Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

2026-05-17T07:24:06Z917839bd4d1cab5000dc40fe20b1c7227b3f4a627570a6f99965c119cd6b2f31
CISA KEVCisco SD‑WANEximLinux LPEMicrosoft ExchangeNGINXP2P botnetRubyGems/GemStufferTurlaWooCommerce checkout skimmingWordPressactive exploitationauthentication bypassmalicious npm packagespatchingprivilege escalationremote code executionsupply chainvulnerabilitieszero‑day

What happened

The feed aggregates multiple high-impact security stories: several newly disclosed and actively exploited vulnerabilities across critical infrastructure and popular software (notably Cisco Catalyst SD‑WAN CVE-2026-20182 — CVSS 10.0 — added to CISA KEV, and Exchange Server CVE-2026-42897 under active exploitation). Other severe flaws include Exim BDAT (CVE-2026-45185, Dead.Letter), NGINX rewrite module RCE (CVE-2026-42945), Linux Fragnesia LPE (CVE-2026-46300), and the PraisonAI auth bypass (CVE-2026-44338) which was targeted within hours of disclosure. The feed also highlights ongoing supply‑s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
917839bd4d1cab5000dc40fe20b1c7227b3f4a627570a6f99965c119cd6b2f31
Enrichment time
2026-05-17T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.