News roundup web-app cloud
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
CVE Tools coverage
This week's security highlights include two actively exploited zero-day vulnerabilities in SonicWall Secure Mobile Access appliances (CVE-2026-15409, CVE-2026-15410), which have been patched and require immediate firmware upgrades. Additionally, the latest WordPress 7.0.2 update resolves one critical and one high-severity flaw, both labeled as urgent for remediation. Other notable developments include new AI-driven attack methods, phishing trends, and a surge in ransomware activity via email vectors.