What changed
Finding 01 records CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital, attributed to digital.nhs.uk.
Finding 02 records CVE-2026-39808 — OS Command Injection vulnerability, attributed to fortiguard.fortinet.com.
Finding 03 records CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks, attributed to www.bleepingcomputer.com.
Finding 04 records SonicWall SMA1000 flaws exploited as zero-days to push custom malware, attributed to www.bleepingcomputer.com.
Finding 05 records CVE-2025-3646 — Missing Authentication for Critical Function vulnerability, attributed to nvd.nist.gov.
Finding 06 records CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities, attributed to ubuntu.com.
Finding 07 records SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines, attributed to thehackernews.com.
Why it matters
Finding 01 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.
Finding 01 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.
Finding 02 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.
Finding 02 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.
Finding 03 requires assessment at the evidence-backed Critical priority. Observed in-the-wild exploitation is confirmed.
Finding 03 priority rationale: the frozen public severity is CRITICAL, and observed in-the-wild exploitation is confirmed.
Finding 04 requires assessment at the evidence-backed High priority. Observed in-the-wild exploitation is confirmed.
Finding 04 priority rationale: the frozen public severity is HIGH, and observed in-the-wild exploitation is confirmed.
Finding 05 requires assessment at the evidence-backed Medium priority. Observed in-the-wild exploitation is not confirmed.
Finding 05 priority rationale: the frozen public severity is MEDIUM, and observed in-the-wild exploitation is not confirmed.
Finding 06 requires assessment at the evidence-backed Medium priority. Observed in-the-wild exploitation is not confirmed.
Finding 06 priority rationale: the frozen public severity is MEDIUM, and observed in-the-wild exploitation is not confirmed.
Finding 07 requires assessment at an unbadged evidence-limited priority. Observed in-the-wild exploitation status is unknown.
Finding 07 priority rationale: the frozen public severity is INFO, and observed in-the-wild exploitation status is unknown.
- Recommended actions
- Finding 01 exposure owners: review CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital, identify potentially affected deployments, and record whether the cited source applies.
- Finding 01 remediation owners: use the cited source for CVE-2026-63030 — Critical Vulnerability Chain in WordPress Core Under Exploitation (wp2shell) - NHS England Digital to document the patch or mitigation decision.
- Finding 02 exposure owners: review CVE-2026-39808 — OS Command Injection vulnerability, identify potentially affected deployments, and record whether the cited source applies.
- Finding 02 remediation owners: use the cited source for CVE-2026-39808 — OS Command Injection vulnerability to document the patch or mitigation decision.
- Finding 03 exposure owners: review CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks, identify potentially affected deployments, and record whether the cited source applies.
- Finding 03 remediation owners: use the cited source for CVE-2026-6875 — Critical ServiceNow code execution flaw now exploited in attacks to document the patch or mitigation decision.
- Finding 04 exposure owners: review SonicWall SMA1000 flaws exploited as zero-days to push custom malware, identify potentially affected deployments, and record whether the cited source applies.
- Finding 04 remediation owners: use the cited source for SonicWall SMA1000 flaws exploited as zero-days to push custom malware to document the patch or mitigation decision.
- Finding 05 exposure owners: review CVE-2025-3646 — Missing Authentication for Critical Function vulnerability, identify potentially affected deployments, and record whether the cited source applies.
- Finding 05 remediation owners: use the cited source for CVE-2025-3646 — Missing Authentication for Critical Function vulnerability to document the patch or mitigation decision.
- Finding 06 exposure owners: review CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities, identify potentially affected deployments, and record whether the cited source applies.
- Finding 06 remediation owners: use the cited source for CVE-2025-68950 — USN-8558-1: ImageMagick vulnerabilities to document the patch or mitigation decision.
- Finding 07 exposure owners: review SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines, identify potentially affected deployments, and record whether the cited source applies.
- Finding 07 remediation owners: use the cited source for SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines to document the patch or mitigation decision.
Evidence limits
Finding 01 is limited to the frozen evidence from https://digital.nhs.uk/cyber-alerts/2026/cc-4815. Observed in-the-wild exploitation is confirmed.
Finding 01 required limitation: fixed version or patch state unknown
Finding 01 required limitation: affected product not structured
Finding 02 is limited to the frozen evidence from https://fortiguard.fortinet.com/psirt/FG-IR-26-100. Observed in-the-wild exploitation is confirmed.
Finding 02 required limitation: fixed version or patch state unknown
Finding 02 required limitation: affected product not structured
Finding 03 is limited to the frozen evidence from https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/. Observed in-the-wild exploitation is confirmed.
Finding 03 required limitation: fixed version or patch state unknown
Finding 03 required limitation: affected product not structured
Finding 04 is limited to the frozen evidence from https://www.bleepingcomputer.com/news/security/sonicwall-sma1000-flaws-exploited-as-zero-days-to-push-custom-malware/. Observed in-the-wild exploitation is confirmed.
Finding 04 required limitation: grounded severity unavailable
Finding 04 required limitation: fixed version or patch state unknown
Finding 04 required limitation: affected product not structured
Finding 05 is limited to the frozen evidence from https://nvd.nist.gov/vuln/detail/CVE-2025-3646. Observed in-the-wild exploitation is not confirmed.
Finding 05 required limitation: exploitation not confirmed
Finding 05 required limitation: fixed version or patch state unknown
Finding 05 required limitation: affected product not structured
Finding 06 is limited to the frozen evidence from https://ubuntu.com/security/notices/USN-8558-1. Observed in-the-wild exploitation is not confirmed.
Finding 06 required limitation: exploitation not confirmed
Finding 06 required limitation: fixed version or patch state unknown
Finding 06 required limitation: affected product not structured
Finding 07 is limited to the frozen evidence from https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html. Observed in-the-wild exploitation status is unknown.
Finding 07 required limitation: grounded severity unavailable
Finding 07 required limitation: exploitation status unknown
Finding 07 required limitation: fixed version or patch state unknown
Finding 07 required limitation: affected product not structured