Today’s Briefing
CVE-2026-63030 and CVE-2026-60137 form an exploited chain in WordPress Core that permits unauthenticated remote code execution on default installations, now tracked as wp2shell and added to CISA KEV today alongside CVE-2026-0770 in Langflow. CISA also published advisories for an authentication bypass in Siemens Opcenter X before V2604 and an impersonation vulnerability in Rockwell Automation FactoryTalk Services Platform 6.6, both affecting operational technology environments.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.