wp2shell Unauth RCE Hits WordPress Core, Plus a 7-Zip Flaw (07/18/2026)
- › A public proof-of-concept dropped for wp2shell, an unauthenticated remote code execution chain in WordPress Core that runs code from a single anonymous HTTP request.
- › 7-Zip 26.02 fixes a heap overflow that runs code when a user opens a crafted archive, and 7-Zip has no auto-update.
- › Microsoft warns of a surge in ACR Stealer attacks lifting passwords, session tokens, and documents from enterprise customers.
- › Ernst & Young disclosed a data breach after attackers hit a support system.
- › A lock screen bug let Google Gemini send SMS messages from a locked Android phone without a PIN.
Today is a patch day, and the clock started the moment the exploit went public. wp2shell is an unauthenticated remote code execution chain in WordPress Core, the software behind a large share of the web, and a working proof-of-concept is already on GitHub. Add a 7-Zip flaw with no auto-update to push the fix and a surge in ACR Stealer, and the theme is speed: how fast the adversary moves once the writeup is out, and how fast you can close the gap.
Top 5 Critical Security Alerts
1. Public Exploit Drops for an Unauthenticated WordPress Core RCE
Researchers disclosed wp2shell, a chain of two WordPress Core flaws (CVE-2026-63030, a REST API batch-route confusion, and CVE-2026-60137, a SQL injection) that lets an anonymous HTTP request run code on a vulnerable site, and a working proof-of-concept is now public on GitHub (The Hacker News, BleepingComputer). The full chain hits WordPress 6.9.0 through 6.9.4 (fixed in 6.9.5) and 7.0.0 through 7.0.1 (fixed in 7.0.2), and the 6.8 branch carries the SQL injection alone (fixed in 6.8.6). WordPress has pushed forced auto-updates, but any site that blocks them is now exposed to a copy-paste attack.
Operator Note: Unauthenticated plus public PoC plus a target this common is the worst combination there is. If you run self-managed WordPress, confirm the version tonight, because the scanning has already started.
2. 7-Zip Patches a Code-Execution Flaw With No Auto-Update
7-Zip 26.02 fixes a heap-based buffer overflow in its handling of XZ-compressed data (tracked as ZDI-26-444) that lets an attacker run code as the user when they open a crafted archive (BleepingComputer). There is no evidence of active exploitation yet, and there is also no auto-update, so the fix only lands if someone downloads it. That second gap is the one that keeps 7-Zip flaws alive on machines for years.
Operator Note: 7-Zip sits on countless endpoints and updates itself never. Push 26.02 through your software deployment tooling rather than trusting users to fetch it.
3. Microsoft Warns of a Surge in ACR Stealer Attacks
Microsoft reports a surge in ACR Stealer activity against its enterprise customers, with the malware lifting browser-stored passwords, authentication tokens, and sensitive documents (BleepingComputer). Stolen session tokens are the prize, because a live token walks the attacker straight past the password and the second factor into the account, which is the identity-first pattern we keep coming back to in why attackers log in instead of breaking in.
4. Ernst & Young Discloses a Breach After a Support System Hack
Ernst & Young confirmed a data breach after attackers compromised a support system (BleepingComputer). A global professional services firm holds client financials, audit files, and deal data, which makes the support system a side door into some of the most sensitive material an attacker could want.
5. Gemini Could Send Texts From a Locked Android Phone
Google is fixing a lock screen bug that let its Gemini assistant send SMS messages from a locked Android phone without the PIN (The Register). The lock screen is supposed to be the line between “has the phone” and “controls the phone,” and an assistant that acts before the PIN quietly erases it.
Additional Security Alerts
Threat Intelligence
- The Gentlemen Overtakes Qilin as the Most Prolific Ransomware Crew: A new report names The Gentlemen as the busiest ransomware operation, displacing Qilin at the top of the leaderboard. Infosecurity Magazine
- CISA Adds an Exploited SharePoint Zero-Day to KEV: CISA added CVE-2026-58644, an actively exploited SharePoint remote code execution flaw, to its Known Exploited Vulnerabilities catalog. The Hacker News
Security Tools & Best Practices
- Windows Server 2022 Hits End of Mainstream Support in 90 Days: The clock is running on Windows Server 2022 mainstream support, and organizations still standardizing on it need a plan before the deadline. BleepingComputer
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.