Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
WordPress Core has been identified with a critical interpretation conflict vulnerability, tracked as CVE-2026-63030, which could enable attackers to execute SQL Injection and Remote Code Execution (RCE) attacks. This vulnerability can be chained with another known issue, CVE-2026-60137, amplifying its potential impact.
JoomShaper SP Page Builder, a popular website builder for Joomla, has a critical vulnerability (CVE-2026-48908) that allows unauthenticated attackers to upload arbitrary files, including malicious PHP code, leading to remote code execution. CISA confirmed the flaw is actively being exploited in the wild and added it to their Known Exploited Vulnerabilities catalog on July 7, 2026.
KNX Association's KNX Protocol Connection Authorization Option 1 contains a critical vulnerability (CVE-2023-4346) due to an overly restrictive account lockout mechanism. This flaw enables attackers to purge all devices lacking additional security options and set a BCU key to lock the device, effectively rendering it inaccessible.
Adobe ColdFusion: Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
DD-WRT DD-WRT: DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
SonicWall SMA1000 Appliances are affected by a server-side request forgery (SSRF) vulnerability (CVE-2026-15409) that allows remote, unauthenticated attackers to manipulate the appliance into making unauthorized requests to unintended locations. The vulnerability, which has been added to CISA's Known Exploited Vulnerabilities catalog, is reportedly being actively exploited in the wild.