CVE-2026-4020Active Exploitation

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 12 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Gravity SMTP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4. This is due to a REST API endpoint registered at /wp-json/gravitysmtp/v1/tests/mock-data with a permission_callback that unconditionally returns true, allowing any unauthenticated visitor to access it. When the ?page=gravitysmtp-settings query parameter is appended, the plugin's register_connector_data() method populates internal connector data, causing the endpoint to return approximately 365 KB of JSON containing the full System Report. This makes it possible for unauthenticated attackers to retrieve detailed system configuration data including PHP version, loaded extensions, web server version, document root path, database server type and version, WordPress version, all active plugins with versions, active theme, WordPress configuration details, database table names, and any API keys/tokens configured in the plugin.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 43 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 58 mentions across 16 observed days

What's happening

  • Active exploitation reported across 43 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 23 signals
  • Technical details provided in 41 signals
  • Disclosure: 11 classified signals
  • General: 3 classified signals
  • Peaked 9d ago at 12 mentions (2026-06-20); latest day: 1
  • 58 total mentions across 16 days

Deep dive

Activity timeline58 mentions / 16d
036912Mentions · 2026-03-31: 3Mentions · 2026-04-01: 1Mentions · 2026-06-05: 1Mentions · 2026-06-17: 5Mentions · 2026-06-18: 2Mentions · 2026-06-19: 3Mentions · 2026-06-20: 12Mentions · 2026-06-21: 8Mentions · 2026-06-22: 12Mentions · 2026-06-23: 4Mentions · 2026-06-25: 2Mentions · 2026-07-08: 1Mentions · 2026-07-11: 1Mentions · 2026-07-19: 1Mentions · 2026-08-05: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-06-20: 2PoC Mentioned / Linked · 2026-06-21: 1Active Exploitation · 2026-06-17: 4Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-06-19: 2Active Exploitation · 2026-06-20: 11Active Exploitation · 2026-06-21: 8Active Exploitation · 2026-06-22: 10Active Exploitation · 2026-06-23: 4Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-07-11: 1Active Exploitation · 2026-08-21: 1Patch / Workaround · 2026-06-17: 2Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-20: 6Patch / Workaround · 2026-06-21: 6Patch / Workaround · 2026-06-22: 4Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-25: 2Patch / Workaround · 2026-08-21: 1Technical Details · 2026-03-31: 3Technical Details · 2026-04-01: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-17: 2Technical Details · 2026-06-18: 2Technical Details · 2026-06-19: 3Technical Details · 2026-06-20: 11Technical Details · 2026-06-21: 8Technical Details · 2026-06-22: 5Technical Details · 2026-06-23: 1Technical Details · 2026-06-25: 2Technical Details · 2026-07-19: 1Technical Details · 2026-08-05: 103-3104-0106-0506-1706-1806-1906-2006-2106-2206-2306-2507-0807-1107-1908-0508-21
Signal classification5 categories
Active Exploitation
4170.7%
Disclosure
1119.0%
General
35.2%
Patch
23.4%
Exploit
11.7%
Referenced assets33 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-313
Disclosure3
2026-04-011
Disclosure1
2026-06-051
General1
2026-06-175
Active Exploitation4Disclosure1
2026-06-182
Active Exploitation1Disclosure1
2026-06-193
Active Exploitation2Disclosure1
2026-06-2012
Active Exploitation11Disclosure1
2026-06-218
Active Exploitation7Exploit1
2026-06-2212
Active Exploitation10Disclosure1General1
2026-06-234
Active Exploitation4
2026-06-252
Active Exploitation1Patch1
2026-07-081
Disclosure1
2026-07-111
Active Exploitation1
2026-07-191
General1
2026-08-051
Disclosure1
2026-08-211
Patch1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    A Gravity SMTP WordPress plugin flaw is already being exploited. CVE-2026-4020 can expose API keys, OAuth tokens, and system data through an unauthenticated REST API endpoint. Wordfence says it has blocked 17M+ exploit attempts. Read the full story: https://thehackernews.com/2026/06/hackers-exploit-gravity-smtp-wordpress.html https://t.co/6mR9EvAVgb

    Post summary

    CVE-2026-4020 is actively exploited to steal API keys and sensitive data via an unauthenticated REST endpoint, with Wordfence reporting millions of blocked attempts.

    629680620.4K
    2.2M followersView on X
  • Welsh ICP Conviction 🏴󠁧󠁢󠁷󠁬󠁳󠁿🏉@ICPLEGEND1966
    Active Exploitation

    🚨 WORDPRESS API KEYS EXPOSED. 17 MILLION EXPLOIT ATTEMPTS. THIS IS WHY $ICP MATTERS. Another day. Another Web2 stack bleeding secrets. Hackers are exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin, installed on around 100,000 sites. The issue is brutal: • Unauthenticated REST API access • Exposed configuration data • Exposed API keys • Exposed OAuth tokens • Exposed plugin versions • Exposed server and database details • Exploit traffic reportedly exceeded 17 million attempts • Peak activity hit over 4 million requests in one day • Patch required: Gravity SMTP v2.1.5 This is not “just a WordPress bug.” This is the business case. The old internet is built on fragile plugin chains, leaked API keys, rented servers, exposed endpoints, third-party secrets, and endless patch panic. One weak plugin can expose the entire stack. $ICP by @dfinity changes the model. $ICP enables applications to run as smart contract canisters, with backend logic, data, identity, web serving, and execution hosted directly on a decentralized compute network. No traditional cloud server dependency. No single hosting provider. No Web2 backend stitched together with exposed secrets. No fragile plugin stack pretending to be infrastructure. This is what cybersecurity is becoming: Not just firewalls. Not just patching. Not just alerts after the damage. Cybersecurity needs architecture-level resilience. And that is exactly where $ICP belongs. The next wave of cyberattacks will not slow down. They will accelerate. They will be automated. They will be AI-assisted. They will hit weak Web2 infrastructure every single day. The answer is not more duct tape. The answer is sovereign, tamper-resistant, decentralized compute. $ICP is not just another blockchain. $ICP is a new internet execution layer. Build where the backend cannot be quietly owned by one weak endpoint. Build on $ICP. #ICP #InternetComputer #DFINITY #Cybersecurity #WordPress #InfoSec #Web3 #DecentralizedCloud #AI #Blockchain #CyberAttack #DataSecurity #SovereignCompute Donation / contribution address: 1e672d038cebc619d93186418fa98f6499dbdb9cfdfac54f366c61a4a4ee4362

    Post summary

    The Gravity SMTP WordPress plugin (CVE‑2026‑4020) is being widely exploited with over 17 million attack attempts; a patch (v2.1.5) is required, and the post emphasizes the urgency of remediation.

    150160570
    1.6K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Active Exploitation

    Attackers are actively exploiting a critical Gravity SMTP vulnerability (CVE-2026-4020) causing sensitive information exposure. Update your plugin now. #GravitySMTP #Vulnerability #CyberSecurity #WordPress #CVE20264020 https://securityonline.info/gravity-smtp-vulnerability-active-exploits https://t.co/bxHnqBGvbr

    Post summary

    The tweet reports that CVE-2026-4020 is being exploited in the wild and urges users to update the Gravity SMTP plugin to mitigate the risk.

    1301311.0K
    12.8K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    هکرها در حال استفاده از یک آسیب‌پذیری امنیتی در افزونه وردپرسی Gravity SMTP هستند که روی حدود ۱۰۰٬۰۰۰ وب‌سایت نصب شده است. این آسیب‌پذیری با شناسه CVE-2026-4020 و امتیاز CVSS برابر با ۵.۳، یک نقص افشای اطلاعات (information disclosure) با شدت متوسط است که به مهاجمان احراز هویت‌نشده اجازه می‌دهد داده‌های حساسی نظیر کلیدهای API، توکن‌های OAuth و اطلاعات پیکربندی یکپارچه‌سازی‌های ایمیلی افزونه را استخراج کنند. شرکت امنیتی Wordfence اعلام کرد که این نقص ناشی از یک نقطه پایانی (REST API endpoint) است که بدون هیچ‌گونه احراز هویتی در دسترس عموم قرار دارد و بازگشت حدود ۳۶۵ کیلوبایت داده JSON شامل گزارش کامل سیستم را ممکن می‌سازد.

    Post summary

    Hackers are actively exploiting the CVE-2026-4020 vulnerability in the Gravity SMTP plugin to harvest sensitive configuration data from about 100,000 WordPress sites.

    0101401.4K
    19.2K followersView on X
  • yuutanman 💐:*.@yuutanman
    Disclosure

    【緊急】WordPressプラグイン「Gravity SMTP」に深刻な脆弱性!APIキーがダダ漏れに(CVE-2026-4020)|東京PCレスキュー隊長 @yuutanman https://note.com/tolove/n/ndaba396b6ffb?sub_rt=share_pb #WordPress脆弱性 #セキュリティ対策 #エンジニア #SMTP #サイバーセキュリティ

    Post summary

    The notice reports a serious vulnerability (CVE‑2026‑4020) in the Gravity SMTP WordPress plugin that allows API keys to be leaked, but it does not provide a PoC, exploit, patch or evidence of active exploitation.

    06060192
    2.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-4020 (CVSS 5.3) in Gravity SMTP exposes API keys, OAuth tokens, and full system data via a single unauthenticated GET to wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings. #DFIR_Radar https://t.co/ed0GctWjCB

    Post summary

    The tweet discloses that CVE-2026-4020 in Gravity SMTP allows an unauthenticated GET request to a specific API endpoint to retrieve API keys, OAuth tokens, and full system data, with a CVSS score of 5.3.

    24051306
    1.8K followersView on X
  • Wordfence@wordfence
    Active Exploitation

    Attackers Actively Exploiting Sensitive Information Exposure Vulnerability in Gravity SMTP WordPress Plugin The Wordfence Firewall has blocked over 17 million exploit attempts targeting CVE-2026-4020 (CVSS 5.3) in Gravity SMTP, a plugin with an estimated 100,000 active installations. Update to version 2.1.5. https://www.wordfence.com/blog/2026/06/attackers-actively-exploiting-sensitive-information-exposure-vulnerability-in-gravity-smtp-plugin/

    Post summary

    The article reports that CVE-2026-4020 in Gravity SMTP is being actively exploited, with millions of attack attempts detected, and advises users to update to version 2.1.5.

    12071447
    8.2K followersView on X
  • Anavem.com@Anavem_
    Disclosure

    CVE-2026-4020: Gravity SMTP Info Disclosure Hits 100K Sites CVE-2026-4020 lets unauthenticated attackers pull 365 KB of JSON - API keys, DB details… Read more: https://www.navanem.com/news/cve-2026-4020-hackers-exploit-gravity-smtp-info-disclosure-bug-on-100k-mqlg8t0g #Cve20264020 #GravitySmtp #Wordpress #InformationDisclosure

    Post summary

    CVE-2026-4020 allows unauthenticated attackers to retrieve confidential configuration and database information from Gravity SMTP installations, potentially affecting hundreds of thousands of WordPress sites.

    020401.0K
    164 followersView on X
  • Cyber Edition@CyberEdition
    Active Exploitation

    🐞 Attackers are actively exploiting the Gravity SMTP flaw (CVE-2026-4020) on WordPress sites. The bug can expose API keys, OAuth tokens, email credentials, and server details without authentication. If you're using Gravity SMTP, update now. #WordPress #CyberSecurity Read more: https://thecyberedition.com/gravity-smtp-flaw-exploited/

    Post summary

    The tweet reports that attackers are exploiting CVE-2026-4020 in Gravity SMTP on WordPress sites, exposing sensitive credentials, and urges users to update to mitigate the vulnerability.

    1002194
    763 followersView on X
  • CyberNewsDaily@NewsDaily18579
    Active Exploitation

    🟡 Threat Alert: Hackers exploit Gravity SMTP WordPress plugin bug (CVE-2026-4020 (CVSS: N/A) [EPSS: 3.0%]) to expose API keys, configuration data, and OAuth tokens. Unauthenticated attackers can extract sensitive data. 100,000 sites impacted. via The Hacker News… https://t.co/zndyXUzgxx

    Post summary

    The message reports that CVE-2026-4020 is being actively exploited by attackers to steal API keys and OAuth tokens from over 100,000 WordPress sites.

    0102181
    21 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-4020 - high 🚨 Gravity SMTP WordPress Plugin - Sensitive Information Exposure > Gravity SMTP WordPress plugin <= 2.1.4 contains a sensitive information exposure caus... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-4020 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-4020, a sensitive information exposure affecting Gravity SMTP WordPress Plugin versions up to 2.1.4, without mentioning exploits, patches, or active attacks.

    01021245
    960 followersView on X
  • CyberX@CyberXlx9q
    Active Exploitation

    ‼️𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗪𝗼𝗿𝗱𝗣𝗿𝗲𝘀𝘀 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗔𝗹𝗲𝗿𝘁 A critical vulnerability, tracked as CVE-2026-4020, has been reported in the Gravity SMTP WordPress plugin, potentially impacting more than 100,000 websites. According to security researchers, the flaw allows unauthenticated attackers to access sensitive information without valid credentials, including API keys, OAuth tokens, email service credentials, authentication tokens, and website configuration data. Reports indicate that the vulnerability is being actively exploited in the wild, with researchers observing millions of exploitation attempts targeting vulnerable installations. Successful exploitation could enable attackers to compromise connected email services, gain access to sensitive configuration data, and potentially facilitate further attacks against affected organizations. Website administrators are advised to update Gravity SMTP to version 2.1.5 or later and rotate any potentially exposed API keys, passwords, authentication tokens, and email service credentials. #CyberSecurity #WordPress #CVE20264020 #Vulnerability #ThreatIntel #WebsiteSecurity #InfoSec #PatchNow

    Post summary

    CVE-2026-4020 in the Gravity SMTP plugin is actively exploited, enabling attackers to harvest sensitive credentials; administrators should update to 2.1.5+ and rotate exposed keys.

    00021273
    606 followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    Gravity SMTP CVE-2026-4020 100,000 WordPress sites can leak their own secrets to anyone who asks. CVE-2026-4020 (CVSS 5.3) in the Gravity SMTP plugin lets unauthenticated attackers pull config data, API keys, secrets, and OAuth tokens. Already being exploited. "Medium severity" undersells it handing out OAuth tokens with no auth is a full credential-leak primitive. Patch now, then rotate every key that plugin could see. Source: @TheHackersNews via @VulnerabilityNw

    Post summary

    CVE‑2026‑4020 in Gravity SMTP permits unauthenticated attackers to exfiltrate sensitive configuration data and OAuth tokens, with evidence that it is already being exploited; the vendor is urged to patch immediately.

    01020132
    176 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Active Exploitation

    A Gravity SMTP WordPress vulnerability (CVE-2026-4020) exposes API keys and config data. 17M+ exploit attempts detected. Patch to 2.1.5 immediately. For More: https://www.redsecuretech.co.uk/blog/post/gravity-smtp-vulnerability-under-active-attack/1262 #GravitySMTP #CVE #WordPressSecurity #InfoDisclosure #EmailSecurity #Wordfence #PatchNow https://t.co/FegLNwsU1P

    Post summary

    CVE‑2026‑4020 is being actively exploited with over 17 million attempts; the advisory urges applying patch 2.1.5 immediately.

    0102087
    76 followersView on X
  • Cyberdark Imapct@kenebeii
    Active Exploitation

    【サイバーセキュリティ動向分析】 今日の主なサイバーセキュリティニュース(2026年6月20日時点) 1. Gravity SMTP WordPressプラグインの情報漏洩脆弱性(CVE-2026-4020)の積極的悪用 背景 Gravity SMTPは、WordPressサイトでメール送信機能を強化する人気のプラグインで、世界中で約10万サイトに導入されています。このプラグインはAmazon SES、Google、Mailjet、Resend、Zohoなどの外部メールサービスと連携し、APIキーやOAuthトークンを保存してメール配信を管理します。 2026年3月17日にベンダーからパッチ(バージョン2.1.5)がリリースされ、脆弱性はすでに修正されていましたが、6月に入ってから攻撃者による積極的な悪用が確認されています。脆弱性はCVE-2026-4020(CVSS 5.3、中程度)と追跡されており、Wordfenceの調査で3月下旬に公開され、以降数百万回の攻撃試行が観測されています。特に6月7日には1日で400万件以上のリクエストがブロックされるなど、悪用が急増しました。 技術的には、プラグインが登録するREST APIエンドポイント(/wp-json/gravitysmtp/v1/tests/mock-data)のpermission_callbackが無条件にtrueを返す設計ミスが原因です。クエリパラメータ?page=gravitysmtp-settingsを付与してアクセスすると、約365KBのJSON形式で詳細な「System Report」が返却されます。このレポートには、サーバー環境情報、WordPressのバージョン・プラグイン一覧、データベース構成に加え、メール連携で使用されているAPIキー・シークレット・OAuthトークンが含まれるため、認証なしで機密情報が取得可能です。 影響 影響を受けるサイトは依然として多く、パッチ未適用環境では攻撃者が容易にメールサービスのアカウントを乗っ取り、被害者名義で大量のスパム送信や標的型フィッシングメールを送信できるリスクがあります。また、システムレポートからサーバー構成や使用プラグインの情報が得られるため、さらなる脆弱性攻撃(例:他の未パッチ脆弱性の特定)の足がかりとなります。 Wordfenceはすでに1,700万件以上の悪用試行をブロックしており、実際の被害報告も出始めています。メール関連の資格情報が漏洩した場合、ビジネスメール詐欺(BEC)やアカウント乗っ取りによる金銭被害、ブランドイメージの毀損につながる可能性が高いです。特に中小企業や個人運営のWordPressサイトが多く影響を受けやすい点が懸念されています。 対策 最も優先すべきは、直ちにGravity SMTPをバージョン2.1.5以上に更新することです。パッチ適用後も、過去に保存されていたAPIキーやパスワードは漏洩している可能性があるため、**すべてのメール連携資格情報をローテーション(変更)**してください。 Webサーバーのアクセスログで、/wp-json/gravitysmtp/v1/tests/mock-dataへのリクエスト(特に?page=gravitysmtp-settings付き)を監視し、異常なIPアドレスをブロックリストに登録します。WordfenceなどのセキュリティプラグインやWAF(Web Application Firewall)を導入し、既知の悪用パターンをブロックするのも有効です。 また、WordPress全体のセキュリティベストプラクティス(定期的なプラグイン更新、最小権限の原則、2要素認証の導入)を徹底し、メールサービス側でもAPIキーの使用制限や監査ログの有効化を検討してください。 2. FortiBleedキャンペーンによるFortinet FortiGate VPN資格情報の大規模漏洩 背景 FortiBleedと呼ばれるロシア語圏の多人数犯罪グループによる大規模な資格情報収集・漏洩キャンペーンが明らかになりました。このグループは、過去のデータ漏洩やインフォスティーラーマルウェアから得た資格情報を基に、約32万台のインターネット公開FortiGateデバイスに対して11億6,000万回以上の認証試行を実施。さらに、SSL VPNの認証ハッシュを傍受し、45基のGPUクラスタ(Hashtopolis管理)でオフラインクラッキングを行い、平文パスワードを復元しました。 以前の2025年の類似漏洩(約1万5,000台規模)とは異なるIPアドレス群であり、より大規模かつ組織的な作戦であることが特徴です。漏洩データには、管理者資格情報だけでなく、組織の業種・売上・従業員数などのメタデータも含まれており、攻撃計画に活用された形跡があります。 影響 世界194カ国で約7万3,000〜7万5,000台のFortiGateファイアウォールおよびSSL VPNの管理者・VPN資格情報が漏洩したとされ、インターネット公開FortiGateの約半数に相当する規模です。影響を受けた組織には、Chevron、Samsung、Foxconn、Comcast、AT&T、Mercedes-Benz、Toyota、Siemensなどの大企業や、政府機関・重要インフラ事業者が多数含まれています。 攻撃者は漏洩した資格情報を使ってVPN経由で内部ネットワークに侵入し、Active Directoryへのラテラルムーブメント(横移動)を行い、機密データの窃取やランサムウェア展開の足がかりにできます。すでにトルコのNATO関連防衛請負業者から機密文書が盗まれた可能性が指摘されており、国家的・産業的スパイ活動や大規模データ侵害のリスクが現実化しています。多くのデバイスで管理インターフェースが直接インターネットに露出していた点も、被害拡大を助長しました。 対策 影響の可能性がある組織は、即座にFortinet関連の管理者パスワードとVPN資格情報をすべてローテーションしてください。多要素認証(MFA)の強制適用と、VPN接続時の追加認証を徹底します。 FortiGateの管理インターフェースをインターネットから直接露出させず、VPNやジャンプサーバー経由でのアクセスのみに制限します。ログを詳細に監査し、異常なログイン試行や内部からの不審な活動を検知する体制を強化してください。CISAや各国のセキュリティ機関の警告に従い、Fortinet公式のセキュリティアドバイザリを確認し、最新ファームウェアへの更新も並行して行います。 組織全体として、資格情報管理ツールの導入や、定期的なダークウェブ監視サービスを利用して、自社関連の漏洩を早期発見するのも有効です。 3. AutoJack攻撃:AIエージェントを悪用したホスト上でのリモートコード実行(RCE) 背景 MicrosoftのオープンソースAIフレームワーク「AutoGen」のプロトタイピングツール「AutoGen Studio」(プレリリース版0.4.3.dev1およびdev2)で発見された新種の攻撃手法です。AIエージェントがウェブブラウジング機能を使って悪意あるページを読み込むと、単一の悪意あるウェブページだけでホストマシン上で任意のコードを実行できる「AutoJack」と呼ばれるエクスプロイトチェーンがMicrosoft Security Blogで2026年6月19日に公開されました。 これはAIエージェントの普及に伴う新しい攻撃ベクトルで、従来のプロンプトインジェクションを超え、AIが「混乱した代理人(confused deputy)」として機能する点が特徴です。Model Context Protocol (MCP) WebSocketの実装に、localhost信頼境界のバイパス、認証スキップ、コマンド実行の未検証という3つの弱点が悪用されます。 影響 開発者やAIツールを日常的に使用する組織・個人が主な標的です。AIエージェント(例:Webコンテンツ要約エージェント)が攻撃者のURLを処理すると、JavaScript経由でローカルMCPサービスに接続し、ホスト上でプロセスを起動できます。PoCでは計算機アプリの起動が確認されており、実環境ではファイル操作、データ窃取、さらなるマルウェア展開が可能になります。 AIエージェントの自律性が高まるほど、この種の攻撃の影響は深刻化します。特にプレリリース版や開発環境でAIブラウジングエージェントを扱う場合、ホストマシン全体が危険にさらされるリスクがあります。現在、野外での実被害報告はありませんが、AIツールの急速な普及を考えると、将来的にサプライチェーン攻撃や標的型攻撃に悪用される可能性が高いです。 対策 安定版のPyPIパッケージ(0.4.2.2)を使用し、プレリリース版は避けてください。GitHubの最新コミット(b047730以降)で修正されたパッチを適用するか、公式リポジトリから最新版を取得します。 AIエージェントとブラウジング機能を同一ホスト上で実行せず、コンテナや仮想マシンで分離します。低権限アカウントで実行し、MCP制御プレーンの認証を強化、プロセス実行の許可リスト化を実施してください。 より広範には、AIエージェントフレームワーク全体で「localhostを信頼境界としない」設計の見直し、プロンプトやWebコンテンツの厳格なサニタイズ、実行時監視ツールの導入が推奨されます。開発者はAI関連ツールのセキュリティアップデートを常に監視し、Sandbox環境でのテストを徹底してください。 これらのニュースは、WordPressのような広く使われるツールの脆弱性悪用、VPNなどのインフラ機器の資格情報漏洩、そしてAIツールという新領域への攻撃という、現在のサイバー脅威の多様性を象徴しています。組織・個人ともに、迅速なパッチ適用と多層防御を心がけることが重要です。

    Post summary

    CVE-2026-4020 is actively exploited with millions of attempts; the post provides technical details, a patch, and remediation advice.

    000304.7K
    846 followersView on X
  • CyberAlertsHQ@CyberAlertsHQ
    Active Exploitation

    🚨 NEW: CVE-2026-4020 (CVSS 5.3) — Gravity SMTP WordPress plugin (100K+ installs) exposes API keys, OAuth tokens, and full system data via an unauthenticated REST endpoint. A single request to /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings returns a 365 KB JSON dump with everything. Wordfence has blocked 17M+ exploitation attempts. Peak: 4M requests on June 7 alone. The endpoint's permission_callback unconditionally returns true — authentication doesn't exist. Attackers get PHP version, database details, all plugin versions, API keys for Amazon SES, Google, Mailjet, Resend, and more. Patch to 2.1.5 now. If you run Gravity SMTP, assume your API credentials have been harvested. Rotate them immediately. 👇 https://www.bleepingcomputer.com/news/security/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin/

    Post summary

    CVE‑2026‑4020 in the Gravity SMTP WordPress plugin is actively exploited via an unauthenticated REST endpoint, exposing sensitive data; the vendor has released patch 2.1.5 and recommends immediate credential rotation.

    1001068
    86 followersView on X
  • ctrlaltnod@ctrlaltnod
    Active Exploitation

    CVE-2026-4020: Gravity SMTP Zero-Auth Flaw Exploited on 100K WordPress Sites Active exploitation of CVE-2026-4020 targets Gravity SMTP WordPress plugin. 412 attacking IPs recorded in 5 days. Pat... #Vulnerabilities #Cybersecurity #CyberNews #InfoSec https://www.ctrlaltnod.com/news/cve-2026-4020-gravity-smtp-flaw-hits-100k-wordpress-sites/

    Post summary

    CVE‑2026‑4020, a zero‑authentication flaw in the Gravity SMTP WordPress plugin, is being actively exploited across 100,000 sites with 412 distinct attacking IPs in five days; no PoC, patch, or tool details are disclosed.

    1001088
    289 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Active Exploitation

    Hackers are exploiting CVE-2026-4020 in Gravity SMTP, affecting 100,000+ WordPress sites and exposing API keys, OAuth tokens, and email credentials via a REST endpoint. #GravitySMTP #CVE20264020 #WordPress https://ift.tt/RpPE87D

    Post summary

    CVE-2026-4020 in Gravity SMTP is actively exploited, leaking API keys, OAuth tokens, and credentials through a REST endpoint on more than 100,000 WordPress sites.

    0101097
    4.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2026-4020. 0day Intel: Attackers are actively exploiting a critical Gravity SMTP vulnerability (CVE-202

    Post summary

    The text reports that attackers are actively exploiting CVE-2026-4020, a critical vulnerability in Gravity SMTP; no proof‑of‑concept, exploit code, or patch information is provided.

    1000076
    310 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    WordPress SMTP Plugin の脆弱性 CVE-2026-4020:高機密コンフィグ・データの抽出を検出 https://iototsecnews.jp/2026/06/18/hackers-exploit-wordpress-smtp-plugin-with-100000-installs-to-steal-sensitive-data/ この問題の原因は、メール配信機能を拡張するプラグインにおいて、外部へ向けて内部データを出力する際の権限検証設定に不備が残っていた点にあります。この脆弱性 CVE-2026-4020 を悪用する攻撃者は特別な資格を必要とせずに、外部通信用の大切な秘密鍵や許可証などの環境情報を一括で盗み出せる危険性を得ます。ユーザーにとって必要なことは、対策が施されたバージョン 2.1.5 以降への速やかなアップデートです。ご利用のチームは、ご注意ください。 #CVE20264020 #SMTPPlugin #Vulnerability #WordPress

    Post summary

    CVE-2026-4020 in the WordPress SMTP Plugin lets attackers extract sensitive configuration data without special privileges, with reports of active exploitation and a clear update recommendation to version 2.1.5 or newer.

    01000136
    501 followersView on X

Explore more