WordPress wp2shell RCE Flaw: Patch Now, Public Exploits Active

Wordpress-wp2shell

WordPress Core “wp2shell” RCE Flaw: Public Exploits Now Circulating; Patch Immediately A critical pre-authentication remote code execution vulnerability in WordPress Core, dubbed wp2shell, is now under active exploitation after proof-of-concept code surfaced publicly. The flaw, tracked as CVE-2026-63030, allows an unauthenticated attacker to take complete control of a WordPress site with no login credentials, no … Read more

CVE-2026-41089: Critical Windows Netlogon RCE Exploited

Active Directory Vulnerability

CVE-2026-41089: Critical Windows Netlogon RCE Flaw Now Actively Exploited A critical Windows Netlogon remote code execution flaw is now being actively weaponized in the wild, three weeks after Microsoft shipped the patch. CVE-2026-41089, carrying a near-perfect CVSS score of 9.8, allows unauthenticated attackers to seize full SYSTEM-level control of any unpatched Windows domain controller by … Read more