daily cyber × ai intelligence

index

tagged

[watchtowr]

4 editions · 4 items

July 18, 2026

  • "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST /batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory. · Vulnerabilities & Exploits

in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

July 11, 2026

  • Progress Software emailed ShareFile customers urging them to immediately power down Windows servers running Storage Zone Controllers after identifying a "credible external security threat," and has temporarily disabled affected accounts. watchTowr says it is tracking rumors of active zero-day exploitation against exposed on-prem controllers and has notified clients with internet-facing instances. Treat any exposed Storage Zone Controller as potentially compromised. The Hacker News, BleepingComputer · Vulnerabilities & Exploits

in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat