Today’s Field Note

The theme today is speed. WordPress wp2shell (CVE-2026-63030 chained with CVE-2026-60137) went from disclosure to mass exploitation in roughly three days, and with millions of sites in scope, “later” is not a plan. ServiceNow’s CVE-2026-6875 (CVSS 9.5, unauthenticated RCE via sandbox escape) is following the same curve, in-the-wild exploitation confirmed by Defused Cyber days after patches shipped. Meanwhile Qilin has adopted the critical PAN-OS GlobalProtect auth bypass, so your edge VPN is now a ransomware on-ramp per Arctic Wolf. None of these are theoretical, and all three sit on internet-facing surfaces that attackers scan by default.

Today’s Action

  • Patch WordPress plugin/core to close CVE-2026-63030 and CVE-2026-60137 now, then hunt for web shells and unexpected admin users on any site not patched before the weekend.
  • Apply the ServiceNow fix for CVE-2026-6875 and audit AI Platform access logs for anomalous script execution since disclosure.
  • Confirm PAN-OS GlobalProtect is patched against the auth bypass, and check for Qilin precursors (new accounts, lateral movement, staged encryptors) if your appliance was exposed.
  • Pull edge appliances off the open internet where you can; management interfaces on VPN gear should not be reachable from anywhere.
  • Prioritize by exposure, not CVSS alone: internet-facing WordPress, ServiceNow, and Palo Alto instances go to the front of the queue today.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

Disclosure is the starting gun, not the deadline. Move accordingly.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.