Vulnerabilità · 68 giorni fa
wp2shell entra in campo, Windmill resta sotto attacco La storia non è più solo un file-read su Windmill. Ora ci sono due fronti attivi: su WordPress i public PoC di wp2shell lasciano artefatti locali facili da riconoscere, anche quando gli indicatori di rete cambiano, e il controllo non può fermarsi alla sola caccia sugli IOC esterni.
Le fonti confermano lo sfruttamento attivo di CVE-2026-29059 su Windmill e la circolazione rapida dei PoC per CVE-2026-63030 e CVE-2026-60137 in WordPress Core. Elastic descrive shell, directory di plugin finte e tracce coerenti sui sistemi colpiti; CISA ha inserito entrambe le CVE di WordPress nel KEV, con una finestra molto stretta di patching.
Il rischio pratico è che un’istanza esposta sia già compromessa prima della correzione. Su Windmill, se è presente SUPERADMIN_SECRET, un file read diventa accesso da superadmin; su WordPress, la compromissione può emergere anche dai reperti sul disco, non solo dal traffico di rete.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 6% (93º percentile).
Data di correzione federale CISA 4 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
Data di correzione federale CISA 24 lug
CVE-2026-29059 NVD KEV
EPSS 2% (81º percentile).
Cronologia Fonti 20 fonti che coprono questa storia
Elastic Security Labs 22 lug
wp2shell: detecting WordPress pre-auth RCE end-to-end — Elastic Security Labs
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend.
The Hacker News 22 lug
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
Help Net Security 21 lug
SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security
CVE-2026-15409 and CVE-2026-15410 were exploited since June 22, 2026, allowing threat actors to install custom malware.
The Hacker News 21 lug
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
The Register Security 21 lug
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Dark Reading 20 lug
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
SANS ISC 20 lug
WordPress Exploitation Underway (CVE-2026-63030) - SANS ISC
WordPress Exploitation Underway (CVE-2026-63030), Author: Johannes Ullrich
BleepingComputer 20 lug
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Wiz Research 20 lug
Exploitation in the Wild of wp2shell | Wiz Blog
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137).
TechCrunch Security 20 lug
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
SecurityWeek 20 lug
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The Hacker News 20 lug
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.
Entità CVE-2026-63030 CVE-2026-60137 CVE-2026-29059 Part of the PlainSec briefing for 2026-07-20
Editions Storie correlate
Vulnerabilità · 68 giorni fa
wp2shell entra in campo, Windmill resta sotto attacco La storia non è più solo un file-read su Windmill. Ora ci sono due fronti attivi: su WordPress i public PoC di wp2shell lasciano artefatti locali facili da riconoscere, anche quando gli indicatori di rete cambiano, e il controllo non può fermarsi alla sola caccia sugli IOC esterni.
Le fonti confermano lo sfruttamento attivo di CVE-2026-29059 su Windmill e la circolazione rapida dei PoC per CVE-2026-63030 e CVE-2026-60137 in WordPress Core. Elastic descrive shell, directory di plugin finte e tracce coerenti sui sistemi colpiti; CISA ha inserito entrambe le CVE di WordPress nel KEV, con una finestra molto stretta di patching.
Il rischio pratico è che un’istanza esposta sia già compromessa prima della correzione. Su Windmill, se è presente SUPERADMIN_SECRET, un file read diventa accesso da superadmin; su WordPress, la compromissione può emergere anche dai reperti sul disco, non solo dal traffico di rete.
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 6% (93º percentile).
Data di correzione federale CISA 4 ago
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
Data di correzione federale CISA 24 lug
CVE-2026-29059 NVD KEV
EPSS 2% (81º percentile).
Cronologia Fonti 20 fonti che coprono questa storia
Elastic Security Labs 22 lug
wp2shell: detecting WordPress pre-auth RCE end-to-end — Elastic Security Labs
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend.
The Hacker News 22 lug
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
Help Net Security 21 lug
SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security
CVE-2026-15409 and CVE-2026-15410 were exploited since June 22, 2026, allowing threat actors to install custom malware.
The Hacker News 21 lug
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
The Register Security 21 lug
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Dark Reading 20 lug
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
SANS ISC 20 lug
WordPress Exploitation Underway (CVE-2026-63030) - SANS ISC
WordPress Exploitation Underway (CVE-2026-63030), Author: Johannes Ullrich
BleepingComputer 20 lug
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Wiz Research 20 lug
Exploitation in the Wild of wp2shell | Wiz Blog
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137).
TechCrunch Security 20 lug
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
SecurityWeek 20 lug
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The Hacker News 20 lug
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.
Entità CVE-2026-63030 CVE-2026-60137 CVE-2026-29059 Part of the PlainSec briefing for 2026-07-20
Editions Storie correlate