threat-intel WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) A critical WordPress webshell vulnerability (CVE-2026-63030) is being actively exploited. This vulnerability, stemming from a SQL injection flaw in the WordPress Core REST API, allows unauthenticated remote code execution. The vulnerability was initially announced without a CVE number, but is now actively being used to… SANS Internet Storm Center · Jul 20, 2026 Critical CVE-2026-63030sql injectionwebshellwordpress
threat-intel Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites A cybercrime crew exposed its operations – including tools, logs, and target lists – after leaving a server open for three weeks. The WP-SHELLSTORM operation, which involved planting webshells on vulnerable WordPress and… The Hacker News · Jul 10, 2026 High CVE-2026-3844CVE-2021-29441CVE-2026-3300CHwebshellvulnerabilityexploit
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication