⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
AI Summary
This week's threat landscape highlights critical vulnerabilities in widely used platforms such as WordPress, SonicWall, and Microsoft SharePoint, with active exploitation observed in the wild. A pre-authenticated remote code execution flaw in WordPress Core (CVE-2026-63030 and CVE-2026-60137) enables unauthenticated attackers to execute code, posing a significant risk due to WordPress's global reach. SonicWall SMA appliances were exploited via zero-day vulnerabilities prior to patching, while CISA added a SharePoint RCE (CVE-2026-58644) to its known exploited list. Additionally, new malware frameworks like OkoBot and NadMesh target crypto assets and cloud AI services, indicating evolving attacker tactics leveraging automation and AI.
AI-extracted · verify before operational use