Back to news

WordPress RCE Flaw Exploited in the Wild; Microsoft Issues Record 570-Patch Update

Two critical WordPress vulnerabilities are being actively exploited for unauthenticated remote code execution while Microsoft drops its largest-ever patch batch, partly driven by AI-assisted vulnerability discovery.

WordPress RCE Flaw Exploited in the Wild; Microsoft Issues Record 570-Patch Update

What happened

Security researchers have confirmed active exploitation of a pair of critical WordPress vulnerabilities, collectively dubbed wp2shell and tracked as CVE-2026-63030 and CVE-2026-60137. When chained together, the flaws allow unauthenticated attackers to execute arbitrary code and gain full control of affected sites — with confirmed successful attacks recorded within hours of a public exploit becoming available. Meanwhile, Microsoft's July Patch Tuesday addressed at least 570 security vulnerabilities across Windows and related software products, nearly tripling the count from the previous month's record-setting release. The company credited AI-assisted tooling as a key driver behind the accelerating pace of vulnerability identification.

Why it matters for your business

Any organization running a WordPress installation that has not patched against wp2shell is exposed to complete site compromise without requiring attacker credentials — a worst-case scenario for e-commerce platforms, media properties, and SaaS marketing sites alike. The rapid shift from public exploit release to mass scanning underscores how little time defenders have to act once a proof-of-concept surfaces. On the Microsoft side, a 570-patch release demands careful prioritization; security teams should immediately triage any critical- or actively-exploited-rated items and deploy updates in a staged but urgent manner. The broader takeaway: AI is now accelerating both the discovery and, potentially, the weaponization of vulnerabilities, compressing patch windows industry-wide.

What to watch next

WordPress site owners and hosting providers should monitor threat intelligence feeds for indicators of compromise tied to wp2shell as scanning activity is expected to intensify. On the Microsoft front, analysts will be watching whether the AI-assisted discovery pipeline sustains or further expands patch volumes in coming months — a trend with significant implications for security team resourcing. Both developments signal that manual, calendar-driven patch cycles are increasingly inadequate for the current threat environment.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp