PoC dropped. WordPress Core unauth LFI → RCE is not theoretical anymore.
CVE-2026-87902 : get_page_template() urldecode()'s a double-encoded pagename and locate_template() includes it with zero theme-root jail.
Chain: unauth POST (page_id + pagename) → path traversal include → pearcmd.php config-create → /tmp PHP drop → second include → www-data shell
https://t.co/FYznul9aov
https://t.co/CaG3UCpqPG
tip: if you're still on 4.7→7.1.1 with a page-templates/ theme, treat internet-facing WP as RCE until you prove the PEAR path is dead.
🔴 F5 BIG-IP APM'de kimlik doğrulamasız RCE'ye yol açan kritik heap overflow açığı CVE-2026-94127
Heap-based buffer overflow (CWE-122) olarak takip edilen açık, belirli OAuth Authorization Server yapılandırmalarında uzaktan kod çalıştırılmasına izin veriyor. CVSS 9.8 ve aktif olarak istismar edildiği F5 tarafından doğrulandı; CVEs CISA KEV'e de eklendi.
Unauth WordPress LFI → PHP exec. Public PoC is live!!!
CVE-2026-87902. get_page_template() builds page-{urldecode($pagename)}.php. locate_template() includes it with no theme-root jail.
No account. Pair a page-templates/ theme with pearcmd.php (register_argc_argv=On) and you get two-request www-data RCE. Lab-verified Sept 22.
Fixed in 7.1.2 / backports to 4.7.37.
https://t.co/D2d5ylfS5K
#Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #WordPress #RCE #BugBounty
‼️ WARNING - F5’s BIG-IP APM 0-day is being exploited for unauthenticated RCE.
CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV.
What to patch and check: https://t.co/AP8y7sIIto
And so it begins.
Started to see attempted WordPress RCE (CVE-2026-87902) exploitation in @PrevidianCyber honeypots from 104.194.9[.]227
They try to include /usr/local/lib/php/pearcmd.php
They try to write a file in /tmp/
Then try to include a Github hosted upload PHP file
🔴 Check Point Quantum Security Management'daki kimlik doğrulamasız path traversal/file upload açığı CVE-2026-93616'yı test eden bir PoC yayınlandı. Açık, saldırganların Management Server'a dosya yükleyerek keyfi script çalıştırmasına olanak sağlıyor.
https://t.co/Ls2Ig7cNj3
Ayrıca sunucunun daha önce ele geçirilmiş olup olmadığını anlamaya yönelik kontrol scriptleri: https://t.co/WsAbmN19Km
🚨[POC] CVE-2026-87902: WordPress Core versions up to and including 7.1.1 are affected by a Local File Inclusion vulnerability in the locate_template() function.
GitHub: https://t.co/VqaHEnmKku
⚡ Attackers are exploiting WordPress CVE-2026-87902 within hours of disclosure.
The attacks use pearcmd.php to write attacker-controlled PHP files to disk, but only when specific theme and server conditions are met.
🔗 How the exploit works → https://t.co/4cvsef8nYg
🚨 CRITICAL NEXT.JS RCE DISCLOSED — ATTACKER-CONTROLLED SVG DATA CAN LEAD TO SERVER CODE EXECUTION
Vercel has disclosed a critical remote-code-execution vulnerability affecting the Node.js implementation of ImageResponse in Next.js.
• CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j
• CVSS 9.5 Critical
• Affects Next.js >=16.2.0 and <16.3.6
• Exploitation is network-accessible and requires no authentication or user interaction, but requires an affected application configuration
• Applications are vulnerable when attacker-controlled values reach SVG content, attributes or styles rendered through next/og ImageResponse
• Successful exploitation can lead to remote code execution on the Node.js server
• The Edge implementation of ImageResponse is NOT affected
• Applications that never place attacker-controlled data into generated SVG content, attributes or styles are also not affected
• Fixed in Next.js 16.3.6
• Vercel recommends removing untrusted SVG input from Node.js ImageResponse as a workaround where immediate upgrading is impossible
• No confirmed in-the-wild exploitation has been identified at this time
⚠️ Analyst Note:
The interesting attack surface is dynamic image generation. Open Graph/social-preview images often incorporate URL parameters, usernames, titles or other externally supplied content — exactly the type of data that can become attacker-controlled.
Internet-facing Next.js applications using server-side ImageResponse should therefore review not only their framework version but whether untrusted values flow into SVG generation.
Original Vercel / Next.js security advisory:
https://t.co/Lk1URQhyBT
#NextJS #Vercel #CVE202694545 #RCE #WebSecurity #Vulnerability #ThreatIntel #DDW #DarkWeb
🔍 SploitScan: Investigating CVE-2024-21413
A quick demo using SploitScan to retrieve vulnerability and publicly available exploit information for a specific CVE. 💻🛡️
GitHub
Educational & defensive security research only
#SploitScan#CVE#CyberSecurity#InfoSec
F5, BIG-IP, a 20-year-old primitive, a security appliance, an "authentication" mechanism - and a CISA promise ring.
Yes, it's CVE-2026-94127.
Give us strength. Speak soon xo
https://t.co/1l3e0Y3wNN
Seems highly likely this was the vuln used to hack the FBI.
CVE-2026-35273 - Missing Authentication for Critical Function
It came out June 11th and was immediately added to the CISA Known Exploited list - which means it was seen in real world attacks all the way back then.
🚨يمكن لمختصين الأمن السيبراني والهكر من خلال مكالمة على واتساب whatsapp الوصول إلى :
- الحصول على الموقع الجغرافي و عنوان الـ IP
- عدد الأجهزة المتصلة بالحساب المخترق
- معرفة اذا كان يتصل بالأنترنت من خلال البيانات المحلية ام من خلال شبكة WiFi
- معلومات عن الجهاز Android ام iPhone ونظام التشغيل
هذه المعلومات يمكن الحصول عليها من خلال مكالمة واحدة فقط (في حال تم الرد عليها)