Tech News
← Home  ·  All topics

Rce

4 GoKawiil briefs on this topic

Attackers exploit WordPress CVE-2026-87902 within hours of patch release

Security firm Patchstack says threat actors began exploiting a critical WordPress path traversal flaw, CVE-2026-87902, to write files that execute shell commands, after initial reconnaissance traffic surged tenfold. The bug, discovered by researcher Robert Ressl and rated 9.2/10 in severity, allows unauthenticated attackers to trick get_page_template() into loading arbitrary local PHP files under certain theme and server configurations. WordPress patched the issue in version 7.1.2 and backported fixes to branches as old as 4.7.

Hacktron discloses HEIF Heist, a remote code execution flaw in HEIC/AVIF image parsers

Security researchers at Hacktron identified a class of vulnerabilities, dubbed HEIF Heist, affecting native decoders like libheif and libde265 that process HEIF, HEIC, and AVIF image formats. These libraries are widely bundled inside popular tools such as ImageMagick, libvips, and Sharp, meaning the flaw can reach production systems through indirect dependencies rather than direct use.

WeWorm Demonstrates Zero-Click WeChat Exploit on iOS and Android

Researchers unveiled WeWorm, a proof-of-concept worm that spreads through WeChat calls without user interaction, affecting both iOS and Android devices. The demo involved three phones where an attacker could hijack accounts and propagate the infection by simply calling victims, who need not answer or even interact with their phones.

Attackers chain two Microsoft SharePoint flaws using public PoC exploits

Threat intelligence firm Defused reports that hackers are actively probing SharePoint servers by combining two vulnerabilities: an authentication bypass in JWT token validation (CVE-2026-55040) and a Business Connectivity Services flaw (CVE-2026-63520) that enables remote code execution. Proof-of-concept code for both bugs was published publicly in August by researchers at Rapid7 and VulnCheck, and Defused says it has already observed the bypass being exploited alongside admin enumeration on honeypots, though no successful code execution has been confirmed yet.