Critical RCE Vulnerability in WordPress Core (CVE-2026-63030)
A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.
Read ArticleCurrent CVEs, vendor advisories, and specific recommendations for addressing critical security vulnerabilities.
A critical vulnerability (CVE-2026-63030) in WordPress Core allows unauthenticated remote code execution. Versions up to 7.0.1 are affected. Action is required.
Read Article
Analysis of the critical RCE vulnerability CVE-2026-9726 (AlternativeCommerce Basket) and the information leak CVE-2026-10768 (LocalGov Workflows) in Drupal.
Read Article
Microsoft Entra ID is introducing passkeys as the default. At the same time, critical zero-day vulnerabilities were disclosed in SharePoint (CVE-2026-56164), AD FS (CVE-2026-55040, CVSS 9.1), and Exchange (CVE-2026-55008). Updates are available.
Read Article
Analysis of Critical Vulnerabilities in SAP Commerce Cloud and NetWeaver (CVE-2026-44761 CVSS 9.1, CVE-2026-44747, CVE-2026-27690, CVSS 9.9). OAuth2 credentials, NetWeaver ABAP, and Approuter are affected. Details and mitigation steps.
Read Article
Two critical SSRF vulnerabilities (CVE-2026-15378, CVE-2026-15143) with a CVSS score of 9.3 in Red Hat OpenShift AI allow attackers to gain unauthorized access to cloud and Kubernetes systems.
Read Article
Phishing campaigns exploit the Microsoft 365 OAuth device code flow to take over accounts. The ARToken Kit and a Ghost phishing variant bypass standard MFA. Analysis and protective measures.
Read Article
Critical RCE vulnerability (CVSS 9.8) in the WordPress plugin WPFunnels: CVE-2026-14345 allows unauthenticated code execution. Update to version 3.12.8.
Read Article
Critical vulnerabilities in Plesk (CVE-2026-48614, CVE-2026-56843, CVSS 9.9) allow for privilege escalation and password disclosure. A patch is available for CVE-2026-56843.
Read Article
Analysis of critical vulnerabilities in Adobe ColdFusion (CVSS 10.0), including CVE-2026-48316 and CVE-2026-48282. CISA warns of active exploitation. Patches are available.
Read Article
Three critical Gitea vulnerabilities: CVE-2026-58426 (data access), CVE-2026-20896 (account takeover), CVE-2026-22874 (SSRF). Updating to version 1.26.4 is recommended.
Read Article
CVE-2026-9725 (CVSS 9.1) in the WordPress plugin Printcart allows unauthenticated deletion of arbitrary files. Update to version 2.5.3.
Read Article
CVE-2026-57677 (CVSS 9.8) in the Novalnet plugin for WooCommerce allows unauthenticated store takeover. Update to version 12.10.4.
Read Article
CVE-2026-37106 (DokuWiki): Not RCE, but a controversial account creation feature—only when self-registration is enabled (default: disabled). Assessment & Protection.
Read Article