View Ridge Security
Back to Cyber HoseVendor Bulletins & Advisories

Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Dark Caracal Deploys GoCaracal Malware Framework in Latin America
    Dark Caracal is using the new GoCaracal framework for cyberespionage.
    • Dark Caracal targets Latin American organizations, including a Venezuelan communications organization.
    • Arctic Wolf analyzed about 250 GoCaracal samples and identified lightweight and extended builds.
    • GoCaracal steals files and credentials, logs keystrokes, and provides interactive remote shells.
    • Spanish-language financial and document-themed domains deliver malicious SVG files, with GoCaracal deployed alongside updated Bandook.
    • The extended build uses an Ethereum-based database to locate backup command-and-control servers.
      ๐Ÿ“„ Source: arcticwolf.com ยท ๐Ÿ“Ž Coverage: darkreading.com ยท ๐Ÿ‘ via Dark Reading

๐Ÿ“‹ ADVISORIES

  • Trump order restricts risky foreign equipment in U.S. bulk-power system
    Trump has declared a national emergency over foreign equipment risks to the U.S. bulk-power system.

    • The order affects U.S. bulk-power system equipment, excluding local electric distribution facilities.
    • Covered equipment includes foreign-produced electrical hardware, critical components, software, firmware, digital services, maintenance services and remote-access capabilities.
    • The Energy Secretary can prohibit post-Aug. 26, 2026 acquisitions, imports, transfers or installations tied to covered foreign entities.
    • Officials cite risks including sabotage, unauthorized access, malicious remote actions, supply disruption and digital backdoors.
      ๐Ÿ“„ Source: whitehouse.gov ยท ๐Ÿ“Ž Coverage: cyberscoop.com ยท ๐Ÿ‘ via CyberScoop
  • Critical Avada WordPress Theme Flaw Enables Unauthenticated RCE
    Wordfence disclosed a critical unauthenticated RCE in the Avada WordPress theme.

    • WordPress sites using Avada and its bundled Fusion Builder are affected; the theme has over 1 million sales.
    • Avada versions up to and including 7.16 are vulnerable with Fusion Builder up to and including 3.16; CVE-2026-18431.
    • A six-step chain of authorization and input-validation weaknesses enables unauthenticated arbitrary file writes.
    • Attackers can write and execute arbitrary PHP, requiring both components to be active and certain administrator-authored content to be present.
      ๐Ÿ“Ž Coverage: therepository.email ยท ๐Ÿ‘ via BleepingComputer

๐Ÿ”“ CVEs & KEV

  • CVE-2026-65641 โ€” CVSS 9.3 โ€” A vulnerability allowing an unauthenticated network attacker to coerce SMB au...

  • CVE-2026-65646 โ€” CVSS 8.7 โ€” Improper neutralization of special elements in Plesk allows remote authentica...

  • CVE-2026-65647 โ€” CVSS 8.7 โ€” Improper symlink resolution before file access in Plesk allows remote authent...

  • CVE-2026-77298 โ€” CVSS 8.7 โ€” SeaweedFS S3 OIDC Bearer authentication bypasses IAM role trust policySeaweed...

  • CVE-2026-55182 โ€” CVSS 8.6 โ€” LibreNMS: Remote Code Execution by Signal Alert Transportation ModuleLibreNMS...

  • CVE-2026-65642 โ€” CVSS 8.6 โ€” Insecure direct object reference in Plesk 18.0.79.7 and earlier or 18.0.80 th...

  • CVE-2026-77317 โ€” CVSS 8.1 โ€” SeaweedFS: SFTP path ACL literal prefix match permits cross-tenant file read ...

  • CVE-2026-80182 โ€” CVSS 7.6 โ€” In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token,...

  • CVE-2026-77368 โ€” CVSS 7.6 โ€” SeaweedFS: Authenticated Cross-Prefix IDOR in Filer TUS Handler Enables Arbit...

  • CVE-2026-77611 โ€” CVSS 7.1 โ€” SeaweedFS: Authenticated S3 object-scope bypass in PutObjectAcl allows overwr...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check