Ubuntu snap-confine Flaw Lets Local Users Gain Root on Default Desktop Installs A high-severity flaw in Ubuntu's snap-confine utility could let any local user escalate to root on default desktop installs of Ubuntu 24.04, 25.10, and 26.04.
WordPress wp2shell Exploit Drives a New Wave of Mass Scanning Two newly disclosed WordPress flaws are being chained into an unauthenticated remote code execution bug dubbed wp2shell. Public exploit code has triggered mass scanning, putting unpatched sites at serious risk.
Ninety Minutes to Weaponized: Inside the WordPress Core RCE Race A pre-auth SQL injection and a REST batch route confusion in WordPress core were chained into remote code execution. Attackers hit the internet roughly ninety minutes after the fix shipped, and the campaign has not slowed down.
React Server Components Flight Protocol: Deserialization Risks and Defenses A practical look at how the React Flight streaming protocol became a deserialization attack surface, what the React2Shell flaw exposed, and how teams can harden Server Components.
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation A critical SharePoint deserialization flaw, CVE-2026-50522, is now being actively exploited after a public proof-of-concept emerged, putting on-premises SharePoint servers at serious risk.
Cloudflare WAF Blocks Two Critical WordPress Vulnerabilities: What Site Owners Must Do Cloudflare activated emergency WAF rules for a critical WordPress REST API RCE and a related SQL injection flaw. Here is what affected versions are, how the rules work, and the steps every site owner should follow.