Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
2026-09-16T07:23:59Z•00ea41ff687178473816328b97bc61713b667d69143f2f6220771f3a893f99fb
CVE-2026-42016CVE-2026-5430CVE-2026-76461CVE-2026-85706CISA KEVCisco Secure Email GatewayGitLabGiteaMQTTTelegram malwareWSO2WordPressactive exploitationbanking malwarebrowser extensioncloud credential theftconfidential computingcredential theftespionagephishingremote code executionsession hijackingsupply chainweb shellzero-day
What happened
The feed highlights multiple high-impact cybersecurity threats, including active exploitation of critical vulnerabilities in WSO2 API Manager, Cisco Secure Email Gateway, Gitea, GitLab, WooCommerce Wholesale Lead Capture, and other exposed technologies. Reported activity includes unauthenticated remote code execution, arbitrary file upload and web-shell deployment, account takeover, root-level command execution, credential and session-token theft, espionage malware, supply-chain compromise, cloud credential exfiltration, and rapid post-compromise lateral movement. Several entries describe in-w
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 00ea41ff687178473816328b97bc61713b667d69143f2f6220771f3a893f99fb
- Enrichment time
- 2026-09-16T07:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.