Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

2026-05-17T01:24:03Z9509784b8f5d44d9c43863e02d169085fdbab0940e8412460051d0c26f16fc7b
CISA KEVCisco SD‑WANEximFragnesiaGemStufferKazuarLinux LPEMicrosoft ExchangeNGINXPraisonAIRubyGemsTurlaWooCommerceWordPressactive exploitationcheckout skimmingnode‑ipcsupply chainzero‑day

What happened

Recent reporting highlights a surge of high‑impact active exploitation and supply‑chain incidents. Notable active attacks and disclosures include WooCommerce checkout skimming via a Funnel Builder WordPress plugin flaw, Cisco Catalyst SD‑WAN Controller authentication bypass (CVE‑2026‑20182) exploited for admin access, on‑prem Exchange spoofing/XSS exploitation (CVE‑2026‑42897), fast exploitation attempts against PraisonAI missing‑auth endpoints (CVE‑2026‑44338), a critical Exim BDAT/GnuTLS memory corruption issue (CVE‑2026‑45185), an 18‑year‑old NGINX ngx_http_rewrite_module heap overflow (CVE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
9509784b8f5d44d9c43863e02d169085fdbab0940e8412460051d0c26f16fc7b
Enrichment time
2026-05-17T01:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.