news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-63030

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
9.8 Critical
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Risk score
100.0
Known exploited
CISA KEV
Published
2026-07-17
Status
Analyzed

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

Weaknesses

CWE-436

Coverage 8

ransomware

Don’t swing at everything

This week’s Threat Source newsletter highlights a new Rust-based remote access trojan (RAT), “msaRAT,” deployed by the Chaos ransomware group. The RAT leverages Chrome DevTools Protocol (CDP) to establish a covert comman…

Cisco Talos · Jul 23, 2026 High

Advisories and references