This is a serious vulnerability affecting all supported WordPress versions. It can be exploited by any unauthenticated attacker, and a working proof of concept is available. However, to achieve remote code execution an attacker must trick a WordPress admin into opening a malicious link as part of a social engineering attack. This vulnerability is patched in WordPress 7.0.3 (released Aug 6, 2026).
Vulnerability intelligence
Updated 28 minutes ago
FeedsTrending now
CVEs trending on social media within the last 24 hours
Hypemeter
Current score
Not much to see here
1
CVE-2026-100520 Published Sep 26, 2026Hype score
16
high 8.7
CVE-2026-100520 is a path traversal vulnerability affecting Laranode, a multi-tenant application, in versions prior to 1.2.1. The issue resides in the `POST /filemanager/upload-file` endpoint, which is used for file management operations. It allows authenticated users to write arbitrary files outside of their designated home directory by manipulating the file upload path. To exploit this vulnerability, an attacker can input directory traversal sequences into the `path` parameter during a file upload. This allows them to write PHP files into the web roots of other tenants, leading to arbitrary code execution under the context of those tenants. The vulnerability has been resolved in Laranode version 1.2.1.
2
CVE-2026-40281 Published May 6, 2026Hype score
15
critical 10.0
CVE-2026-40281 is a vulnerability affecting Gotenberg, a Docker-powered stateless API used for PDF file processing, in versions 8.30.1 and earlier. The issue resides in the metadata write endpoint, which validates metadata keys for control characters but leaves metadata values unsanitized. By inserting a newline character into a metadata value, an attacker can split the ExifTool stdin line into two separate arguments. This allows the injection of arbitrary ExifTool pseudo-tags, such as `-FileName`, `-Directory`, `-SymLink`, and `-HardLink`, bypassing a previous key-sanitization fix introduced in version 8.30.1. Exploitation of this flaw allows an unauthenticated attacker to manipulate files within the container filesystem. Specifically, they can rename or move any PDF currently being processed to an arbitrary path, overwrite existing files, or create symlinks and hard links at arbitrary locations.
3
CVE-2026-96940 Published Oct 2, 2026Hype score
11
high 8.8
CVE-2026-96940 is an elevation of privilege vulnerability in Microsoft Exchange Server stemming from weak authorization mechanisms. An authenticated attacker can exploit this flaw over a network to elevate their privileges without requiring any user interaction. Successful exploitation allows the attacker to access other users' mailboxes within the same organization, read email messages and attachments, modify server configurations, and disrupt service availability. The vulnerability affects on-premises deployments, including Microsoft Exchange Server 2016 Cumulative Update 23, Exchange Server 2019 Cumulative Updates 14 and 15, and Exchange Server Subscription Edition RTM. Microsoft discovered the flaw internally and reported no evidence of active exploitation or public proof-of-concept exploits. To address the issue, Microsoft released the September 2026 V2 security updates. Exchange Online customers are already protected and do not require further action.
Known exploited
Sourced from CISA's Known Exploited Vulnerability (KEV) catalog.
- CVE-2026-88779 Published Oct 4, 2026
high 8.7
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
- CVE-2026-102490 Published Sep 30, 2026
Hype score
6
critical 9.4
Exploit known
CVE-2026-102490 is a local privilege escalation vulnerability affecting Zammad, an open-source helpdesk and ticketing system. The flaw is present in all versions of the software, including the latest alpha releases, and allows a local user with access to the `zammad` account to bypass permission checks and escalate their privileges to `root`. This unauthorized access enables the execution of privileged operations, allowing an attacker to modify system files, install software, or access other parts of the host system. The vulnerability was highlighted in reports after being chained with CVE-2026-102489 in an attack against the Dutch Institute for Vulnerability Disclosure (DIVD). In that incident, attackers utilized an autonomous, agentic AI to exploit both flaws, allowing them to hijack sessions, execute code remotely, and escalate privileges to root within seconds. Following evidence of active exploitation in the wild, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-102490 to its Known Exploited Vulnerabilities (KEV) catalog, requiring organizations to apply the necessary updates.
- CVE-2026-102489 Published Sep 30, 2026
Hype score
7
critical 9.4
Exploit known
CVE-2026-102489 is a session hijacking and remote code execution vulnerability affecting Zammad, an open-source helpdesk and customer support ticketing system. The flaw allows unauthenticated attackers to leak user sessions and remotely execute malicious code as the local `zammad` user. It affects Zammad versions 6.3.0 through 6.5.4 in an exploitable state. While the vulnerability is present in versions 7.0.0 through 7.1.3, environmental conditions prevent its exploitation in those later releases. The vulnerability gained public attention after being exploited as a zero-day alongside CVE-2026-102490, a local privilege escalation flaw, in an automated, agentic AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD) in September 2026. By chaining these two vulnerabilities, the automated agent was able to hijack sessions, execute code, and escalate privileges to root within seconds. To mitigate the issue, users are advised to upgrade to Zammad version 7 or take vulnerable instances offline.
Insights
See moreOur Security Team's most recent CVE analysis
- Link to CVE page
CVE-2026-64638
high 8.9
Intruder Insights
Updated Sep 10, 2026
- Link to CVE page
CVE-2026-50522
critical 9.8
Exploit known
Intruder Insights
Updated Jul 21, 2026
This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsofts 'Patch Tuesday' security rollup.
A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.
- Link to CVE page
CVE-2026-63030
critical 9.8
Exploit known
Intruder Insights
Updated Jul 21, 2026
This is one of two vulnerabilities in a combined chain that allows remote code execution on any stock WordPress installation. CVE-2026-63030 is the entry point — a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check. When combined with CVE-2026-60137, the attacker gains the ability to read any data from the WordPress database with a single HTTP request. An exploit chain has been demonstrated which combines both of these bugs to achieve code execution.
WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 are affected. Update to WordPress 6.9.5 or 7.0.2 immediately. No plugins, user interaction, or non-default configuration is required to exploit. Given WordPress powers approximately 43% of all websites, the attack surface is enormous.
WordPress Core contains a pre-authentication route confusion vulnerability in the REST API batch endpoint that, combined with CVE-2026-60137, allows remote code execution.