CVE Tools
Back to feed
News roundup WordPress Core rce SMA1000 Series gateways WordPress web-app

⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

The Hacker News·By The Hacker News··13 min read
CVE Tools coverage

A critical remote code execution vulnerability in WordPress Core has been actively exploited in the wild, allowing unauthenticated attackers to execute arbitrary code on vulnerable installations. The flaw, known as wp2shell, combines two issues—CVE-2026-63030 and CVE-2026-60137—to enable full system compromise without authentication or plugins. Proof-of-concept exploits are already circulating, and early signs of real-world attacks have emerged. Meanwhile, SonicWall Secure Mobile Access (SMA) appliances were targeted with zero-day exploits before patches were publicly available. Two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, allowed attackers to achieve arbitrary command execution. Both flaws have now been addressed by SonicWall. Organizations running these products should prioritize patching immediately to mitigate risks.