CyberNotableConfirmedDeveloping
10.0
Zimbra releases security patches for critical command injection and SSRF vulnerabilities
SecurityWeek·about 13 hours ago
Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in WordPress Core to deploy persistent webshells and malicious plugins. The scope of the compromise and the specific threat actor attribution remain uncertain, posing a significant risk to server integrity across the WordPress ecosystem.
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.