WordPress, SonicWall, SharePoint, and OpenSSL Vulnerabilities Highlight Active Exploitation
This week's security landscape is dominated by critical vulnerabilities in widely used software, including WordPress, SonicWall, Microsoft SharePoint, and OpenSSL, with many already being actively exploited in the wild.

This week's security recap paints a grim picture of the threat landscape, with critical vulnerabilities discovered and actively exploited across a range of popular software. From unauthenticated remote code execution in WordPress Core to zero-day attacks on SonicWall VPN appliances and a SharePoint Server flaw added to CISA's Known Exploited Vulnerabilities (KEV) catalog, defenders are facing a barrage of immediate threats.
The most concerning disclosure involves a pre-authenticated remote code execution (RCE) vulnerability in WordPress Core, dubbed 'wp2shell'. Disclosed by Searchlight Cyber, this flaw (a chain of CVE-2026-63030 and CVE-2026-60137) allows unauthenticated attackers to execute arbitrary code on a standard WordPress installation without any special conditions or plugins. Proof-of-concept exploits are already circulating, and early signs of in-the-wild exploitation have been observed, prompting urgent calls for immediate patching.
SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances are also under siege. A threat actor, codenamed UTA0533, has been exploiting two previously undocumented vulnerabilities (CVE-2026-15409 and CVE-2026-15410) as zero-days since June 22, 2026, prior to their public disclosure. These flaws, which can be chained for arbitrary command execution, were used in conjunction with custom malware designed specifically for the SMA appliances. SonicWall released patches last week, but the active exploitation highlights the speed at which attackers move.
Microsoft SharePoint Server is also in the crosshairs, with a critical deserialization vulnerability (CVE-2026-58644) added to CISA's KEV catalog. This flaw, which allows unauthorized attackers to execute arbitrary code, was exploited in the wild as a zero-day before Microsoft released patches as part of its July Patch Tuesday updates. This update also addressed a record-breaking 622 vulnerabilities in total, underscoring the sheer volume of security issues Microsoft is contending with.
Beyond these high-profile exploits, other significant vulnerabilities have emerged. A denial-of-service (DoS) flaw in OpenSSL, disclosed by Okta, allows unauthenticated attackers to trigger memory exhaustion with a mere 11-byte payload. While not leading to code execution, this HollowByte flaw can cripple servers by depleting available RAM. Patches have been released for various OpenSSL versions.
Additionally, a new malware framework named OkoBot has been identified, targeting Windows systems with the aim of stealing cryptocurrency seed phrases. OkoBot, an evolution of the TookPS downloader, utilizes a sophisticated framework with over 20 malicious payloads and implants, orchestrating attacks via SSH tunnels. It employs various methods, including exploiting browser extensions and injecting into cryptocurrency wallet processes, to achieve its objectives.
The proliferation of these vulnerabilities and active exploitation campaigns underscores a challenging security environment. The increasing sophistication of attack vectors, coupled with the speed at which vulnerabilities are weaponized, necessitates rapid patching, robust security monitoring, and proactive threat hunting. The trend of vulnerabilities being chained together or exploited as zero-days before patches are available remains a significant concern for organizations worldwide.
As AI-assisted tooling continues to lower the barrier for attackers to discover and weaponize vulnerabilities, the cybersecurity industry must adapt. The focus remains on swift response, comprehensive vulnerability management, and staying ahead of emerging threats that leverage both novel techniques and well-established software weaknesses.