Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Prioritize remediation for affected systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Track advisory updates for patch or workaround availability
Recommended action window: Immediate (within 24h)
NVD description
The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
Exploiting A Pre-Auth RCE in W3 Total Cache For WordPress <= 2.9.1 (CVE-2025-9501) #W3TotalCache#WordPress#RCE#CVE20259501#PatchBypass https://www.rcesecurity.com/2025/11/exploiting-a-pre-auth-rce-in-w3-total-cache-for-wordpress-cve-2025-9501/
Post summary
The post announces a pre-authentication RCE in W3 Total Cache 2.9.1 or earlier (CVE‑2025‑9501) and links to an article containing a proof‑of‑concept exploit, but does not detail active exploitation, patching, or a false‑positive assertion.
But .env scraping was just phase one.
It also had active exploits for:
🔹 CVE-2025-55182 — @nextjs Server Action RCE via prototype pollution (with @Cloudflare WAF bypass built in)
🔹 CVE-2025-9501 — @WordPress W3 Total Cache RCE (v2.0.x–2.8.12)
@vercel
Post summary
The post notes that CVE‑2025‑55182 (Next.js Server Action RCE) and CVE‑2025‑9501 (WordPress W3 Total Cache RCE) are actively exploited in the wild, with mention of prototype pollution and WAF bypass, but provides no PoC, patch, or exploit tool details.
"PCP replaced" - the metric tracked by PCPJack's C2.
PCPJack is a Linux credential-stealing worm disclosed May 7, 2026 by SentinelLabs. It exploits five CVEs to spread:
- CVE-2025-29927 (Next.js middleware auth bypass)
- CVE-2025-55182 "React2Shell" (Next.js Server Actions deserialization)
- CVE-2026-1357 (WPVivid Backup unauth file upload)
- CVE-2025-9501 (W3 Total Cache PHP injection via cached mfunc)
- CVE-2025-48703 (CentOS Web Panel Filemanager shell injection)
http://bootstrap.sh kills competing TeamPCP processes before installing itself, then drops six Python scripts handling orchestration, credential parsing, lateral movement, encryption, cloud-IP refresh, and port scanning.
Lateral movement targets SSH, Kubernetes, Docker, Redis, RayML, MongoDB. Persistence via systemd, cron, Redis rewrites, and privileged containers. Targets pulled from Common Crawl parquet files. http://check.sh probes IMDS endpoints and Kubernetes service accounts.
Credentials harvested cover Anthropic, OpenAI, HashiCorp Vault, 1Password, Slack, SSH keys, and WordPress configs. Exfil uses X25519 ECDH + ChaCha20-Poly1305, 2800-byte chunks, to Telegram.
SentinelLabs links it to a likely former TeamPCP affiliate from tooling overlap. No cryptomining, unlike TeamPCP - the C2 explicitly tracks "PCP replaced" successes.
A worm built to evict its predecessor and harvest the cloud underneath.
Post summary
SentinelLabs reports on the active exploitation of five CVEs by the PCPJack worm, which harvests credentials from cloud services, but provides no public PoC, patch, or false‑positive clarification.
NEW THREAT INTEL: Bissa Scanner -- AI-orchestrated mass exploitation of CVE-2025-55182 (Next.js RCE) and CVE-2025-9501 (W3 Total Cache). 9 detections, 29 IOCs. https://intel.threadlinqs.com/#TL-2026-0428 #ThreatIntel#CyberSecurity#CVE#Nextjs#WordPress https://t.co/w9wVc3LQZj
Post summary
The intelligence indicates AI-driven mass exploitation of CVE-2025-55182 (Next.js RCE) and CVE-2025-9501 (W3 Total Cache), with multiple detections and IOCs, but no PoC, exploit code, or patch information is provided.