Breaking: Three Critical RCE Flaws Under Active Exploitation — WordPress, Check Point, SharePoint — 24 July 2026
WordPress Core Unauthenticated RCE (wp2shell) Under Active Exploitation
Three critical vulnerabilities with confirmed active exploitation were added to CISA's Known Exploited Vulnerabilities catalog this week. The most urgent: a WordPress Core flaw chain enabling unauthenticated remote code execution on default installations.
WordPress wp2shell — CVE-2026-63030 + CVE-2026-60137 (CVSS 9.1/10.0). Two vulnerabilities in WordPress Core that, when chained, allow an unauthenticated attacker to achieve full RCE on default WordPress installations. No plugins, no special configuration, no authentication required. CVE-2026-63030 is a REST API batch-route interpretation conflict that enables SQL injection via CVE-2026-60137 (a WP_Query `author__not_in` SQLi). The chain has been dubbed "wp2shell." Wiz reports 60% of organisations running WordPress initially had at least one vulnerable instance, with 25% exposing it to the internet. Public PoC exploits are circulating. Active exploitation confirmed by Wiz and Coalition. CISA added both CVEs to KEV on July 21 with a remediation deadline of July 24 for CVE-2026-63030. Patch: WordPress 7.0.2.
Check Point SmartConsole Auth Bypass — CVE-2026-16232 (CVSS 9.3). An improper authentication vulnerability in SmartConsole that allows an unauthenticated remote attacker to obtain a login token and authenticate with full administrative privileges. Check Point has confirmed active exploitation in the wild affecting a small number of customers. Any exposed Check Point management server is at critical risk. CISA KEV added July 22, remediation deadline July 25. Patch: Check Point sk185169.
Microsoft SharePoint Deserialization RCE — CVE-2026-50522 (CVSS 9.8). The third SharePoint RCE added to KEV in this month's sustained exploitation campaign, following CVE-2026-56164 and CVE-2026-58644. An unauthenticated deserialization vulnerability enabling remote code execution. watchTowr reports active exploitation following public PoC release, with attackers pulling SharePoint machine keys for persistent access. Defused Cyber has observed .NET deserialization payloads hitting SharePoint sign-in endpoints with no authentication material. CISA KEV added July 22, remediation deadline July 25. This is the fourth SharePoint zero-day exploited in the past month.
So what? Three of the most widely deployed platforms in enterprise environments — WordPress, Check Point, and SharePoint — have critical unauthenticated RCE or admin-takeover flaws under active exploitation simultaneously. The wp2shell chain is particularly dangerous because it requires no plugins and hits default WordPress installations. CISA's three-day remediation deadlines (July 24-25) signal urgency. If you run any of these, patch immediately and assume compromise: rotate credentials on exposed SharePoint servers, audit Check Point management server access logs, and scan WordPress instances for webshell indicators. The WordPress patch deadline is today.

