Threat intelligence, automated.
AI-researched threat write-ups, live IOC feeds, and MITRE ATT&CK mappings — human-reviewed before every publish. Built for defenders.
WordPress Core SQL Injection (CVE-2026-60137) Chained for RCE
A SQL injection vulnerability in WordPress Core’s `WP_Query` `author__not_in` parameter (CVE-2026-60137) allows attackers to inject malicious SQL. This vulnerability can be chained with CVE-2026-63030 to achieve unauthenticated remote code execution on default WordPress installations, and is currently being actively exploited in the wild.
Read full report →CVE-2026-50522: Critical SharePoint RCE via Deserialization of Untrusted Data
CVE-2026-50522 is a critical deserialization vulnerability in Microsoft SharePoint Server, allowing unauthorized remote code execution. Actively exploited, this flaw enables attackers to compromise SharePoint instances, potentially leading to machine key theft and broader network compromise. Immediate patching is required.
CVE-2026-63030: WordPress REST API RCE via Chained SQL Injection
A critical vulnerability, CVE-2026-63030, in WordPress Core’s REST API batch endpoint, when chained with CVE-2026-60137 (SQL Injection), allows unauthenticated attackers to achieve Remote Code Execution. This flaw affects WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 and is actively exploited in the wild.
CVE-2026-16232: Check Point SmartConsole Authentication Bypass Vulnerability
A critical authentication bypass vulnerability (CVE-2026-16232) in Check Point SmartConsole allows unauthenticated remote attackers to gain full administrative privileges. This flaw enables attackers to modify security policies and configurations on affected Check Point Management Servers. Check Point has confirmed active exploitation of this vulnerability.
CVE-2026-46817: Oracle E-Business Suite Payments Takeover Vulnerability
A critical improper privilege management vulnerability (CVE-2026-46817) in Oracle E-Business Suite’s Payments product allows unauthenticated attackers to achieve full takeover of Oracle Payments via network access. This vulnerability affects versions 12.2.3 through 12.2.15 and has a CVSS 3.1 score of 9.8.
CVE-2026-58644: Microsoft SharePoint Deserialization RCE
A critical deserialization of untrusted data vulnerability (CVE-2026-58644) in Microsoft SharePoint allows unauthenticated, remote code execution. This flaw, with a CVSSv3.1 score of 9.8, enables attackers to compromise affected SharePoint servers without prior authentication. Immediate patching is advised to prevent exploitation.
CVE-2026-39808: Fortinet FortiSandbox OS Command Injection Vulnerability
A critical OS command injection vulnerability (CVE-2026-39808) exists in Fortinet FortiSandbox versions 4.4.0 through 4.4.9. This flaw allows an unauthenticated attacker to execute arbitrary code or commands via crafted HTTP requests. The vulnerability has a CVSSv3.1 score of 9.8 (CRITICAL) and is listed in CISA’s Known Exploited Vulnerabilities Catalog, indicating active exploitation.
CVE-2026-25089: Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet FortiSandbox products are vulnerable to an unauthenticated OS command injection (CVE-2026-25089). This critical flaw allows remote attackers to execute arbitrary commands via crafted HTTP requests. Active exploitation has been observed, making immediate patching crucial for affected organizations.
CVE-2026-41091: Microsoft Defender Link Following Vulnerability
CVE-2026-41091 is a high-severity local privilege escalation vulnerability in Microsoft Defender, rated 7.8 CVSSv3.1. It stems from improper link resolution, allowing an authorized local attacker to gain elevated privileges. This vulnerability is listed in CISA’s KEV catalog, indicating active exploitation.
Transparently AI-authored
Every report on this site is researched and drafted by an AI agent, then reviewed and approved by a human analyst before publication. The Agent Logbook shows every step — sources consulted, enrichment calls, tokens used, and approval status — in real time.