Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

2026-06-21T07:24:17Zec811c7658d8b1283b105a8c787caea6b0743432635ffb20889b5508094aa7a7
Apple SecureROMCVE-2026-42530CVE-2026-48907CVE-2026-50656FortiBleedFortiGateFortinetGravity SMTPJCEJetBrainsJoomlaMastraMicrosoft DefenderOAuth-token-abuseRCERoguePlanetSalesforce/Klue integration issue','ransomware','Gentlemen RaaS'WordPressinformation-disclosuremalicious-pluginsnginxnpm compromisesupply-chainunpatchable-flawusbliter8

What happened

A broad set of active threats and patches were reported: attackers are exploiting a recently fixed Gravity SMTP WordPress information-disclosure bug (CVE-2026-4020) to steal API keys; F5/NGINX fixes address critical RCE (CVE-2026-42530); CISA warns of an actively exploited Joomla JCE code-execution flaw (CVE-2026-48907); Microsoft disclosed a Defender privilege-escalation zero-day (CVE-2026-50656); and Apple A12/A13 SecureROM is broken by an unpatchable usbliter8 exploit. Additional high-impact activity includes FortiBleed compromises of tens of thousands of FortiGate devices, supply-chain and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ec811c7658d8b1283b105a8c787caea6b0743432635ffb20889b5508094aa7a7
Enrichment time
2026-06-21T07:24:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.