logo

NGINX, WordPress, SonicWall RCEs under active exploitation; patched versions released

ID: 4a3757a0-fcbb-59bf-a632-7b9670a4c5d0

STIX ID: report--4a3757a0-fcbb-59bf-a632-7b9670a4c5d0

Feed Name: defend.network

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: defend.network

...
...

Executive Summary: This briefing describes multiple high-severity threats — a patched NGINX heap buffer overflow (CVE-2026-42533), public exploits for WordPress 'wp2shell' RCEs, actively exploited SonicWall SMA 1000 zero-days (chained by Inc ransomware), an OpenSSL 'HollowByte' memory-exhaustion flaw, and a Russian-attributed UAC-0145 ClickFix campaign delivering data-stealing malware — and urges immediate patching, log review, isolation of vulnerable appliances, and heightened detection efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.