Attackers are actively exploiting WordPress CVE-2026-87902, a critical vulnerability that could enable remote code execution. Administrators are advised to update affected versions.
Security researchers have found the third-party.com placeholder domain serving ClickFix malware lures, affecting users through fake verification pages and malicious commands.
CISA adds CVE 2026 54420 affecting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities catalog, warning of root privilege escalation risks on shared hosting servers.