New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
2026-09-18T19:23:59Z•bba03ee7140fe1e8edec7c655654fefd56dd81c2fee38fd72ec520bc0257bca2
CVE-2026-76460CVE-2026-77179CVE-2026-81642CVE-2026-85889CVE-2026-89026AI-securityAPTAndroid-malwareDDoSactive-exploitationauthentication-bypasscloud-securitycontainer-escapedata-breachdnsinfostealernpm-malwareprivilege-escalationremote-code-executionsoftware-supply-chainstate-sponsoredvulnerabilityzero-day
What happened
The document is a cybersecurity news feed covering critical vulnerabilities, active exploitation, malware campaigns, threat actors, supply-chain compromises, data breaches, and AI security incidents. Notable items include actively exploited Cisco ISE authentication bypass (CVE-2026-76460), exploited Issabel command execution (CVE-2026-89026), critical Unbound DNSSEC RCE (CVE-2026-81642), critical Docker Sandboxes host file access (CVE-2026-77179), and a CVSS 10.0 Azure AI Foundry privilege-escalation flaw (CVE-2026-85889). It also reports npm malware, AI coding-agent/plugin supply-chain risks,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- bba03ee7140fe1e8edec7c655654fefd56dd81c2fee38fd72ec520bc0257bca2
- Enrichment time
- 2026-09-18T19:23:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.