WordPress 7.0.4 Released to Patch High-Severity RCE Vulnerability CVE-2026-65640
The WordPress development team has released WordPress 7.0.4 to address a remote code execution vulnerability that affects specific server environments. The update is being distributed as a security release, and site owners are strongly encouraged to apply it without delay.
The flaw, identified as CVE-2026-65640, was reported by an external security vendor. It allows an authenticated user with Author privileges or higher to execute arbitrary code on the server under certain conditions. Exploitation requires the presence of both the Imagick and Ghostscript image-processing tools, which are commonly used for handling uploaded media files.
According to the advisory, an attacker can upload a malicious PostScript file that is processed by these components, resulting in remote code execution. The vulnerability has been assigned a CVSS v3.0 base score of 8.8 and is rated High severity.
WordPress 7.0.4 can be installed manually from the administration dashboard. Sites configured for automatic background updates will receive the patch progressively. The team is also preparing backported fixes for the older 4.7 branch, which are expected to be released in the near future.
Related articles
SAP Releases August 2026 Security Patch Day Advisories Including Four Critical Vulnerabilities
SAP published 28 new security advisories on August 11, 2026, aligned with the monthly Patch Tuesday schedule. Four of these received the highest severity rating of Critical. The most severe issue affects SAP Commerce Cloud Data Hub Adapter with an authorization bypass flaw rated CVSS 10.0. Two code injection vulnerabilities were disclosed in SAP Manufacturing Integration and Intelligence with CVSS scores of 9.9 and 9.1. A memory corruption vulnerability impacting SAP NetWeaver and ABAP Platform received a CVSS score of 9.8. The release also incorporates one GitHub advisory and two updates to previously published advisories.
AI Uncovers Zoom Vulnerabilities Allowing Silent Device Takeover via Screen Sharing Annotations
Researchers at A Security identified multiple vulnerabilities in Zoom that enabled attackers to compromise participant devices during video calls without any user interaction. The flaws resided in the shared annotations protocol used for drawing and marking on shared screens. Victims only needed to join a meeting where screen sharing was active, affecting both regular participants and meeting organizers. The discovery was notable because it relied on publicly available AI models, requiring fewer than 20 prompts to locate the issues and build a working exploit prototype. The vulnerabilities impacted Zoom clients across Windows, macOS, Linux, iOS, and Android. Zoom addressed the problems through security bulletin ZSB-26015 with server-side and client patches. The research highlights how AI can dramatically accelerate vulnerability discovery compared to traditional manual analysis.
Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access
A critical vulnerability identified as CVE-2026-59310 in Broadcom VMware vCenter Server is being actively exploited in the wild against internet-exposed instances. The flaw resides in the Syslog server component and enables remote code execution through a path traversal weakness, carrying a CVSS score of 9.8. Attackers have been observed deploying malicious cron jobs and the reverse_ssh tool to establish persistent outbound command-and-control channels since early August 2026. The campaign has impacted 361 unique IP addresses across 47 countries, with notable concentrations in Germany, the United States, Turkey, Iran, and France. Broadcom has released patches under advisory VMSA-2026-0006.1, which also addresses the related CVE-2026-59309, and strongly recommends immediate updates along with network segmentation and log reviews. No workarounds exist, making prompt patching the only effective mitigation.
SAP Releases August Security Update Patching 28 Vulnerabilities Including Critical CVSS 10 Flaw
SAP has issued a broad security update to address multiple critical vulnerabilities that could enable code injection, memory corruption, and privilege escalation across enterprise systems. The August package includes 28 new security notes along with a GitHub advisory and two prior fix updates. The highest-severity issue, CVE-2026-58231, carries a maximum CVSS score of 10 and affects the Data Hub Adapter in SAP Commerce Cloud versions 2211 and 2211-JDK21, allowing remote exploitation without user interaction due to improper authorization. Another critical flaw, CVE-2026-44772 rated 9.9, impacts SAP Manufacturing Integration and Intelligence 15.4 and 15.5, permitting malicious code injection into industrial process monitoring systems. Additional vulnerabilities rated 9.1 and lower cover directory traversal, SQL injection, XSS, XXE, hardcoded credentials, and OS command injection across various corporate components. Administrators are advised to identify affected systems and prioritize installation of the critical patches first.