Follow the latest coverage, related explainers and connected technology stories.
Kiteworks has released updates to address 126 vulnerabilities, including CVE-2026-54154 in the Email Protection Gateway, which could have been exploited remotely and without authentication to take control of a device with full administrative privileges. Users of versions older than 9.4.1 should update immediately.
Attackers have begun exploiting CVE-2026-87902 in WordPress to write PHP files to disk and run shell commands when those files are accessed, just hours after the patch was released. Site administrators are advised to update to version 7.1.2 and review logs immediately.
CISA added CVE-2026-7273 in Zyxel GS1900 switches to its catalog of exploited vulnerabilities and ordered U.S. federal civilian agencies to address it by Thursday. GreyNoise says attackers exploited the vulnerability to compromise 996 switches in 48 countries.
Researchers disclosed details of a CSRF vulnerability in the WordPress core that, without requiring an attacker account, allows a site to be forced to install a theme and execute PHP code, provided that a logged-in administrator visits a specially crafted link. WordPress addressed the issue in version 7.1.1, while the proof-of-concept exploit has become publicly available.