Critical Avada WordPress theme flaw enables zero-click RCE

2026-08-27T07:23:21Z582bcb68233c530508812e18fecddb37c1117f8e062dfe7a8eb3ca36a66b81e8
active-exploitationavadacloud-securitycyberattackdata-breachddosespionagegiteagovernmentgpu-securityhealthcareidentity-securitymicrosoft-sharepointphishingphishing-as-a-serviceprivilege-escalationremote-code-executionrowhammerubiquitivulnerabilitywordpress

What happened

BleepingComputer security feed covering critical vulnerabilities, active exploitation, ransomware or cyberattack-related disruptions, data breaches, phishing operations, DDoS activity, espionage infrastructure disruption, and security product updates. Notable items include unauthenticated remote code execution in the Avada WordPress theme, active exploitation of Microsoft SharePoint and Gitea flaws, maximum-severity Ubiquiti vulnerabilities, GPU ECC bypass enabling root access, and attacks affecting healthcare and government organizations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
582bcb68233c530508812e18fecddb37c1117f8e062dfe7a8eb3ca36a66b81e8
Enrichment time
2026-08-27T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.