New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

2026-09-18T19:23:59Z•bba03ee7140fe1e8edec7c655654fefd56dd81c2fee38fd72ec520bc0257bca2
CVE-2026-76460CVE-2026-77179CVE-2026-81642CVE-2026-85889CVE-2026-89026AI-securityAPTAndroid-malwareDDoSactive-exploitationauthentication-bypasscloud-securitycontainer-escapedata-breachdnsinfostealernpm-malwareprivilege-escalationremote-code-executionsoftware-supply-chainstate-sponsoredvulnerabilityzero-day

What happened

The document is a cybersecurity news feed covering critical vulnerabilities, active exploitation, malware campaigns, threat actors, supply-chain compromises, data breaches, and AI security incidents. Notable items include actively exploited Cisco ISE authentication bypass (CVE-2026-76460), exploited Issabel command execution (CVE-2026-89026), critical Unbound DNSSEC RCE (CVE-2026-81642), critical Docker Sandboxes host file access (CVE-2026-77179), and a CVSS 10.0 Azure AI Foundry privilege-escalation flaw (CVE-2026-85889). It also reports npm malware, AI coding-agent/plugin supply-chain risks,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
bba03ee7140fe1e8edec7c655654fefd56dd81c2fee38fd72ec520bc0257bca2
Enrichment time
2026-09-18T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.