CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
SAP patches three critical security vulnerabilities (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761) in NetWeaver, AppRouter and Commerce Cloud that enable memory corruption, DoS attacks and token theft.