Advertisement
CVE-2026-73570: Unauthenticated RCE in Zimbra ZCS Exploited
Threat actors are actively exploiting CVE-2026-73570, an unauthenticated RCE flaw in Zimbra Collaboration Suite, to deploy web shells and exfiltrate sensitive data.
CVE-2026-12569: Clop Exploits Windchill with Custom Web Shell
Clop ransomware group exploited CVE-2026-12569 in PTC Windchill and FlexPLM servers, deploying a custom web shell for deep data theft. Patch immediately.
BdThemes WordPress Plugin Supply Chain Attack Creates Rogue Admins
A supply chain attack on BdThemes WordPress plugins exploited an XSS vulnerability, creating stealthy rogue admin accounts and webshells.
WordPress Core RCE via CVE-2026-63030 — wp2shell Mitigation Guide
Attackers are exploiting critical wp2shell vulnerabilities in WordPress Core to deploy persistent webshells. Learn how to detect and secure your servers.
OP-512: Analyzing the Custom Web Shell Framework Targeting Microsoft IIS
Security researchers have identified OP-512, a China-nexus threat cluster targeting Microsoft IIS servers with a bespoke web shell framework for espionage.
Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide
Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.
Advertisement
CVE-2024-34102: PolyShell Exploits Target 56% of Magento Stores
Attackers are aggressively exploiting the CosmicSting vulnerability (CVE-2024-34102) in Magento and Adobe Commerce stores using PolyShell polyglot web shells.
900+ Sangoma FreePBX Servers Compromised via Web Shell Exploitation
Over 900 Sangoma FreePBX instances are currently infected with web shells following a command injection campaign first observed in late 2025.