WordPress Core Pre-Auth RCE (wp2shell): Update Every 6.9 and 7.0 Site Now — CVE-2026-63030
WordPress Core 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to a pre-authentication RCE chain that requires no login, no plugins, and no special configuration.…
Security research, penetration testing, CVE analysis, PCI-DSS compliance, and defensive programming techniques for web applications.
69 ARTICLES
WordPress Core 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to a pre-authentication RCE chain that requires no login, no plugins, and no special configuration.…
Gravity Forms 2.10.4 and earlier allow an unauthenticated attacker to read any file the web server process can access — including wp-config.php and .env — and…
F5 shipped three out-of-band NGINX patches on July 15, 2026, alongside the 1.31.3 mainline release. The headline flaw, CVE-2026-42533, is a heap buffer…
Adobe shipped a second Priority 1 ColdFusion advisory in two weeks, fixing 13 flaws - eight of them Critical. The lead bug, CVE-2026-48318, is a path traversal…
Microsoft patched CVE-2026-55040 on July 14, 2026 - a SharePoint Server flaw that lets an unauthenticated attacker forge JWT tokens and impersonate any user,…
SonicWall confirmed that two zero-day flaws in SMA 1000 remote access appliances are under active exploitation. CVE-2026-15409 is a CVSS 10.0 unauthenticated…
Microsoft shipped fixes for 570 vulnerabilities in July 2026, including three zero-days - two already exploited in the wild and one publicly disclosed.…
CVE-2026-57807 is a CVSS 9.8 authentication bypass in the miniOrange OAuth Single Sign On - SSO (OAuth Client) WordPress plugin, versions up to and including…
SAP released 16 fixes on July 2026 Patch Day, three of them Critical. CVE-2026-44747 is a CVSS 9.9 memory corruption flaw in NetWeaver AS ABAP that any…
Broadcom patched seven vulnerabilities in VMware Avi Load Balancer on July 14, 2026, led by CVE-2026-47865 - a Critical CVSS 9.8 authentication bypass that…
Two CVSS 10.0 Joomla extension flaws - CVE-2026-48939 in iCagenda and CVE-2026-56291 in Balbooa Forms - let any anonymous visitor upload a PHP web shell and…
Zimbra shipped Collaboration Suite 10.1.19 to fix a critical stored XSS in the Classic Web Client, the default Ajax webmail interface on millions of…