CVE Tools

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

The Hacker NewsBy The Hacker News

RoundupWordPress CoreSMA1000 Series gateways

Our summary

A critical remote code execution vulnerability in WordPress Core has been actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary code on vulnerable installations. The flaw, known as wp2shell, combines two issues—CVE-2026-63030 and CVE-2026-60137—to enable full system compromise without authentication or plugins. Proof-of-concept exploits are already circulating, and early signs of real-world attacks have emerged. Meanwhile, SonicWall Secure Mobile Access (SMA) appliances were targeted with zero-day exploits before patches were publicly available. Two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, allowed attackers to achieve arbitrary command execution. Both flaws have now been addressed by SonicWall. Organizations running these products should prioritize patching immediately to mitigate risks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store