CVE-2026-6854
CVSS 7.5 HIGH: the My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via… EPSS 2% (75th percentile).
Threats & Adversaries · Credential Theft
Microsoft says ClickFix campaigns are using browser cache smuggling to turn a pasted Windows Run command into execution of a VBScript payload that targets credentials. The trick is that the malicious script is preloaded into the browser cache first, disguised as an image file, so the victim is not fetching it at launch.
That matters because the normal Run-dialog character limit and download-based defenses never see a long remote command or a fresh web pull. Microsoft’s observed chain then copies the cached file into a .vbs file, runs it with wscript.exe, and moves on to in-memory stages that can reach browser and device credentials.
For Windows environments where users are trained to paste instructions into Run, the browser cache has become part of the execution path, not just a browsing artifact. If defenders only watch for obvious downloads or oversized paste-run payloads, this class of ClickFix traffic can still land on the endpoint and continue past the first prompt.
1 source · 6h ago
CVSS 7.5 HIGH: the My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via… EPSS 2% (75th percentile).
The Hacker News
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
Microsoft observed ClickFix attacks using browser cache smuggling to execute cached VBScript and launch a credential-targeting malware chain.
originalPart of the PlainSec briefing for 2026-10-06
Every edition of this story: ClickFix Uses Browser Cache to Evade Run Limits