Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
CVE-2026-47876, rated 9.3, may let a guest VM with a VMXNET3 adapter escape to the VMware ESX host. Two vCenter flaws rated 9.8 shipped in the same advisory, and one is already being exploited in the wild.
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Metabase's cloud service was breached through a zero-day, and the vendor patched every hosted instance before most customers heard. Self-hosted operators had to find out, patch by hand and hunt for evidence. Five customers came forward in four days, and about 2,500 instances remain visible online.
Cloudflare reached FedRAMP High without a separate gov cloud: one network, U.S.-only processing, 22 agencies on board. One catch: it brands the milestone Class D, a certification FedRAMP's roadmap only pilots next fiscal year. The Pentagon's IL4 is the next target.
Zapscape lets an attacker who controls a guest climb out and seize the Linux host as root. Wherever /dev/kvm is open to ordinary users, a plain shared-hosting box is in range too, because a local user can spin up their own guest. Exploit code is public; patched kernels are rolling out.
Roundcube shipped eleven security fixes across its current and LTS branches, including an IMAP command injection and a conditional code execution flaw. The notes name no CVE identifiers, so version-matching scanners stay quiet, and cPanel has historically taken five to nine days to follow.
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Freenom gave away millions of domains and became the internet's biggest source of phishing, until Meta sued and it promised to quit. Now, per Domain Incite, it is back, running .tk, .cf and .gq again from €8.22 a year. What changed is what fueled the abuse: the domains are no longer free.
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Telegram's t.me domain went offline worldwide, placed on serverHold by the .me registry. The likely trigger is a US OFAC sanction on a cybercrime group whose t.me address was listed, enforced through a Montenegrin ccTLD run by US firms Identity Digital and GoDaddy. One URL, a whole domain down.
Januscape (CVE-2026-53359) lets a guest VM escape to the host and take over co-tenants; Bad Epoll (CVE-2026-46242) lets any unprivileged user reach root with a near-perfect exploit. Both are patched upstream and in AlmaLinux, and for both the only fix is a new kernel and a reboot.