CRITICAL 4 min read 21 Jul 2026

CVE-2026-63030: Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital Leads Today's Security Review

What changed Finding 01 records CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital, attributed to digital.nhs.uk. Finding 02 records CVE-2026-39808 — OS Command Injection vulnerability, attributed to fortiguard.fortinet.com. Finding 03 records CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks, attributed to www.bleepingcomputer.com.

Key findings
01
CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital
CRITICAL
Exploit availability / observed attacks: Observed in-the-wild exploitation is confirmed.
02
CVE-2026-39808 — OS Command Injection vulnerability
CRITICAL
Exploit availability / observed attacks: Observed in-the-wild exploitation is confirmed.
03
CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks
CRITICAL
Exploit availability / observed attacks: Observed in-the-wild exploitation is confirmed.
04
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
HIGH
Exploit availability / observed attacks: Observed in-the-wild exploitation is confirmed.
05
CVE-2025-3646 — Missing Authentication for Critical Function vulnerability
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation is not confirmed.
06
CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities
MEDIUM
Exploit availability / observed attacks: Observed in-the-wild exploitation is not confirmed.
07
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
INFO
Exploit availability / observed attacks: Observed in-the-wild exploitation status is unknown.

What changed

Finding 01 records CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital, attributed to digital.nhs.uk.

Finding 02 records CVE-2026-39808 — OS Command Injection vulnerability, attributed to fortiguard.fortinet.com.

Finding 03 records CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks, attributed to www.bleepingcomputer.com.

Finding 04 records SonicWall SMA1000 flaws exploited as zero-days to push custom malware, attributed to www.bleepingcomputer.com.

Finding 05 records CVE-2025-3646 — Missing Authentication for Critical Function vulnerability, attributed to nvd.nist.gov.

Finding 06 records CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities, attributed to ubuntu.com.

Finding 07 records SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines, attributed to thehackernews.com.

Why it matters

Finding 01 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.

Finding 01 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.

Finding 02 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.

Finding 02 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.

Finding 03 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.

Finding 03 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.

Finding 04 requires assessment at the evidence-backed High priority. Observed in-the-wild exploitation is confirmed.

Finding 04 priority rationale: the frozen public severity is HIGH, and observed in-the-wild exploitation is confirmed.

Finding 05 requires assessment at the evidence-backed Medium priority. Observed in-the-wild exploitation is not confirmed.

Finding 05 priority rationale: the frozen public severity is MEDIUM, and observed in-the-wild exploitation is not confirmed.

Finding 06 requires assessment at the evidence-backed Medium priority. Observed in-the-wild exploitation is not confirmed.

Finding 06 priority rationale: the frozen public severity is MEDIUM, and observed in-the-wild exploitation is not confirmed.

Finding 07 requires assessment at an unbadged evidence-limited priority. Observed in-the-wild exploitation status is unknown.

Finding 07 priority rationale: the frozen public severity is INFO, and observed in-the-wild exploitation status is unknown.

  • Recommended actions
  • Finding 01 exposure owners: review CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 01 remediation owners: use the cited source for CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital to document the patch or mitigation decision.
  • Finding 02 exposure owners: review CVE-2026-39808 — OS Command Injection vulnerability, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 02 remediation owners: use the cited source for CVE-2026-39808 — OS Command Injection vulnerability to document the patch or mitigation decision.
  • Finding 03 exposure owners: review CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 03 remediation owners: use the cited source for CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks to document the patch or mitigation decision.
  • Finding 04 exposure owners: review SonicWall SMA1000 flaws exploited as zero-days to push custom malware, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 04 remediation owners: use the cited source for SonicWall SMA1000 flaws exploited as zero-days to push custom malware to document the patch or mitigation decision.
  • Finding 05 exposure owners: review CVE-2025-3646 — Missing Authentication for Critical Function vulnerability, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 05 remediation owners: use the cited source for CVE-2025-3646 — Missing Authentication for Critical Function vulnerability to document the patch or mitigation decision.
  • Finding 06 exposure owners: review CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 06 remediation owners: use the cited source for CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities to document the patch or mitigation decision.
  • Finding 07 exposure owners: review SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines, identify potentially affected deployments, and record whether the cited source applies.
  • Finding 07 remediation owners: use the cited source for SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines to document the patch or mitigation decision.

Evidence limits

Finding 01 is limited to the frozen evidence from https://digital.nhs.uk/cyber-alerts/2026/cc-4815. Observed in-the-wild exploitation is confirmed.

Finding 01 required limitation: fixed version or patch state unknown

Finding 01 required limitation: affected product not structured

Finding 02 is limited to the frozen evidence from https://fortiguard.fortinet.com/psirt/FG-IR-26-100. Observed in-the-wild exploitation is confirmed.

Finding 02 required limitation: fixed version or patch state unknown

Finding 02 required limitation: affected product not structured

Finding 03 is limited to the frozen evidence from https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/. Observed in-the-wild exploitation is confirmed.

Finding 03 required limitation: fixed version or patch state unknown

Finding 03 required limitation: affected product not structured

Finding 04 is limited to the frozen evidence from https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/. Observed in-the-wild exploitation is confirmed.

Finding 04 required limitation: grounded severity unavailable

Finding 04 required limitation: fixed version or patch state unknown

Finding 04 required limitation: affected product not structured

Finding 05 is limited to the frozen evidence from https://nvd.nist.gov/vuln/detail/CVE-2025-3646. Observed in-the-wild exploitation is not confirmed.

Finding 05 required limitation: exploitation not confirmed

Finding 05 required limitation: fixed version or patch state unknown

Finding 05 required limitation: affected product not structured

Finding 06 is limited to the frozen evidence from https://ubuntu.com/security/notices/USN-8558-1. Observed in-the-wild exploitation is not confirmed.

Finding 06 required limitation: exploitation not confirmed

Finding 06 required limitation: fixed version or patch state unknown

Finding 06 required limitation: affected product not structured

Finding 07 is limited to the frozen evidence from https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html. Observed in-the-wild exploitation status is unknown.

Finding 07 required limitation: grounded severity unavailable

Finding 07 required limitation: exploitation status unknown

Finding 07 required limitation: fixed version or patch state unknown

Finding 07 required limitation: affected product not structured

cve-2025-3646cve-2025-68950cve-2026-39808cve-2026-63030cve-2026-6875

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.