The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

WordPress Core Flaw Lands on CISA List with July 24 Deadline

The Perimeter Desk
2026-07-24
# WordPress Core Flaw Lands on CISA List with July 24 Deadline If you're reading this on a Friday, you're already late. The federal patch deadline for CVE-2026-63030 is today, July 24. This isn't some theoretical risk found by a researcher in a vacuum; it's a pre-auth vulnerability that lets attackers read arbitrary server files. There are 8 stories on the board this week alone detailing its exploitation. If you're running WordPress and haven't updated, you aren't "managing risk." You're just hoping the attackers have a busy weekend. Here is how you actually rank your priorities this afternoon, based on who is currently winning. First, the "Do It Now" pile. Along with that WordPress Core flaw, you have Langflow (CVE-2026-0770) and DD-WRT (CVE-2021-27137). Both hit their CISA deadlines today. These are your internet-facing liabilities. If they're exposed, they're essentially open doors. Second, the "Do It Before Monday" pile. Tomorrow, July 25, is the deadline for the Check Point SmartConsole improper authentication flaw (CVE-2026-16232) and a new SharePoint deserialization bug (CVE-2026-50522). The Check Point one is particularly nasty because of the human incentive. Patching a security console is terrifying. If you brick the management interface, you're effectively locked out of your own house while the windows are open. Most admins will push this to next week because the fear of a self-inflicted outage outweighs the fear of a breach. That's exactly the gap attackers exploit. Third, the "It Can Wait" pile. The WordPress SQL injection (CVE-2026-60137) has a deadline of August 4. It's serious, but in a world of limited man-hours, you don't prioritize a bug with a two-week window over a bug that's being used to drain servers right now. We see this tension play out in the numbers every week. Look at Suno. They just dealt with a breach affecting 55 million users. Or Chick-fil-A, where a leak hit just over 13,000 customers. These aren't usually the result of a mastermind with a custom exploit; they're the result of a gap between a patch being available and a human being deciding it's worth the risk of a reboot. The real victims here aren't just the companies on the list. Think about the second-order effect: the managed service providers (MSPs) and freelance web devs. There are thousands of small businesses who pay a "guy" to keep their WordPress site running. That guy is currently staring at a dashboard, wondering if updating the core will break the custom CSS he spent three days on in 2022. He's incentivized to keep the site looking pretty, not to keep the server secure. When the breach happens, the business blames the dev, the dev blames the plugin, and the attacker keeps the data. Some will argue that we can't possibly patch everything instantly. They'll say the volume of CVEs is too high for any human team to keep up with. That's a convenient excuse. It treats patching like a lottery rather than a triage process. You don't need to patch everything; you just need to patch the things that are actively being used to break into your neighbors' houses. The board tells us exactly what those are. If a flaw is in the KEV and the deadline is today, the "stability" argument is a lie we tell ourselves to avoid the discomfort of a potential outage. Which brings us to the uncomfortable part. If you're the one signing off on the maintenance windows, be honest: are you actually weighing the technical risk of the vulnerability, or are you just terrified of explaining to a VP why the internal portal was down for twenty minutes on a Friday afternoon?
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Data Breach Confirmed After Australian Energy Giant Origin Is Hacked SecurityWeek
  2. Zero-day flaw in Check Point SmartConsole is under exploitation - Cybersecurity Dive Google News Security
  3. From 90,000 AI tracks hitting Deezer daily to Suno’s 55m-user data breach… it’s MBW’s Weekly Round-up - Music Business Worldwide Google News Security
  4. Data breach hits Seoul bike-sharing service: 4.6M victims get free bikes for a month - Cybernews Google News Security
  5. Origin Energy confirms data breach impacting millions of customers - SC Media Google News Security
  6. Singapore tightens cybersecurity rules for critical infrastructure after China-linked hack hit all four major telcos - Startup Fortune Google News Security
  7. Origin Energy Sector Data Breach Widens to 5 Million Customers - Cybersecurity Insiders Google News Security
  8. OpenAI claims its artificial intelligence gained access to the Internet on its own and breached a ‘partner’ - HealthExec Google News Security

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.