Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming
2026-05-17T01:24:03Z•9509784b8f5d44d9c43863e02d169085fdbab0940e8412460051d0c26f16fc7b
CISA KEVCisco SD‑WANEximFragnesiaGemStufferKazuarLinux LPEMicrosoft ExchangeNGINXPraisonAIRubyGemsTurlaWooCommerceWordPressactive exploitationcheckout skimmingnode‑ipcsupply chainzero‑day
What happened
Recent reporting highlights a surge of high‑impact active exploitation and supply‑chain incidents. Notable active attacks and disclosures include WooCommerce checkout skimming via a Funnel Builder WordPress plugin flaw, Cisco Catalyst SD‑WAN Controller authentication bypass (CVE‑2026‑20182) exploited for admin access, on‑prem Exchange spoofing/XSS exploitation (CVE‑2026‑42897), fast exploitation attempts against PraisonAI missing‑auth endpoints (CVE‑2026‑44338), a critical Exim BDAT/GnuTLS memory corruption issue (CVE‑2026‑45185), an 18‑year‑old NGINX ngx_http_rewrite_module heap overflow (CVE
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 9509784b8f5d44d9c43863e02d169085fdbab0940e8412460051d0c26f16fc7b
- Enrichment time
- 2026-05-17T01:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.