A SQL injection in WordPress core, government-confirmed as exploited and now with a public PoC. High velocity, evidence accumulating fast — treat as immediate.
Week of July 28, 2026
Your CVE score is data. The change is the signal.
The week's movers, every Tuesday. No noise, just what changed.
Exploitation probability spikes overnight. Public exploits land. CVEs cross into confirmed in-the-wild use. That movement, the change, is what ESIP scores and surfaces.
Silence is not clearance: a CVE that didn't move isn't a safe one, just one nothing has happened to this week. When something does move, that change is the exposure signal.
A SQL injection in WordPress core, government-confirmed as exploited and now with a public PoC. High velocity, evidence accumulating fast — treat as immediate.
A confirmed-exploited stack overflow in DD-WRT’s UPnP stack, with exploitation probability rising fast. Escalating at critical severity — treat as immediate.
Government-confirmed exploitation, corroborated by ENISA EUVD, now with a public weaponized exploit. Act now — don’t wait for more evidence.
Command injection in a self-hosted Git service, weaponized just three days ago. The threat picture is changing fast — review against your inventory.
Updated every Tuesday. Subscribe to get it by email.