< Back to all clusters
[TECHNOLOGY] · Spain · 3 sources

started · updated

INCIBE issues security bulletins on critical WordPress and Linux kernel flaws

INCIBE released two security bulletins updated on 22 July 2026. The first bulletin lists recent vulnerabilities, notably a high‑severity use‑after‑free flaw in the Linux kernel netfilter subsystem (CVE‑2023‑3390) that could allow local privilege escalation, and several medium‑severity cross‑site scripting issues in WordPress email‑encoder plugins (CVE‑2023‑47821, CVE‑2023‑7070, CVE‑2024‑1282). The second bulletin focuses on WordPress, reporting a critical vulnerability (CVE‑2026‑63030) that enables remote code execution through path‑confusion, and a high‑severity SQL‑injection flaw (CVE‑2026‑60137) that can be chained to achieve the same effect. Affected versions include WordPress 6.9, 6.8, and the beta of 7.1. INCIBE advises updating to the patched releases (WordPress 6.9.5, 6.8.6, 7.1 beta2) to mitigate these risks. The bulletin also outlines several Oracle product vulnerabilities, but the primary emphasis is on the WordPress and Linux kernel issues.