Skip to main content

WordPress Core Pre-Authentication RCE Chain "wp2shell" Now Has Public Exploits (CVE-2026-63030 / CVE-2026-60137)

Scope: WordPress Core Versions 6.8.0 through 6.8.5 (SQL injection only), 6.9.0 through 6.

VentraConnect WordPress Plugin OTP Brute Force Enables Unauthenticated Administrator Account Takeover (CVE-2026-13142)

Scope: Social Login, Passkeys, Magic Link and Email OTP WordPress Plugin (VentraConnect)

WSO2 API Manager and Identity Server Reflected XSS Enables Session Manipulation and Credential Theft (CVE-2026-2445)

Scope: WSO2 API Manager 4.2.0 to 4.6.0 and WSO2 Identity Server 6.0.0 and 7.1.0 (Multiple

FreeRDP Pre-Authentication Heap Buffer Overflow Enables Remote Code Execution Against RDP Clients (CVE-2026-64620)

Scope: FreeRDP Versions 3.27.1 and Earlier (Linux, macOS, Windows, Android Clients)

Windows Remote Desktop Protocol Server Unauthenticated RCE Patched in July 2026 Patch Tuesday (CVE-2026-56190)

Scope: Windows Server 2019, 2022, 2025 and Windows 10/11 (All Builds with RDP Server Enabled)

Microsoft SharePoint Server Deserialization RCE Exploited as Zero-Day, Now Added to CISA KEV (CVE-2026-58644 / CVE-2026-50522)

Scope: Microsoft SharePoint Server 2016, 2019, and Subscription Edition (All On-Premises Deployments

Microsoft AD FS Zero-Day Actively Exploited to Grant Admin Privileges, Patched in Record July 2026 Patch Tuesday (CVE-2026-56155)

Scope: Microsoft Active Directory Federation Services (Windows Server 2019, 2022, 2025 with AD FS Ro

Subscribe to Advisories