WordPress wp2shell RCE: CVE-2026-63030 & CVE-2026-60137

🔴 Critical | Source: The Hacker News Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137 (collectively dubbed wp2shell), are being actively exploited in the wild. When chained together, they allow unauthenticated attackers to achieve remote code execution and full site compromise without any credentials. Mass scanning activity began almost immediately after a public exploit was released, significantly raising the risk for unpatched WordPress installations. Security Architect’s Take: Audit your organisation’s WordPress estate immediately and apply available patches or mitigations without delay. If you host WordPress on cloud infrastructure (EC2, App Service, Cloud Run, etc.), consider placing WAF rules blocking wp2shell exploit patterns at the edge while patching is carried out, and review web application firewall logs for scanning activity originating from the past 72 hours. ...

21 July 2026 · ZX Cloud Security

CVE-2026-6875: ServiceNow AI Platform RCE Exploited

🔴 Critical | Source: The Hacker News A critical vulnerability in the ServiceNow AI Platform (CVE-2026-6875, CVSS 9.5) is being actively exploited in the wild, allowing unauthenticated attackers to escape the application sandbox and execute arbitrary code. The flaw requires no credentials, significantly lowering the bar for attackers. Patches have been released, but active exploitation means organisations running ServiceNow are at immediate risk. Security Architect’s Take: Prioritise patching CVE-2026-6875 across all ServiceNow instances immediately — active exploitation with no authentication requirement means exposure windows must be minimised to hours, not days. If patching cannot be applied immediately, consider restricting network access to ServiceNow instances to known IP ranges and review logs for anomalous unauthenticated activity. ...

21 July 2026 · ZX Cloud Security

OVH Januscape Bug: Silent Mass Reboots Risk Downtime

🔴 Critical | Source: The Register — Security OVH implemented a patch for a critical vulnerability dubbed ‘Januscape’ by silently backporting a fix into Debian and scheduling mass reboots of customer infrastructure without explicit customer consent. The approach risked unplanned downtime for workloads not tolerant of unexpected restarts. This raises serious questions about cloud provider transparency and customer communication during emergency patching events. Security Architect’s Take: Audit your OVH-hosted workloads immediately to confirm reboot resilience and check whether your instances were affected by this patching cycle. Beyond the immediate fix, review your cloud provider contracts and escalation procedures to ensure you have enforceable notification rights before unscheduled maintenance — and document your recovery posture for critical hypervisor-level vulnerabilities. ...

21 July 2026 · ZX Cloud Security

OVH Januscape Hypervisor Bug: Secret Mass Reboots

🔴 Critical | Source: The Register — Security OVH identified a critical vulnerability in its Januscape hypervisor and rolled out a patch via mass, largely unannounced reboots of customer virtual machines, backporting the fix into Debian without seeking prior customer consent. The approach prioritised rapid remediation but risked unplanned downtime for tenants. The French cloud provider used an Australian region as an initial test environment before wider rollout. Security Architect’s Take: If you run workloads on OVH, audit your service agreements and maintenance notification policies immediately — this incident demonstrates that OVH may apply emergency hypervisor patches without explicit consent or advance warning. Ensure your resilience design accounts for unplanned hypervisor reboots, and establish a direct alerting channel with your OVH account team for critical infrastructure changes. ...

21 July 2026 · ZX Cloud Security

CVE-2026-0770: Langflow RCE Vulnerability Actively Exploited

🔴 Critical | Source: CISA Known Exploited Vulnerabilities CVE-2026-0770 is a critical remote code execution vulnerability in Langflow, an open-source tool used to build AI-powered workflows. The flaw allows attackers to execute arbitrary code on affected systems by abusing untrusted functionality included within the application. It has been added to CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Identify any Langflow instances running in your environment — including developer sandboxes and AI/ML pipelines — and patch immediately or isolate them from public access. Given active exploitation, treat any internet-exposed Langflow deployments as potentially compromised and conduct a thorough investigation before patching. ...

21 July 2026 · ZX Cloud Security

CVE-2026-60137: WordPress Core SQL Injection & RCE

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A SQL injection vulnerability in WordPress Core allows malicious input passed by a plugin or theme to compromise the database layer. When chained with CVE-2026-63030, an unauthenticated attacker can achieve remote code execution on default WordPress installations with no prior access required. This is actively exploited in the wild and carries a CISA remediation deadline of 4 August 2026. Security Architect’s Take: Patch WordPress Core immediately and audit all third-party plugins and themes for untrusted input handling; consider placing WordPress instances behind a WAF with SQL injection and RCE rules enabled, and restrict outbound network access from web servers to limit post-exploitation blast radius. ...

21 July 2026 · ZX Cloud Security

CVE-2026-63030: WordPress SQL Injection & RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in WordPress Core allows attackers to perform SQL Injection, potentially leading to full Remote Code Execution on affected sites. The flaw stems from an interpretation conflict and is actively being exploited in the wild, as confirmed by CISA’s Known Exploited Vulnerabilities catalogue. It can be chained with a second vulnerability (CVE-2026-60137) to amplify impact. Security Architect’s Take: Patch WordPress Core immediately to the remediated version — the CISA-mandated deadline of 24 July 2026 applies to federal agencies but should be treated as urgent for all environments. Audit any cloud-hosted WordPress deployments (e.g. on AWS, Azure, or GCP via managed app services or self-hosted VMs) and ensure WAF rules are in place to block SQL injection attempts while patching is underway. ...

21 July 2026 · ZX Cloud Security

Critical WordPress Vulnerability Exploited in the Wild

🔴 Critical | Source: The Register — Security A critical vulnerability in WordPress is being actively exploited in the wild, with attackers leveraging it to cause a range of malicious outcomes including site takeovers and malware injection. Dozens of proof-of-concept exploits have been published publicly, significantly lowering the bar for less skilled attackers. The combination of active exploitation and widespread PoC availability makes this an urgent patching priority for any organisation running WordPress. ...

20 July 2026 · ZX Cloud Security

CVE-2026-42533: Critical NGINX RCE & Crash Flaw

🔴 Critical | Source: The Hacker News A critical heap buffer overflow vulnerability in NGINX (CVE-2026-42533) allows an unauthenticated remote attacker to crash worker processes or potentially execute arbitrary code by sending crafted HTTP requests. F5 patched the flaw on 15 July 2026 in NGINX stable (1.30.4), mainline (1.31.3), and NGINX Plus (37.0.3.1). Given NGINX’s ubiquity as a web server and reverse proxy across cloud-hosted infrastructure, the blast radius is significant. ...

19 July 2026 · ZX Cloud Security

SonicWall SMA 1000 Zero-Days Exploited for Root Access

🔴 Critical | Source: The Hacker News A previously unknown threat actor, tracked as UTA0533, exploited zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to gain root-level access before the flaws were publicly disclosed. Exploitation is believed to have begun as early as 22 June 2026, discovered during an incident response investigation by Volexity. This is significant because VPN appliances sit at the network perimeter and root access means full device compromise, potentially exposing internal corporate networks. ...

19 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options