← BACK TO FEED
TAG

remote code execution2 articles

Half a Million WordPress Sites Running Vulnerable Form Plugin — 300,000 Still Unpatched

A critical remote code execution vulnerability (CVE-2026-15748, CVSS 9.8) has been discovered in the Forminator Forms WordPress plugin, affecting all versions up to 1.56.1. The flaw allows unauthenticated attackers to bypass file type validation and upload executable files, potentially leading to full site compromise — but only poses a significant risk when a Custom File Upload Storage root has been configured. The bug was patched in version 1.56.2 on July 31, though roughly 300,000 of the plugin's 600,000+ installations are still running a vulnerable version.

19 Aug 2026

ServiceNow RCE Flaw Exploited Within Days of Patch — But Who's Actually Behind It?

A critical remote code execution vulnerability in ServiceNow (CVE-2026-6875) is reportedly being exploited in the wild just days after patches were released on July 14 and technical details were publicly disclosed. Threat intelligence firm Defused observed exploitation activity on July 18, though closer analysis revealed the payload was identical to a published proof-of-concept rather than an independently developed exploit. ServiceNow states it has found no evidence of compromise on its hosted instances, and there is speculation the activity may originate from security researchers rather than malicious threat actors.

21 Jul 2026