CyberHighConfirmedAccelerating
10.0
Active exploitation of critical WordPress wp2shell vulnerabilities detected
BleepingComputer·about 5 hours ago
Exploitation of CVE-2026-60137 and CVE-2026-63030 began shortly after disclosure, indicating a high-risk situation.
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.