Security news.
Threat actors are actively exploiting freshly disclosed zero-day and unpatched flaws in WordPress, Roundcube, and enterprise VPN appliances. Meanwhile, CISA has added high-impact vulnerabilities in TeamCity, WSO2, and Adobe Commerce to its Known Exploited Vulnerabilities catalog as ransomware groups accelerate automated attacks. Developers and administrators should immediately patch public-facing services and audit autonomous AI agent permissions.
WordPress Under Active Attack via Critical CVE-2026-87902
Threat actors began exploiting an unauthenticated remote code execution vulnerability (CVSS 9.2) in WordPress within hours of public disclosure. The flaw allows attackers to manipulate page-template inclusion to execute arbitrary PHP code.
Hackers Exploit High-Severity Roundcube Webmail Flaw
The Canadian Centre for Cyber Security warns that a code injection vulnerability patched in May is now facing active in-the-wild exploitation. Unpatched Roundcube servers risk full compromise via malicious email processing.
Ransomware Gangs Weaponize Patched JetBrains TeamCity Flaw
CISA issued a warning that ransomware operators are actively exploiting a critical TeamCity vulnerability originally disclosed in July. Administrators must verify on-premises build servers are running the latest patched release.
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA has added CVE-2026-5430 (WSO2 path traversal) and CVE-2026-71362 (Adobe Commerce and Magento authorization bypass) to its catalog following evidence of active exploitation. Federal agencies and enterprises have strict deadlines to apply vendor remediations.
Check Point Confirms Exploitation of Security Gateway VPN RCE
Threat actors are actively targeting CVE-2026-85102, a pre-authentication remote code execution flaw within the VPN certificate-handling functionality of Check Point Security Gateways. Organizations are urged to immediately apply the vendor-issued emergency hotfix.
SolarWinds Patches Critical Unauthenticated RCE Bugs
SolarWinds addressed two critical vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, affecting Observability Self-Hosted deployments. Both flaws can be triggered remotely without authentication to execute arbitrary code.
Unpatched OnePlus OxygenOS Flaws Grant Root Without Permissions
Researchers revealed an exploit chain affecting OnePlus and OPPO devices running OxygenOS that allows any newly installed, unprivileged app to gain full root access. The vendor confirmed multiple device families remain affected while patches are finalized.
Documentation Placeholder third-party.com Hijacked for ClickFix Attacks
The domain "third-party[.]com," widely cited as an example URL across thousands of developer repositories and guides, was weaponized to serve ClickFix PowerShell lures to Windows visitors. Developers are advised to scrub project documentation and substitute reserved domains like example.com.