Vendor
critical
threat
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
exploited
PoC
WordPress Core 6.9.0 +51
wordpress
rce
web-vulnerability
cve
2t
15c
8i
updated
high
advisory
Forge RSA Signature Forgery Vulnerability
2 rules 1 TTP 2 CVEsForge is vulnerable to signature forgery in RSA-PKCS due to ASN.1 extra field, allowing attackers to forge signatures by stuffing garbage bytes within the ASN structure for low public exponent keys (e=3), enabling Bleichenbacher style forgery and affecting npm/node-forge versions less than 1.4.0.
node-forge
forge
rsa
signature-forgery
bleichenbacher
2r
1t
2c
updated