CVE-2026-48907
Sfruttamento noto · CISA KEV
EPSS 16% (97º percentile).
Data di correzione federale CISA 19 giu · data superata
Vulnerabilità ed exploit · Attacco ad app web
Il punto non è la campagna di massa in sé. Il rischio reale è che un sito compromesso resti monetizzabile anche dopo la pulizia, se il webshell o il foothold sopravvive e permette all’attaccante di rientrare o rivendere l’accesso più avanti.
Un server lasciato aperto di WP-SHELLSTORM ha esposto strumenti, log e liste di target, con 25.195 compromissioni validate. Le fonti indicano un’operazione di access brokering contro siti WordPress e Joomla, con forte concentrazione su plugin obsoleti; tra i casi più sfruttati ci sono Breeze Cache e JCE editor, legati a CVE-2026-3844 e CVE-2026-48907.
Per chi ripulisce web server compromessi, il confine non è la rimozione del malware visibile. Se il webshell o un accesso residuo resta in piedi, il sito può tornare merce da rivendere e il rischio non si esaurisce con il primo incidente.
1 fonte · 10 lug
Sfruttamento noto · CISA KEV
EPSS 16% (97º percentile).
Data di correzione federale CISA 19 giu · data superata
CVSS 9.8 CRITICAL: the Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… EPSS 4% (89º percentile).
The Hacker News
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
An open WP-SHELLSTORM server exposed tools, logs, and target lists naming 1.4 million sites, with researchers validating 25,195 compromises.
originalePart of the PlainSec briefing for 2026-07-10
Every edition of this story: Un server esposto mostra il mercato dei webshell rubati