Oracle’s July 2026 Critical Patch Update fixes multiple flaws in WebLogic Server’s Core component, several letting an unauthenticated attacker fully take over the server over T3, IIOP, HTTP, and SOAP.
A PHP object injection flaw in PrestaShop’s ps_facetedsearch module lets an unauthenticated attacker smuggle a malicious object through a slider filter and achieve remote code execution on the storefront.
wp2shell chains a REST API batch-route confusion flaw with a SQL injection in WordPress core’s WP_Query, letting an unauthenticated attacker run code on a default install and take over the site.
A missing authentication flaw in on-premises Microsoft SharePoint Server lets an unauthenticated attacker escalate privileges over the network, a zero-day Microsoft confirms is already under active exploitation.
An unauthenticated file upload flaw in Balbooa Forms for Joomla lets any anonymous visitor drop a PHP file into a public folder, resulting in full remote code execution.
A blind SQL injection in Control Web Panel’s userRes parameter lets attackers with a guessable username gain MySQL root access, enabling full server takeover via a planted PHP webshell.
Two pre-authentication vulnerabilities in BeyondTrust Remote Support and Privileged Remote Access let attackers bypass authentication entirely and gain unauthorized, potentially privileged, access to affected appliances.
Two Gitea vulnerabilities, a Docker default that lets any IP impersonate a user and a container registry flaw exposing private images, leave self-hosted instances open to unauthenticated attackers.
A code injection flaw in n8n’s expression evaluation lets any authenticated user with workflow edit rights run arbitrary system commands on the host, enabling full server compromise.
A memory-exhaustion flaw in Apache HTTP Server’s mod_http2 lets an unauthenticated attacker crash HTTP/2 web servers within seconds using a single crafted connection.