Security Digest: July 1, 2026 - 19 Critical Vulnerabilities
Today’s alert is dominated by remote takeover risks, unauthenticated exposure, and WordPress plugin flaws that can be exploited with little or no user interaction. The most urgent issues are UltraVNC repeater RCE, a default-password weakness in the same product, and multiple WordPress bugs that allow file deletion, SQL injection, privilege escalation, and stored XSS.
· 13 min read
Executive Summary
Today’s alert is dominated by remote takeover risks, unauthenticated exposure, and WordPress plugin flaws that can be exploited with little or no user interaction. The most urgent issues are UltraVNC repeater RCE, a default-password weakness in the same product, and multiple WordPress bugs that allow file deletion, SQL injection, privilege escalation, and stored XSS. Patch exposed systems immediately, disable public access where possible, and assume internet-facing instances are at highest risk.
Critical Vulnerabilities
CVE-2026-7840: UltraVNC repeater HTTP admin buffer overflow
- Impact: Remote, unauthenticated attackers can trigger arbitrary code execution on the repeater host.
- Affected Systems: UltraVNC repeater through 1.8.2.2.
- Immediate Action: Remove public exposure to the repeater HTTP port now; block TCP 80 at the perimeter if it is not required.
- Mitigation: Apply the vendor fix as soon as available; until then, restrict access to trusted admin networks only.
CVE-2026-7839: UltraVNC repeater hardcoded default admin password
- Impact: Remote attackers can log in as administrator on fresh or unmodified installs.
- Affected Systems: UltraVNC repeater through 1.8.2.2.
- Immediate Action: Change credentials immediately and audit any repeater instance reachable from the internet.
- Mitigation: Replace the default password, rotate any related credentials, and update to a fixed release when available.
CVE-2026-6070: WP-BusinessDirectory arbitrary file deletion
- Impact: Unauthenticated attackers can delete critical files, including
wp-config.php. - Affected Systems: WP-BusinessDirectory plugin up to and including 4.0.1.
- Immediate Action: Disable the plugin or remove public access to the affected endpoint right away.
- Mitigation: Patch to the vendor-fixed version and verify site integrity and backups.
CVE-2026-10539: Control-M/Server command execution risk
- Impact: Attackers may run unauthorized commands on affected servers.
- Affected Systems: Control-M/Server 9.0.20.x through 9.0.21.200, and potentially earlier unsupported versions.
- Immediate Action: Limit access to Control-M services to trusted hosts only.
- Mitigation: Apply BMC guidance and update to a safe release; review for suspicious command activity.
CVE-2026-7838: UltraVNC viewer heap overflow in failure-response parsing
- Impact: A malicious VNC server or MITM attacker can crash the viewer and may achieve code execution on the client.
- Affected Systems: UltraVNC viewer through 1.8.2.2.
- Immediate Action: Do not connect to untrusted VNC servers until patched.
- Mitigation: Update the viewer and prefer trusted, encrypted remote-access paths.
CVE-2026-12224: Dokan Pro privilege escalation via REST endpoint
- Impact: Authenticated vendors can grant themselves or others administrator privileges.
- Affected Systems: Dokan Pro up to and including 5.0.4, with Vendor Staff module enabled.
- Immediate Action: Review vendor accounts and remove unnecessary elevated roles.
- Mitigation: Patch immediately and audit user capability changes.
CVE-2026-12158: RegistrationMagic CSRF to admin escalation
- Impact: Attackers can trick an admin into executing actions that elevate a submitter to administrator.
- Affected Systems: RegistrationMagic up to and including 6.0.9.1.
- Immediate Action: Warn admins not to click unknown links and restrict access to admin sessions.
- Mitigation: Update the plugin and verify nonce protections are in place.
CVE-2026-10538: Control-M/Server unsafe deserialization
- Impact: Authenticated attackers may trigger unintended server-side behavior.
- Affected Systems: Out-of-support Control-M/Server and Control-M/Enterprise Manager 9.0.20.x and earlier.
- Immediate Action: Treat affected systems as high risk and isolate them.
- Mitigation: Move to supported versions and monitor messaging consumers for abnormal payloads.
CVE-2026-12576: DVP80ES3 message integrity flaw
- Impact: Potential remote code execution through tampered communications.
- Affected Systems: DVP80ES3.
- Immediate Action: Restrict exposure and verify whether this device is internet-reachable.
- Mitigation: Apply vendor firmware or configuration updates as soon as they are released.
CVE-2026-13468: Visualizer chart export authorization bypass
- Impact: Unauthenticated attackers can export chart data, including private or draft content.
- Affected Systems: Visualizer – Tables & Charts Manager with Built-in AI Generator up to and including 4.0.3.
- Immediate Action: Disable the REST route or the plugin if sensitive charts are present.
- Mitigation: Update immediately and review exposed chart data for leakage.
CVE-2026-11823: BookingPress SQL injection
- Impact: Unauthenticated attackers may extract sensitive database data.
- Affected Systems: BookingPress Appointment Booking Pro up to and including 5.7.1.
- Immediate Action: Patch now and review database logs for suspicious queries.
- Mitigation: Apply the fixed version and rotate credentials if compromise is suspected.
CVE-2026-1239: Ninja Forms data exposure via REST callback
- Impact: Unauthenticated attackers can access form submissions, potentially including sensitive information.
- Affected Systems: Ninja Forms up to and including 3.14.1.
- Immediate Action: Restrict public access to form data endpoints.
- Mitigation: Update the plugin and review exposed submissions for confidential data.
CVE-2026-12575: DVP80ES3 resource shutdown/release flaw
- Impact: May contribute to unstable behavior and potential code execution conditions.
- Affected Systems: DVP80ES3.
- Immediate Action: Isolate the device and verify vendor patch status.
- Mitigation: Install firmware updates and monitor for crashes or service loss.
CVE-2026-54592: Oj gem stack overflow denial of service
- Impact: Crafted deeply nested JSON can crash Ruby applications using Oj.
- Affected Systems: Oj gem versions prior to 3.17.3.
- Immediate Action: Upgrade Ruby dependencies immediately on exposed services.
- Mitigation: Pin to 3.17.3 or later and add request-size and depth limits.
CVE-2026-7830: UltraVNC MS-Logon II weak cryptography
- Impact: Attackers can recover credentials by observing the handshake.
- Affected Systems: UltraVNC through 1.8.2.2 using MS-Logon II.
- Immediate Action: Disable MS-Logon II where possible and move users to stronger auth.
- Mitigation: Use MS-Logon III or another modern authentication method.
CVE-2026-12579: AS228T authentication bypass
- Impact: Attackers may gain unauthorized access to the device.
- Affected Systems: AS228T.
- Immediate Action: Restrict management access immediately.
- Mitigation: Apply the vendor patch or firmware update and rotate admin credentials.
CVE-2026-7829: UltraVNC repeater stack write in rule parser
- Impact: Authenticated attackers can corrupt memory and may execute code on the repeater host.
- Affected Systems: UltraVNC repeater through 1.8.2.2.
- Immediate Action: Remove internet exposure and review admin access paths.
- Mitigation: Patch the repeater and invalidate any credentials that may have been exposed.
CVE-2026-13731: WPBot stored XSS via conversation parameter
- Impact: Attackers can inject scripts that run in visitors’ browsers.
- Affected Systems: WPBot – AI ChatBot for Live Support, Lead Generation, AI Services up to and including 8.4.9.
- Immediate Action: Disable the affected feature or plugin if customer-facing pages are live.
- Mitigation: Update immediately and cleanse any stored malicious content.
CVE-2026-7517: Custom Payment Gateways for WooCommerce stored XSS
- Impact: Unauthenticated checkout submissions can plant scripts for later execution.
- Affected Systems: Custom Payment Gateways for WooCommerce up to and including 2.1.0.
- Immediate Action: Patch now and review checkout traffic for malicious payloads.
- Mitigation: Update the plugin and sanitize any stored data already in the database.
Previously Alerted
- CVE-2026-11387: Security Alert
What to Do Now
- Patch or disable exposed services today, starting with UltraVNC, WordPress plugins, and any internet-facing Control-M systems.
- Remove public access to admin ports and REST endpoints until updates are confirmed.
- Rotate credentials for any system that may have been reachable with default or weak authentication.
- Review logs immediately for suspicious logins, unusual file deletions, SQL errors, and unexpected REST calls.
- Check for compromise on WordPress sites: admin role changes, altered plugins, new scripts, and missing files.
Verification steps:
- Confirm installed versions against the affected ranges above.
- Validate that patched versions are deployed everywhere, including staging and customer-facing clones.
- Search for exposure of TCP 80 on UltraVNC repeater hosts and management interfaces on Control-M and device fleets.
Monitoring recommendations:
- Alert on repeated login attempts, unexpected admin account creation, and changes to capabilities.
- Watch for file deletion, webshell uploads, and unusual outbound connections from affected servers.
- Track WordPress REST activity, checkout payload anomalies, and spikes in 4xx/5xx responses.
Related Resources
- Internal blog post: July 1, 2026 threat roundup (to be published).
- Official vendor advisories: UltraVNC, BMC Control-M, WordPress plugin vendors, and affected device manufacturers.