CVE-2026-63030
WordPress is affected by a REST API batch endpoint route confusion issue which, when combined with other vulnerabilities, can lead to SQL injection and Remote Code Execution.
Critical vulnerabilities, curated daily for security professionals
Tenda TX9 routers account for four of the day's six critical vulnerabilities, alongside a Linux Kernel flaw and an SJCAM SJ4000-Air camera issue, all rated CVSS 9.8. The brief covers 6 critical CVEs (down 25% from 8) and 18 high-priority CVEs (down 25% from 24), for 24 total vulnerabilities disclosed yesterday. CVE-2026-64530 in the Linux Kernel and CVE-2024-51311 through CVE-2024-51315 in Tenda TX9 firmware sit at the top of the severity list, with CVE-2026-52656 affecting SJCAM SJ4000-Air devices. Consumer and small-business network equipment and IoT cameras dominate the critical tier, a pattern that typically indicates unauthenticated remote code execution against internet-reachable devices. No vendor patches were confirmed available for the tracked CVEs at collection time, so network segmentation and management-interface access restrictions are the practical near-term controls. Six vulnerabilities across WordPress, Microsoft SharePoint, Langflow, Check Point SmartConsole, and DD-WRT have confirmed active exploitation.
Immediate action: Prioritize Tenda TX9 routers, SJCAM SJ4000-Air cameras, and DD-WRT installations: remove management interfaces from internet exposure and restrict administrative access to trusted networks. Patch the actively exploited Microsoft SharePoint, WordPress Core, Langflow, and Check Point SmartConsole issues first, since those have confirmed exploitation and vendor fixes are more likely to exist. No patches were confirmed available for the tracked critical CVEs at collection time, so verify vendor advisories directly before assuming a fix is pending.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.