14,971 WordPress Sites Cleaned in Global SocGholish Takedown

2026-06-19T20:51:47Ze4b3dafe0a5b9e552b444a7fe7cb037c4c9a5e2b8c50540e0cc15c158eb29ef6
CISA-KEVCVE-2026-20181CVE-2026-20253CVE-2026-42055CVE-2026-42530Cisco-ISEDragonForceElasticsearchF5FortiBleedFortinetMicrosoft-Defender-RoguePlanet','CVE-2026-50656'Microsoft-Teams-abuseNGINXSocGholishSplunkTorWordPressclippercredentialscrypto-theftdata-leaklaw-enforcement-takedownmalwarevulnerability

What happened

Multiple high-impact security events reported: Operation EndGame disrupted the SocGholish malware distribution network, taking down 106 servers and cleaning 14,971 WordPress sites. Major data exposures include an exposed Elasticsearch cluster with ~24 billion stolen-credentials records and a leakage of admin VPN credentials for ~75,000 Fortinet devices (“FortiBleed”). Several critical vulnerabilities were disclosed/mitigated or added to KEV — Splunk Enterprise CVE-2026-20253 (CVSS 9.8) added to CISA’s KEV, Cisco ISE CVE-2026-20181 (CVSS 9.1) patched, and F5/NGINX issues CVE-2026-42530 and CVE-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e4b3dafe0a5b9e552b444a7fe7cb037c4c9a5e2b8c50540e0cc15c158eb29ef6
Enrichment time
2026-06-19T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 14,971 WordPress Sites Cleaned in Global SocGholish Takedown · Baitaphish