CVE Tools
Back to feed
News roundup web-app cloud

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Help Net Security·By Anamarija Pogorelec··15 min read
CVE Tools coverage

This week's security highlights include two actively exploited zero-day vulnerabilities in SonicWall Secure Mobile Access appliances (CVE-2026-15409, CVE-2026-15410), which have been patched and require immediate firmware upgrades. Additionally, the latest WordPress 7.0.2 update resolves one critical and one high-severity flaw, both labeled as urgent for remediation. Other notable developments include new AI-driven attack methods, phishing trends, and a surge in ransomware activity via email vectors.