This is a serious vulnerability affecting all supported WordPress versions. It can be exploited by any unauthenticated attacker, and a working proof of concept is available. However, to achieve remote code execution an attacker must trick a WordPress admin into opening a malicious link as part of a social engineering attack. This vulnerability is patched in WordPress 7.0.3 (released Aug 6, 2026).
Vulnerability intelligence
Updated 27 minutes ago
FeedsTrending now
CVEs trending on social media within the last 24 hours
Hypemeter
Current score
Not much chatter
1
CVE-2026-1731 Published Feb 6, 2026Hype score
11
critical 9.9
Exploit known
SSHBeyondtrustNetworkAPITunneling protocolOTPort (80)Port (22)HTTPBeyondTrust Remote SupportCVE-2026-1731 is identified as a pre-authentication remote code execution vulnerability impacting BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) products. This flaw, categorized as an operating system command injection, allows an unauthenticated remote attacker to execute operating system commands in the context of the site user. The vulnerability can be exploited by sending specially crafted requests, and successful exploitation does not require any user interaction or prior authentication. BeyondTrust has released updates to address this issue, with patches available for Remote Support versions 25.3.2 and later, and Privileged Remote Access versions 25.1.1 and later.
2
CVE-2026-61500 Published Jul 13, 2026Hype score
11
critical 9.3
Rejetto HFSCVE-2026-61500 describes a vulnerability affecting Rejetto HFS versions 3.0.0 through 3.2.0. The flaw stems from the application's use of the non-cryptographic `Math.random()` generator to create session-cookie signing keys. Additionally, outputs from this same generator are disclosed to unauthenticated clients during the login process. A remote attacker can exploit this by collecting a small number of login responses to reconstruct the state of the `Math.random()` generator. This allows them to recover the session-cookie signing key and subsequently forge a valid administrator session cookie. With a forged administrator session, an attacker can gain full administrative access and achieve remote code execution via the `server_code` configuration feature.
3
CVE-2026-102489 Published Sep 30, 2026Hype score
7
critical 9.4
Exploit known
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
Known exploited
Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.
- CVE-2026-102490 Published Sep 30, 2026
Hype score
7
critical 9.4
Exploit known
All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
- CVE-2026-102489 Published Sep 30, 2026
Hype score
7
critical 9.4
Exploit known
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.
- CVE-2026-76504 Published Sep 30, 2026
Hype score
2
critical 9.8
Exploit known
Cisco Catalyst SD-WAN ManagerCVE-2026-76504 is an API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The issue arises from the improper handling of URI/URL encoding in HTTP requests. An unauthenticated, remote attacker can exploit this flaw by sending a crafted HTTP request to the affected system's API. This allows the request to bypass an authentication rule designed to restrict access to a specific API endpoint, granting the attacker access to the API with administrative privileges without requiring any credentials. The vulnerability affects Cisco Catalyst SD-WAN Manager regardless of its system configuration. Cisco discovered the issue through a customer support case and confirmed that it is being actively exploited in the wild. Consequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76504 to its Known Exploited Vulnerabilities (KEV) catalog on September 30, 2026. Cisco has released software updates to address the flaw, and because no workarounds are available, organizations are advised to apply the patches to secure their systems.
Insights
See moreOur Security Team's most recent CVE analysis
- Link to CVE page
CVE-2026-64638
high 8.9
Intruder Insights
Updated Sep 10, 2026
- Link to CVE page
CVE-2026-50522
critical 9.8
Exploit known
Intruder Insights
Updated Jul 21, 2026
This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsofts 'Patch Tuesday' security rollup.
A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.
- Link to CVE page
CVE-2026-63030
critical 9.8
Exploit known
Intruder Insights
Updated Jul 21, 2026
This is one of two vulnerabilities in a combined chain that allows remote code execution on any stock WordPress installation. CVE-2026-63030 is the entry point — a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check. When combined with CVE-2026-60137, the attacker gains the ability to read any data from the WordPress database with a single HTTP request. An exploit chain has been demonstrated which combines both of these bugs to achieve code execution.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are affected. Update to WordPress 6.9.5 or 7.0.2 immediately. No plugins, user interaction, or non-default configuration is required to exploit. Given WordPress powers approximately 43% of all websites, the attack surface is enormous.
WordPress Core contains a pre-authentication route confusion vulnerability in the REST API batch endpoint that, combined with CVE-2026-60137, allows remote code execution.