problem surfaced downstream: the iOS app enforced encoding validation and therefore cannot parse a node database once it contains a poisoned entry. This caused BLE sync to enter a fail/retry loop, resulting in loss of control over the affected device. For a typical user managing their radio with the iOS app, the device becomes effectively unusable until the poisoned node ages out of the on-device database, or unless they have an alternate management path (e.g., the Python CLI, which can be used to identify and remove the offending entries manually). Because the malformed name propagates through the mesh, the temporary presence of a single affected node can degrade BLE management for iOS users across a wide geographical area for an extended period. Less technical users have no straightforward recovery path. Starting in version 2.7.23.b246bcd, the firmware has added input sanitization and regression tests demonstrating recovery for already-poisoned devices. The apps have also taken steps to ensure more graceful handling of malformed encoding sequences as well.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback

CVE-2026-42566 - DoS in Meshtastic via malformed User.long_name. BLE crash on iOS. CVSS 7.5. Unpatched. Review your mesh setup. #CVE #IoT #infosec

valtersit.com/cve/CVE-2026-425

  • 0
  • 1
  • 0
  • 10h ago

Overview

  • keras-team
  • keras-team/keras

19 Jul 2026
Published
20 Jul 2026
Updated

CVSS v3.0
HIGH (7.8)
EPSS
0.20%

KEV

Description

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes `torch.load(..., weights_only=False)` without requiring an explicit unsafe opt-in, such as a `safe_mode=False` parameter. When called outside a `SafeModeScope(True)` context, the absence of an ambient safe mode state permits unsafe deserialization by default. This issue can lead to arbitrary code execution if untrusted Keras layer configurations are processed using this method. The vulnerability arises because the method does not enforce safe deserialization practices unless explicitly guarded by Keras safe mode.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-12484 - Insecure Deserialization in Keras-Team. Unsafe PyTorch pickle loading in torch.load via TorchModuleWrapper.from_config. CVSS 7.8. Patch unknown, restrict usage immediately. #CVE #infosec #AIsecurity

valtersit.com/cve/CVE-2026-124

  • 1
  • 1
  • 0
  • 20h ago
Profile picture fallback

keras-team/keras v3.15.0 suffers a HIGH severity deserialization flaw (CVE-2026-12484). Unsafe use of TorchModuleWrapper.from_config can lead to code execution via malicious PyTorch pickle files. Enforce safe deserialization or avoid untrusted configs. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
20 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.46%

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

Geopolitical: US forces launched new airstrikes against Iran following military deaths in Jordan; shipping in the Strait of Hormuz is disrupted after a cargo ship attack.

Technology: The EU ordered Google to open Android to rival AI assistants and share search data. Cvent announced a $1 billion investment in AI for event management.

Cybersecurity: A critical Microsoft SharePoint Server RCE zero-day (CVE-2026-58644) is being actively exploited. A federal audit revealed significant gaps in US aviation cybersecurity oversight.

#AnonNews_irc #Cybersecurity #Technology

  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback

⚠️ CRITICAL THREAT: CVE-2026-58644 targets Microsoft SharePoint via deserialization. Active exploitation is verified. Is your perimeter secured? Get the forensic detection queries and hardening playbooks you need to defend your infrastructure now. thecybermind.co/9pxn

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • meshtastic
  • firmware

19 Jul 2026
Published
20 Jul 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.00%

KEV

Description

Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml workflow is triggered by pull_request_target and multiple jobs check out the attacker's fork code and execute it with access to repository secrets and elevated GITHUB_TOKEN permissions. No approval gate exists. Pull requests from external users with author_association: "NONE" triggered the CI workflow automatically. The workflow directly executes attacker-controlled files from the fork checkout. This issue could have resulted in supply chain compromise, self-hosted runner compromise, and/or repository takeover for the repo. This issue is separate from GHSA-6mwm-v2vv-pp96, which addressed a command injection via github.head_ref in the setup job of the same workflow. That fix correctly moved to environment variables. However, the more critical fork checkout vulnerability across the check, build, and build-debian-src jobs was not addressed. Version 2.7.21.1370b23 contains a patch for thie issue.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-44359 - Critical CI/CD command injection in Meshtastic. CVSS 10. Unpatched. Attacker code executed with repo secrets access via pull_request_target. No approval gate. Disable workflow or restrict PR access immediately. #CVE #infosec #Meshtastic

valtersit.com/cve/CVE-2026-443

  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback

Meshtastic firmware (pre-2.7.21.1370b23) has a CRITICAL code injection flaw (CVE-2026-44359) in GitHub Actions (main_matrix.yml), risking repo secrets & supply chain compromise. Patch ASAP. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 19h ago
Showing 1 to 10 of 40 CVEs