CyberHighSingle-sourceAccelerating
7.1
WordPress CVE-2026-87902 Path Traversal Exploited Within Hours of Disclosure
SecurityWeekLO·about 8 hours ago
SolarWinds released patches for two critical remote code execution vulnerabilities (CVE-2026-28324, CVE-2026-28325) in its Observability Self-Hosted product, both exploitable without authentication. The flaws pose a high risk of compromise for affected deployments, though no active exploitation has been reported. Organizations using the platform should prioritize patching given the unauthenticated attack vector.