Vulnerability threat dossier

CVE-2026-63030

wordpresswordpress

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

VTP deterministic threat44.0of 100 · CVSS excluded

VTP analyst assessment

WordPress REST route confusion is known exploited

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence92%
Public exploitation · VTP factKEV

Assessment

CVE-2026-63030 is a WordPress REST API batch-route confusion flaw. Combined with CVE-2026-60137 SQL injection, it can enable SQL injection and remote code execution. CISA and ENISA list known exploitation.

Why it matters

  • The REST API is a reachable application surface on affected WordPress sites.
  • The required companion SQL-injection flaw can turn route confusion into database access and code execution.
  • BleepingComputer reported a Chinese-speaking actor exploiting WordPress vulnerabilities to steal backend database data.

Evidence

4 record references and 3 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The reporting does not establish that CVE-2026-63030 was the specific WordPress flaw used in every reported incident.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use WordPress 6.9.x, update to 6.9.5 or later; if you use 7.0.x, update to 7.0.2 or later.

AI baseline history (5)
  1. BASELINE ASSESSED
    WordPress REST route confusion is known exploitedgpt-5.6-terra · low
  2. BASELINE ASSESSED
    WordPress REST route confusion exploit chaingpt-5.6-terra · low
  3. BASELINE ASSESSED
    WordPress REST API route confusion enabling SQLi chaingpt-5.6-sol · high
  4. BASELINE ASSESSED
    Critical WordPress pre-auth chain in KEVgpt-5.6-sol · high
  5. BASELINE ASSESSED
    WordPress REST batch-route confusiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.1095th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.10; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL DECREASEEPSS changed materially from 0.97 to 0.10
RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
RESEARCH PUBLICATIONNew technical research
ACTIVE EXPLOITATIONENISA EU KEV entry added
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

7publications detected
7underlying evidence chains

3 primary sources · 0 dependent secondary reports · 3 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2026-63030ACTIVE
Evidence
04

Event history

Threat timeline

  1. 18:3624 Sept
    EPSS MATERIAL DECREASE

    EPSS changed materially from 0.97 to 0.10

    Predictive context changed; this is not exploitation evidence.

  2. 14:5728 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-63030.

  3. 13:0824 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-63030.

  4. 21:2714 Aug
    RESEARCH PUBLICATION

    New technical research

    Rapid7 Research published evidence linked to CVE-2026-63030.

  5. 07:2703 Aug
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2026-63030.

  6. 18:0023 Jul
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2026-63030.

  7. 00:0021 Jul
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. This is public intelligence, not a VTP sensor observation.

  8. 00:0021 Jul
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

CVE-2022-0847CVE-2023-54391CVE-2026-34908CVE-2026-34909CVE-2026-34910CVE-2026-54569CVE-2026-56271CVE-2026-60004CVE-2026-60137CVE-2026-63030CVE-2026-7273CVE-2026-79756
Separate evidence group
Original

Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!

CVE-2026-0265CVE-2026-16232CVE-2026-19681CVE-2026-21820CVE-2026-3576CVE-2026-56274CVE-2026-59774CVE-2026-60137CVE-2026-63030CVE-2026-66066CVE-2026-6826CVE-2026-9082CVE-2026-9198
Separate evidence group
Original

Nuclei Templates v10.4.8 - Release Notes

New Templates Added: 112 | CVEs Added: 101 | First-time contributions: 22 🔥 Release Highlights 🔥 [CVE-2026-72898] Metabase - Unauthenticated SQL Injection (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-71362 ] Adobe Commerce/Magento - Customer Session Identity Switch (@0x_Akoko, @dinosn ) [critical] 🔥 [ CVE-2026-64849 ] MLflow Webhook SSRF - Unauth Full-Read via Redirect Bypass ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [CVE-2026-64638] WordPress Core < 7.0.3 - Preauth Reflected XSS (XSS2Shell) ( @flx | Nick Vidovic (greenhats)) [high] 🔥 [ CVE-2026-63077 ] JetBrains TeamCity < 2026.1.3, 2025.11.7 - RCE (@0x_Akoko, @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-59774] Gitea 1.22.1-1.27.0 - Unauthenticated Arbitrary File Read ( @ashish-cybersec ) [critical] 🔥 [ CVE-2026-58644 ] Microsoft SharePoint Server - WS-Federation Deserialization RCE ( @pdteam ) [critical] (kev) (vKEV) 🔥 [CVE-2026-57219] RabbitMQ Management - OAuth 2 Client Secret Disclosure ( @Aryu-RU ) [high] 🔥 [ CVE-2026-56270 ] Flowise <= 3.0.13 - Unauth OAuth Configuration Disclosure (@0x_Akoko, @pdteam ) [high] (vKEV) 🔥 [CVE-2026-53576] Kestra <= 1.3.20 - Remote Code Execution (@0x_Akoko, @pdteam , @Aryu-RU ) [critical] (vKEV) 🔥 [ CVE-2026-52806 ] Gogs <= 0.14.2 - Auth RCE via git rebase Argument Injection ( @dhiyaneshdk , @pdteam ) [critical] (vKEV) 🔥 [ CVE-2026-49049 ] JoomShaper Helix3 <=3.1.0 - Unauth Arbitrary JSON File Write ( @dhiyaneshdk , @pdteam ) [high] (vKEV) 🔥 [ CVE-2026-48939 ] Joomla iCagenda < 3.9.10 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-40217 ] LiteLLM < 1.25.0 - Remote Code Execution ( @ritikchaddha ) [high] (vKEV) 🔥 [ CVE-2026-34908 ] UniFi OS - Authentication Bypass via Path Traversal (..%2f) ( @Boreas37 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-20896 ] Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Auth Bypass ( @prithvee07 ) [critical] (vKEV) 🔥 [ CVE-2026-19478 ] GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method Invocation (@0x_Akoko, @dhiyaneshdk ) [critical] (vKEV) 🔥 What's Changed Bug Fixes Corrected an unclosed string literal in the CVE-2026-0558 dsl matcher (PR #16950 ). Fixed a broken matcher in the newly added CVE-2026-3395 template (PR #16886 ). Fixed the username key structure in mysql-empty-password.yaml (PR #16939 ). Fixed indentation in kubernetes-metrics.yaml (PR #16934 ). Added the missing capture group to regex extractors in oracle-containers-panel, smtp-credentials-exposure and springboot-x-application-context (PR #16663 ). Corrected the max-request counter for CVE-2021-40822 (PR #16875 ). Corrected email and password variable names in CVE-2025-68613 (PR #16918 ). Renamed Wix-detect.yaml, cve-2026-44338 .yaml and CVE-2026-44381.yaml to match the naming convention (PRs #16731 , #16729 , #16730 ). Moved 22 invalid or rejected CVE templates to vulnerabilities (PR #16889 , Issue #16115 ). Removed CVE-2024-28752 .yaml (PR #16745 ). False Negatives CVE-2017-5521 , CVE-2017-7615 and CVE-2020-23575 — regexes were placed in word matchers, so these templates could never fire (PR #16666 ). nh-c2 — corrected a dsl matcher that could never match (PR #16739 ). CVE-2026-21858 — added a /rest/sentry.js fallback to detect n8n 1.65.0 through 1.111.x (PR #16888 ). CVE-2025-14847 — now detects vulnerable MongoDB 8.0.x via buildinfo read-size truncation (PR #16741 ). CVE-2025-32969 — removed an incorrect content_type matcher that suppressed matches (PR #16704 ). CVE-2023-37629 — closed the filename quote before the .php extension so the payload is well formed (PR #16709 ). False Positives CVE-2025-29927 — added negative matchers so WAF block pages returning HTTP 200 no longer match (PR #16870 , Issue #16782 ). wp-vr-view-xss and vrview-xss — no longer fire on hosts that escape the payload (PR #16912 ). wordpress-eol — tightened an over-broad version regex (PR #16752 ). CVE-2021-24139 — both conditions must now match rather than either (PR #16748 ). Marked prec

CVE-2015-7501CVE-2017-5521CVE-2017-7615CVE-2019-1003030CVE-2020-10204CVE-2020-23575CVE-2021-24139CVE-2021-40822CVE-2022-1281CVE-2022-29013CVE-2023-25826CVE-2023-37629CVE-2024-0200CVE-2024-13985CVE-2024-28752CVE-2024-37014CVE-2024-55890CVE-2024-56064CVE-2024-57726CVE-2025-0520CVE-2025-11953CVE-2025-13342CVE-2025-13528CVE-2025-14847CVE-2025-20282CVE-2025-26399CVE-2025-29927CVE-2025-32969CVE-2025-68613CVE-2025-71324CVE-2026-0558CVE-2026-0717CVE-2026-10768CVE-2026-1115CVE-2026-11387CVE-2026-12394CVE-2026-13001CVE-2026-13147CVE-2026-14483CVE-2026-14894CVE-2026-15733CVE-2026-15826CVE-2026-16268CVE-2026-17505CVE-2026-17532CVE-2026-17594CVE-2026-19478CVE-2026-19598CVE-2026-19900CVE-2026-20896CVE-2026-21858CVE-2026-25231CVE-2026-25895CVE-2026-2614CVE-2026-26217CVE-2026-27542CVE-2026-27796CVE-2026-3001CVE-2026-30965CVE-2026-32255CVE-2026-3395CVE-2026-34908CVE-2026-34976CVE-2026-35037CVE-2026-3576CVE-2026-40217CVE-2026-40280CVE-2026-4060CVE-2026-41042CVE-2026-41432CVE-2026-42461CVE-2026-44338CVE-2026-44381CVE-2026-45332CVE-2026-45695CVE-2026-48030CVE-2026-48939CVE-2026-49049CVE-2026-49069CVE-2026-50160CVE-2026-5032CVE-2026-52806CVE-2026-53519CVE-2026-53576CVE-2026-53629CVE-2026-53753CVE-2026-53755CVE-2026-53976CVE-2026-54917CVE-2026-55087CVE-2026-55224CVE-2026-56265CVE-2026-56270CVE-2026-57219CVE-2026-57827CVE-2026-58138CVE-2026-58644CVE-2026-59774CVE-2026-61511CVE-2026-61808CVE-2026-63030CVE-2026-63077CVE-2026-64638CVE-2026-64849CVE-2026-65442CVE-2026-65919CVE-2026-67208CVE-2026-6826CVE-2026-6854CVE-2026-69084CVE-2026-69251CVE-2026-71209CVE-2026-71362CVE-2026-72898CVE-2026-8236CVE-2026-8237CVE-2026-8857CVE-2026-9506
Separate evidence group
Original

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe <rhowe425> Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of local directories. There is currently no CVE assigned to this vulnerability. Issuance is pending with MITRE. Pterodactyl Panel CVE-2025-49132 Remote Code Execution Authors: 0xtensho and jheysel-r7 Type: Exploit Pull request: #21452 contributed by jheysel-r7 Path: `linux/http/pterodactyl_locales_locale_json` AttackerKB reference: CVE-2025-49132 Description: This adds a module which exploits a vulnerability in Pterodactyl Panel before version 1.11.11 that allows unauthenticated remote code execution through improper handling of locale file operations. The vulnerability, CVE-2025-49132, exists in the locale.json endpoint which allows path traversal and arbitrary file creation. This combination of capabilities results in remote code execution in the context of the user running the web server. SonicWall SMA1000 WorkPlace wsproxy SSRF Remote Command Execution Authors: Deral Heiland, Rapid7 Vulnerability Research, and Ryan Emmons Type: Exploit Pull request: # 21678 contributed by dheiland-r7(https://github.com/dheiland-r7) Path: `linux/http/sonicwall_sma1000_wsproxy_rce` AttackerKB reference: CVE-2026-15409 Description: This adds a new exploit module for CVE-2026-15409, a Server-Side Request Forgery (SSRF) vulnerability in the SonicWall SMA1000 WorkPlace wsproxy service. Fragnesia LPE (CVE-2026-46300) Authors: William Bowling and msutovsky-r7 Type: Exploit Pull request: #21456 contributed by msutovsky-r7 Path: linux/local/cve_2026_46300_fragnesia AttackerKB reference: CVE-2026-46300 Description: This adds a local module for the Fragnesia exploit which is a page-cache replacement vulnerability in the Linux kernel's XFRM (IPsec) subsystem, tracked as CVE-2026-46300. Ghost CMS Remote Code Execution Authors: Cristian-Alexandru Staicu and Maksim Rogov Type: Exploit Pull request: #21234 contributed by vognik Path: multi/http/ghostcms_auth_rce_cve_2026_29053 AttackerKB reference: CVE-2026-22594 Description: This adds an exploit module for Ghost CMS (CVE-2026-29053) that achieves remote code execution by uploading a malicious theme. Ghost's theme renderer evaluates untrusted JSONPath expressions through the {{#get}} helper, letting the module inject and trigger arbitrary code once a theme is uploaded and activated. You'll need valid admin or staff credentials to authenticate. Joomla Content Editor Unauthenticated File Upload RCE Authors: David Jardin, Uwe Flottemesch, and ispyispyispy Type: Exploit Pull request: #21615 contributed by 15py15py15py Path: multi/http/joomla_com_jce_unauth_file_upload_rce AttackerKB reference: CVE-2026-48907 Description: This adds a new exploit module for CVE-2026-48907, an unauthenticated arbitrary profile creation vulnerability in the JCE (Joomla Content Editor) extension for Joomla!. The profiles.import task fails t

CVE-2025-49132CVE-2026-15409CVE-2026-22594CVE-2026-27760CVE-2026-29053CVE-2026-33017CVE-2026-3891CVE-2026-46300CVE-2026-48907CVE-2026-52806CVE-2026-60137CVE-2026-63030
Separate evidence group
Original

Nuclei Templates v10.4.7 - Release Notes

New Templates Added: 122 | CVEs Added: 49 | First-time contributions: 23 🔥 Release Highlights 🔥 [CVE-2026-63030] WordPress Core 6.9-7.0.1 - Pre-Auth Batch-Route Confusion ( @slcyber , @mielverkerken , @pdteam , @FLX-0x00 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-60004 ] Gitea <= 1.27.0 - Pre-Auth Remote Code Execution (@0x_Akoko) [critical] 🔥 [ CVE-2026-58455 ] Dockwatch <= 0.6.567 - OS Command Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56291 ] Balbooa Forms < 2.4.1 - Unauth Arbitrary File Upload ( @nick Vidovic, @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-56290 ] Page Builder CK <= 3.5.10 - Unauth File Upload ( @panchiko-p , @0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-48908 ] Joomla SP Page Builder <= 6.6.1 - Unauth Arbitrary File Upload RCE (@0x_Akoko) [critical] (kev) (vKEV) 🔥 [ CVE-2026-46442 ] Flowise < 3.1.2 - node-custom-function Unauth RCE ( @dhiyaneshdk , @princechaddha ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-44825 ] Apache Solr 9.4.0-9.10.1 / 10.0.0 - Hardcoded Default Credentials ( @pdteam , @0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-16232 ] Check Point Security Management Server - SmartConsole Authentication Bypass ( @sfewer-r7 , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-15409 ] SonicWall SMA1000 - Server-Side Request Forgery ( @dhiyaneshdk , @rapid7 ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-9282 ] W3 Total Cache <= 2.9.4 - Unauth Arbitrary File Read (@0x_Akoko) [high] (kev) (vKEV) 🔥 [ CVE-2026-8732 ] WP Maps Pro (wp-google-map-gold) <= 6.1.0 - Unauth Administrator Account Creation ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-8713 ] Avada (Fusion) Builder <= 3.15.3 - Unauth Arbitrary File Deletion (@rool-machine) [critical] (kev) (vKEV) 🔥 [ CVE-2026-6875 ] ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE ( @pdteam , @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2026-3296 ] Everest Forms WordPress Plugin <= 3.4.3 - PHP Object Injection ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-71334 ] Flowise - Path Traversal ( @theamanrawat ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-68493 ] Apache Struts XWork - XML External Entity Injection ( @pussycat0x ) [high] (kev) (vKEV) 🔥 [ CVE-2025-54988 ] Apache Tika - XXE Injection ( @tx1ee ) [critical] 🔥 [ CVE-2025-6389 ] Sneeit WP Social WordPress Plugin - Unauth RCE via call_user_func ( @dhiyaneshdk ) [critical] (kev) (vKEV) 🔥 [ CVE-2025-2505 ] WordPress Age Gate <= 3.5.3 - Unauth Local File Inclusion ( @pussycat0x ) [critical] (kev) (vKEV) 🔥 [CVE-2024-56511] DataEase < 2.10.4 - Authentication Bypass via Whitelist Path Traversal ( @ChrisJr404 ) [critical] 🔥 [ CVE-2023-34992 ] Fortinet FortiSIEM - Unauth Command Injection ( @Thacien ) [critical] 🔥 What's Changed Bug Fixes Stopped credential-stuffing and token-spray templates from sending their first request when no username, password or token is supplied (PR #16589 , Issue #11238 ). Restored missing matcher and extractor values in four templates that silently no-op'd, including CVE-2021-44228 , CVE-2021-45046 and CVE-2026-42281 (PR #16661 ). Replaced an unsupported RE2 lookahead that stopped home-env-permission.yaml from loading at all (PR #16664 ). Added the missing capture group to three regex extractors (PR #16665 ). Corrected the extractor part in portal-api-ssrf from interactsh to interactsh_request (PR #16667 ). Corrected the DSL variable in thinkphp6-arbitrary-write from status_2 to status_code_2 (PR #16668 ). Unhid two extractors marked internal that nothing consumed (PR #16669 ). Marked the setup-stage matchers in CVE-2025-2075 as internal (PR #16671 ). Removed an AWS access key ID from a reference URL in CVE-2024-51482.yaml (PR #16616 ). Fixed an intrusive tag typo in CVE-2023-34124 .yaml (PR #16675 ). Corrected the id and filename for the IBM DB2 Server template (PR #16688 ). Fixed the severity in directory-listing-no-host-header.yaml (PR #16614 ). Corrected the author field for CVE-2024-23108 (PR #16620 ). Moved CVE-2025-296

CVE-2008-2052CVE-2019-14793CVE-2021-27877CVE-2021-44228CVE-2021-45046CVE-2021-47795CVE-2023-34124CVE-2023-34992CVE-2023-50839CVE-2024-22476CVE-2024-23108CVE-2024-42323CVE-2024-51482CVE-2024-56511CVE-2025-14047CVE-2025-2075CVE-2025-2505CVE-2025-29635CVE-2025-32969CVE-2025-54988CVE-2025-55746CVE-2025-6389CVE-2025-68493CVE-2025-71334CVE-2026-15094CVE-2026-15409CVE-2026-16232CVE-2026-1830CVE-2026-1980CVE-2026-22683CVE-2026-23550CVE-2026-23696CVE-2026-23829CVE-2026-30623CVE-2026-31831CVE-2026-3296CVE-2026-3335CVE-2026-33497CVE-2026-34036CVE-2026-3891CVE-2026-39468CVE-2026-42281CVE-2026-42796CVE-2026-44825CVE-2026-46442CVE-2026-48908CVE-2026-48909CVE-2026-4987CVE-2026-49952CVE-2026-52773CVE-2026-52824CVE-2026-54836CVE-2026-55450CVE-2026-56290CVE-2026-56291CVE-2026-58455CVE-2026-60004CVE-2026-6043CVE-2026-63030CVE-2026-65694CVE-2026-6875CVE-2026-8385CVE-2026-8713CVE-2026-8732CVE-2026-9198CVE-2026-9282
Separate evidence group
Original

Don’t swing at everything

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

CVE-2026-60137CVE-2026-63030
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2026-63030

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2026-63030
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score44.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction2.02 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-436
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.