The CyberSec Guru[verified]@thecybersecguruActive Exploitation
Over 440,000 exploit attempts target two WordPress plugins via CVE-2026‑14894 and CVE-2026‑32475, enabling unauthenticated RCE through PHP file upload; attackers are active, and patching is urged.
kokumօtօ[verified]@__kokumotoActive Exploitation
The CVE-2026-14894 affects the Super Forms plugin, has a CVSS score of 9.8, and has been actively exploited since July 14, with reported PHP file upload capabilities.
PositiveSkeptic[verified]@PositiveSkeptikPatch
Chrome has released a patch for CVE‑2026‑85046, a high‑severity V8 flaw that is actively exploited; 440,000+ WordPress plugin attacks were reported, prompting users to update their browsers.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2026‑14894 is a highly critical arbitrary file upload in Super Forms, actively exploited in the wild with thousands of attempts and webshell drops, and a patch is available.
セキュリティ対策Lab[verified]@securityLab_jpActive Exploitation
CVE-2026-14894 in the WordPress Super Forms plugin is being actively exploited, with more than 250,000 attack attempts reported.
Frontiera Tech[verified]@FrontieraTechITActive Exploitation
The bulletin reports several actively exploited CVEs—ranging from a Chrome V8 zero‑day to WordPress plugin RCEs and CISA‑listed KEVs—and urges immediate patching to mitigate the ongoing attacks.
Upwind Security MDR[verified]@UpwindMDRPatch
Critical unauthenticated file upload in Super Forms WordPress plugin enables RCE; update to version 6.3.313 or newer to remediate.
Orizon[verified]@OrizonCyberDisclosure
The tweet announces the critical CVE-2026-14894 affecting the Super Forms WordPress plugin, detailing its severity and type, and indicates that a patch is available.