Cloudflare Deploys WAF Rules to Block Exploited WordPress Vulnerabilities CVE-2026-65640 and XSS2Shell
Cloudflare has issued emergency updates to its Web Application Firewall (WAF) to include detection rules for two critical WordPress vulnerabilities, CVE-2026-65640 and 'XSS2Shell', rated 8.8 and 8.9 on the CVSS scale. These vulnerabilities, which include a remote code execution bug and a login-page script injection leading to server takeover, affect a significant portion of the web.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.