Critical Vulnerabilities in WordPress Core (CVE-2026-64638) and N-able N-central (CVE-2026-18577) Actively Exploited

A pre-authentication XSS to code execution vulnerability (CVE-2026-64638) in WordPress Core, affecting versions since 4.7, has a public exploit available, putting over 500 million sites at risk. Additionally, the Storm-1175 ransomware group is actively exploiting an authentication bypass (CVE-2026-18577) in N-able's N-central remote management platform. Immediate updates are recommended for both.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai