top of page

The Security Brief


CVE-2026-16232: Attackers Are Taking Over Check Point Management Servers
Check Point disclosed CVE-2026-16232 on 22 July after discovering it had already been exploited as a zero-day. The flaw lets an unauthenticated attacker log into a Security Management Server with full administrator rights — the machine that writes and pushes policy to every firewall it manages. Rapid7 published a working proof-of-concept on 29 July, which means the window for quiet patching has closed. What Happened Check Point found the bug during a routine internal review a
Jul 313 min read


wp2shell: A Pre-Authentication WordPress Core Flaw Australian Sites Should Patch Now
A single anonymous HTTP request can run code on a vulnerable WordPress site. The flaw, nicknamed wp2shell, sits in WordPress core rather than a plugin, so even a bare installation with nothing added is in range. WordPress shipped emergency fixes on 17 July, and any Australian organisation running an affected version should treat patching as this week's priority. What Happened On 17 July 2026, WordPress released versions 6.9.5 and 7.0.2 to close a pre-authentication remote cod
Jul 303 min read


SonicWall SMA 1000 Zero-Days: Remote Access Appliances Turned Into Backdoors
Two zero-day vulnerabilities in SonicWall's SMA 1000 remote access appliances are being exploited in the wild, and attackers are using the appliances themselves as a route into corporate networks. SonicWall confirmed active exploitation on 14 July. CISA followed within days, adding both flaws to its Known Exploited Vulnerabilities catalogue and giving US federal agencies until 17 July to patch or disconnect the devices. What Happened The two flaws are CVE-2026-15409, an unaut
Jul 213 min read
bottom of page