HomeIntelligenceBrief
BREACH BRIEF

Vulnerability Brief — July 21, 2026

8 items in DIGEST_VULN digest.

LiveThreat™ Intelligence · 📅 July 21, 2026

⚠️ LiveThreat Vulnerability Brief — Jul 21, 2026

🧭 Unauthenticated remote‑code‑execution exploits hit core SaaS and infrastructure platforms

📌 What happened: Today a cluster of critical zero‑day and newly disclosed flaws—WordPress, ServiceNow, SonicWall, NGINX, 7‑Zip, and AI coding agents—are being weaponized to execute code without any credentials, continuing the month‑long trend of vulnerability‑driven attacks.

⚖️ Why it matters for compliance: Because attackers can take over systems without logging in, you need tighter access controls, rapid patching, and close vendor oversight to stay audit‑ready.

🎯 Who's affected: Technology & SaaS providers, cloud and infrastructure services, and any organization relying on WordPress, ServiceNow, SonicWall, NGINX, 7‑Zip, or AI development tools.

✅ Recommended actions:

• Prioritize patching of all disclosed CVEs today

• Boost monitoring for anomalous web‑server and API traffic

• Confirm vendor patch timelines and enforce rapid update processes

━━━━━━━━━━━━━━━━━━━━━━

📰 The headlines behind this brief:

⚠️ WP2Shell Chains CVE‑2026‑60137 & CVE‑2026‑63030 for Remote Takeover of Millions of WordPress Sites

Attackers are weaponizing two newly disclosed WordPress core vulnerabilities (CVE‑2026‑60137, CVE‑2026‑63030) to gain unauthenticated remote control of unpatche…

🔗 https://www.livethreat.ai/intelligence/wp2shell-opens-millions-of-wordpress-sites-to-remote-takeover-43720

💥 Critical SQL Injection (CVE‑2026‑63030) in WordPress Core Enables Unauthenticated Remote Code Execution

A newly‑assigned CVE reveals a core WordPress SQL‑injection that allows unauthenticated remote code execution. The flaw is being exploited in the wild, undersco…

🔗 https://www.livethreat.ai/intelligence/wordpress-exploitation-underway-cve-2026-63030-mon-jul-20th-43730

💥 Critical Pre‑Auth RCE in ServiceNow AI Platform (CVE‑2026‑6875) Enables Remote Code Execution

A pre‑authentication code‑injection flaw (CVE‑2026‑6875) in ServiceNow's AI Platform is being exploited in the wild, allowing unauthenticated attackers to execu…

🔗 https://www.livethreat.ai/intelligence/servicenow-pre-auth-rce-exploited-in-the-wild-cve-2026-6875-43684

⚠️ Critical 7‑Zip Remote Code Execution Vulnerability in XZ Decompression Requires User Interaction

7‑Zip 26.02 patches a heap‑based buffer overflow that allows arbitrary code execution when a crafted XZ archive is opened. The issue highlights the need for SOC…

🔗 https://www.livethreat.ai/intelligence/critical-7-zip-flaw-allows-code-execution-by-opening-crafted-xz-compressed-files-update-it-now-43587

⚠️ Critical Heap Buffer Overflow in NGINX (CVE‑2026‑42533) Enables Potential Server Takeover

A high‑severity heap‑buffer overflow in NGINX (CVE‑2026‑42533) allows unauthenticated attackers to crash servers or achieve remote code execution under certain …

🔗 https://www.livethreat.ai/intelligence/cve-2026-42533-critical-nginx-bug-could-turn-http-requests-into-server-takeovers-43588

💥 Critical Pre‑Auth RCE in ServiceNow AI Platform (CVE‑2026‑6875) Actively Exploited

🔗 https://www.livethreat.ai/intelligence/critical-servicenow-code-execution-flaw-now-exploited-in-attacks-43533

💥 Zero‑Day Exploits (CVE‑2026‑15409 & CVE‑2026‑15410) Compromise SonicWall SMA‑1000 VPN Appliances

🔗 https://www.livethreat.ai/intelligence/volexity-uncovers-zero-day-campaign-targeting-sonicwall-vpn-appliances-43590

⚠️ Sandbox Escapes Discovered in Popular AI Coding Agents (Cursor, Codex, Gemini CLI, Antigravity)

🔗 https://www.livethreat.ai/intelligence/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes-43677

━━━━━━━━━━━━━━━━━━━━━━

🛡️ Which of your controls does each of these touch? Continuous evidence is what makes an audit defensible.

📖 View all → https://www.livethreat.ai/vulnerabilities

🔔 Follow LiveThreat for daily threat intelligence + compliance readiness

#Compliance #SOC2 #AuditReadiness #Cybersecurity #ThreatIntel #ContinuousCompliance #BreachWatch #VerisqAI #LiveThreat

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →