August 17, 2026
- Forminator WordPress plugin unauthenticated RCE (CVE-2026-15748, CVSS 9.8). Malicious PHP uploads can achieve arbitrary code execution across 600,000+ installs (The Hacker News). · Vulnerabilities & Exploits
in One Video Call to Kernel: Unisoc Baseband Chain Gives Full Android Takeover