WordPress wp2shell Emergency Patch – A Pre-Auth RCE Nightmare for Millions of Sites
On July 17, 2026, WordPress released urgent security updates addressing a critical pre-authentication remote code execution (RCE) vulnerability, dubbed wp2shell. Affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, the flaw (tracked under CVEs like CVE-2026-63030 and CVE-2026-60137) combines REST API confusion with SQL injection in WP_Query. This allows unauthenticated attackers to execute arbitrary code on default installations.
Key Details and Impact:
Discovered by researchers at Assetnote (Adam Kues of Searchlight Cyber), the vulnerability poses an immediate threat to millions of websites. WordPress activated forced automatic updates, Cloudflare deployed firewall rules, and a free checker tool launched at wp2shell.com. Sites not updated quickly remain highly exposed to full server compromise, data theft, or malware injection.
Why It Matters: WordPress powers over 40% of the web. This flaw highlights supply-chain and core platform risks. Lessons include enabling auto-updates, monitoring for anomalous activity, and using WAFs. Patch immediately if not already done—delays could lead to widespread exploitation.
ServiceNow CVE-2026-6875 – Sandbox Escape RCE Exploited in the Wild
ServiceNow users face active exploitation of CVE-2026-6875, a critical sandbox escape in the AI platform leading to remote code execution. Patched around mid-July 2026 (with fixes in various releases like Zurich Patch 7b/9 and Yokohama updates), the vulnerability allows unauthenticated attackers to break out of sandbox restrictions under certain conditions.
Key Details and Impact:
Public proof-of-concept details have surfaced, enabling real-world attacks. ServiceNow instances, especially those using AI features, are prime targets for enterprise environments handling sensitive workflows. Exploitation could lead to full instance compromise, data exfiltration, or lateral movement.
Recommendations: Apply patches urgently, review instance configurations, limit unnecessary AI/sandbox exposure, and monitor for suspicious queries. This incident underscores risks in complex enterprise platforms where AI integrations expand the attack surface.
Persistent Threats – AWS Key Exposures, SonicWall Exploits, and Ransomware Evolution
Recent incidents highlight ongoing operational risks. An exposed AWS long-term access key enabled S3 data exfiltration and ransomware, with attackers disabling versioning to block recovery. SonicWall remote access devices face active zero-days, targeting SMEs for quick network pivots. Broader trends include rapid ransomware deployment (under 24 hours) and data-theft extortion models from groups like ShinyHunters (echoing June breaches at entities like Kodak and DentaQuest).
Key Takeaways:
Secure and rotate cloud credentials; enable detailed logging.
Patch firewall/VPN appliances immediately.
Test backups and incident response plans regularly. Phishing and supply-chain attacks remain dominant entry points.
Combined Insights: These events show a threat landscape favoring speed and automation—vulnerabilities in widely used platforms (WordPress, ServiceNow) combined with misconfigurations enable fast compromise. Organizations should prioritize patching, zero-trust principles, and continuous monitoring.




