Related Threat Clusters
-
Critical RCE and SQL Injection Vulnerabilities in WordPress Disclosed
On July 17, 2026, WordPress disclosed two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, affecting its core software. CVE-2026-63030 is a remote code execution (RCE) vulnerability in the REST API, while…
6 articles · Updated July 17, 2026 -
CISA Alerts on Actively Exploited SQL Injection Vulnerabilities in WordPress
CISA has identified two critical SQL injection vulnerabilities in WordPress Core, CVE-2026-60137 and CVE-2026-63030, as actively exploited in the wild. Both vulnerabilities were published on July 17, 2026, and added to…
2 articles · Updated July 22, 2026 -
Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as…
78 articles · Updated July 20, 2026 -
Critical RCE Vulnerability in BeyondTrust Software Requires Immediate Patching
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
1495 articles · Updated February 9, 2026 -
Critical RCE Vulnerability in BeyondTrust Remote Support and PRA
A critical pre-authentication remote code execution vulnerability, CVE-2026-1731, has been identified in BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA). This vulnerability…
717 articles · Updated February 7, 2026
Recent Intelligence Reports
- CVE-2026-63030 — nvd.nist.gov · July 23, 2026
- CISA Warns of WordPress Core SQL Injection Vulnerability Actively Exploited in the Wild — Cybersecuritynews · July 22, 2026
- Cloudflare has added rules to its Web Application Firewall (WAF) — blog.cloudflare.com · July 21, 2026
- Wp2shell — www.vulncheck.com · July 21, 2026
- Wp2shell — www.hacktron.ai · July 21, 2026
- Attackers pummel critical WordPress vuln to create all sorts of mischief — Theregister · July 20, 2026
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover — Darkreading · July 20, 2026
- wp2shell: WordPress RCE (CVE-2026-63030) — Secra.Es · July 20, 2026