A heap overflow in nginx’s two-pass script engine, reachable through a regex-based
map feeding a directive that also uses a regex capture. Affects 0.9.6 through 1.31.2.The trap: the May fix for Nginx Rift (CVE-2026-42945, fixed in 1.30.1) does not cover this one. Update to 1.30.4 or 1.31.3. Read the full advisorySymlink mishandling in the LiteSpeed cPanel plugin lets an account with nothing more than FTP access escalate to root on shared hosting running CloudLinux or CageFS.In CISA’s KEV catalog since 15 June. Fixed in LiteSpeed WHM plugin 5.3.2.1. Read the full advisory
A routing confusion in the WordPress REST API batch processor, chained with an SQL injection, gives full site takeover without any credentials. Added to CISA’s KEV catalog on 21 July and exploited in the wild.Patched in 6.9.5 and 7.0.2. Read the full advisory
Not a bug but an intent: version 10.8.7 of a WordPress plugin with 20,000 installs shipped a hardcoded administrator backdoor. Caught in under two hours, and pulled from WordPress.org.There is no fixed version — remove the plugin. Read the full advisory
A use-after-free on the futex priority-inheritance path, present since 2011, turns any local user into root in about five seconds and escapes containers to the host.No runtime mitigation exists: patch the kernel and reboot. Read the full advisory
A flaw in the kernel’s cryptographic subsystem, reachable through the AF_ALG interface, lets locally-running code walk out with root. Container escape included.A module blacklist mitigates it until the kernel patch lands. Read the full advisory
Unsafe deserialisation in React 19’s Flight protocol allows arbitrary code execution on the server, unauthenticated. A perfect 10.0, with active exploitation.Read the full advisory
MongoDB’s network layer leaks fragments of server memory to unauthenticated clients — credentials, API keys and BSON documents among them.Read the full advisory
A malicious Lua script escapes the Redis sandbox through a use-after-free in the embedded engine and runs native code on the host. Public proof of concept.Read the full advisory
Four chained flaws in the Ingress NGINX controller take an unauthenticated attacker from a request to code execution, and from there to the whole cluster.Read the full advisory
Four chained CUPS flaws let an attacker register a malicious printer on your network and obtain code execution the moment someone prints to it.Read the full advisory
A 2006 bug reintroduced by a regression: recent OpenSSH versions allow remote code execution as root, with no authentication.Read the full advisory
A backdoor deliberately planted in xz-utils 5.6.0 and 5.6.1, targeting OpenSSH through systemd. Caught before it reached stable distributions.Read the full advisory
Hardening your servers day to day is a different exercise from reacting to a CVE. Our enhanced VPS security guide covers the tools and habits, and the WordPress hardening checklist covers the web side.

