Attackers are actively exploiting WordPress CVE-2026-87902, a critical vulnerability that could enable remote code execution. Administrators are advised to update affected versions.
Security researchers have found the third-party.com placeholder domain serving ClickFix malware lures, affecting users through fake verification pages and malicious commands.
Researchers have disclosed DirtyClone, a Linux kernel vulnerability tracked as CVE 2026 43503 that enables local privilege escalation by corrupting cached memory through cloned network packets.
A newly disclosed Linux kernel vulnerability tracked as CVE 2026 46331 allows local users to gain root privileges by poisoning cached binaries in memory, affecting multiple Linux distributions.
Dirty Frag Linux kernel vulnerability enables local privilege escalation to root across major distributions including Ubuntu, RHEL, Fedora, and CentOS, with active exploitation risk.