ZeroHour

Search: “Google Sites”

2 stories in the last 24h

Android 0-day Vulnerability on Google Pixel Devices Actively Exploited in Attacks

Google patched CVE-2026-58704, an actively exploited Android zero-day allowing proximal privilege escalation via the Pixel cellular modem, urging the 2026-09-05 patch.

Google confirmed CVE-2026-58704, a high-severity elevation-of-privilege flaw in the Pixel cellular modem, is being exploited in limited, targeted attacks and shipped emergency fixes in the September 2026 Pixel Update Bulletin. The low-complexity bug requires no user interaction and enables proximal/adjacent privilege escalation with no additional execution privileges, phrasing Google has historically used for spyware-vendor and state-aligned zero-days. The Pixel bulletin patches 110 flaws including 12 critical RCEs, while the broader September Android update addressed roughly 180 vulnerabilities, including Wi-Fi memory-corruption bug CVE-2026-28662.

Cyber Security Newsupdated · 11h agofirst · 19h agoExploit / PoC in the wild 8 sourcesCVE-2026-58704CVE-2026-28662

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells; Wordfence blocked 100,000+ attempts since June 2026.

Wordfence reports active exploitation of CVE-2026-27540 (CVSS 9.8), an unauthenticated arbitrary file upload in the wwlc_file_upload_handler AJAX action of the WooCommerce Wholesale Lead Capture plugin (versions through 2.0.3.1, 6,000+ installs), enabling remote code execution via uploaded PHP web shells. Over 100,000 exploit attempts were blocked since June 2026, including 99 in the last 24 hours, traced to ten listed IP addresses. Separately, two critical flaws (CVE-2026-78159 and CVE-2026-78006) in The Events Calendar, installed on 600,000+ sites, allow unauthenticated RCE and full site takeover via PHP object injection chains. StellarWP patched the affected plugin versions 6.17.3 and 6.17.4 in releases 6.17.3.1 and 6.17.4.1.

The Hacker Newsupdated · 14h agofirst · 23h agoExploit / PoC in the wild 6 sourcesCVE-2026-27540CVE-2026-78159CVE-2026-78006