The security flaw is tracked as CVE-2026-19949, it impacts the Backup plugin and All-in-One WP Migration, which is utilized by over five million active wordpress installations. The plugin lets site owners to migrate, import, export, and backup sites, this consists of media files, themes, plugins, and databases.
As per Bleeping Computer, the flaw is a second-order SQL injection vulnerability that could permit an unauthorized threat actor to run malicious code on a compromised site. The flaw impacts variants 7.109 and earlier and has been given high severity, with a 8.8 CVSS score.
The vulnerability was found by security expert Jack Taylor, who reported the incident to cybersecurity company Wordfence, which investigated and disclosed the flaw. On August 15, 2026, Wordfence informed the plugin’s developer, Servmask, which released variant 7.220 on August 20 to patch the flaw.
“On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations,” Wordfence reported.
Contrary to flaws that can be abused immediately, this vulnerability consists of an extra step. Threat actors first place specially tailored data on a compromised website.
The malicious information remains latent until a website admin does a backup restoration of the archive. “This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site takeover,” Wordfence said.
In the restoration stage, the stored malicious data can be used as SQL commands which allows threat actors to take out sensitive data from the website’s database.
An important target is the plugin’s secret ai1wm_secret_key.. If a threat actor accesses this key, it can possibly be used to move from database access to remote code execution (RCE), allowing the threat actor more control over the compromised website.
Through RCE, threat actors could install malicious code, change website files, and create backdoors.
ServMask addressed the CVE-2026-19949 in variant 7.110 of the plugin. Users are advised to update their websites to the latest patched versions of Backup and All-in-One WP Migration.
On August 20, ServMask addressed the CVE-2026-19949 vulnerability in version 7.110 of the plugin.
The critical SQL injection (SQLi) flaw, identified as CVE-2024-50387, was discovered in QNAP's SMB Service. This vulnerability has now been patched in versions 4.15.002 or later and h4.15.002 and later. The fix was implemented a week after researchers YingMuo, participating through the DEVCORE Internship Program, successfully exploited the flaw to gain root access to a QNAP TS-464 NAS device at Pwn2Own Ireland 2024.
The Pwn2Own competitions are legendary in cybersecurity circles. These events invite the brightest ethical hackers from around the globe to demonstrate their skills by identifying and exploiting vulnerabilities in widely used software and hardware. The stakes are high, with significant monetary rewards and prestige on the line. The ultimate goal, however, is to strengthen the security of the products we rely on daily by exposing and rectifying their weaknesses.
At the 2024 Pwn2Own Ireland event, a critical vulnerability was uncovered in QNAP's HBS 3 Hybrid Backup Sync software, an essential tool for users seeking to secure their data through backup solutions. This vulnerability, identified as CVE-2024-50388, was an OS command injection flaw that allowed attackers to execute arbitrary commands on the host system. In simpler terms, this flaw could enable unauthorized individuals to gain root access to QNAP NAS devices—a severe security breach.
Upon learning of the exploit, QNAP's response was both prompt and thorough. The company's immediate actions underscore the importance of rapid response in cybersecurity. They quickly released a security patch to address the vulnerability, mitigating the risk to their users. This quick turnaround is crucial because the longer a vulnerability remains unaddressed, the greater the potential for malicious exploitation.
The patch not only protects users from potential attacks but also reinforces trust in QNAP's commitment to security. For any company in the tech space, maintaining user confidence is paramount, and QNAP's decisive action in patching the vulnerability goes a long way in assuring their user base.
This incident with QNAP's HBS 3 software offers the importance of regular software updates and patches. Users must diligently apply updates to protect their systems against known vulnerabilities. Companies must maintain robust monitoring and response mechanisms to swiftly address any emerging threats.
Events like Pwn2Own stress the value of collaboration between tech companies and the ethical hacking community. By working together, they can identify and fix vulnerabilities before they can be exploited by malicious actors. This proactive approach to cybersecurity is essential in a world where the threat landscape is continually evolving.
This vulnerability exists because the web-based management interface does not adequately validate user input. An attacker could exploit this vulnerability by authenticating to the application and sending crafted SQL queries to an affected system.
A successful exploit could allow the attacker to obtain any data from the database, execute arbitrary commands on the underlying operating system, and elevate privileges to root. To exploit this vulnerability, an attacker would need at least Read Only user credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability
SQL injection is a type of security vulnerability that occurs when an attacker manipulates input data to execute arbitrary SQL queries against a database. In the case of Cisco FMC Software, an authenticated attacker can exploit this vulnerability by sending crafted SQL queries to the web-based management interface.
Successful exploitation of this vulnerability can have severe consequences:
Data Extraction: The attacker can retrieve sensitive data from the database, including user credentials, configuration details, and logs.
Command Execution: By injecting malicious SQL queries, the attacker can execute arbitrary commands on the underlying operating system.
Privilege Escalation: If the attacker gains access to the database, they can potentially elevate their privileges to root.
Cisco has published free software upgrades to address the vulnerability mentioned in this advisory. Customers with service contracts that include regular software updates should receive security fixes through their usual update channels.
Customers can only install and receive support for software versions and feature sets for which they have acquired a license.
Cisco has promptly addressed this issue by releasing software updates. Organizations using Cisco FMC Software should take the following steps:
Millions of Americans recently experienced prescription medicine delays or were forced to pay full price as a result of a ransomware assault. While the United States has begun to make headway in reacting to cyberattacks, including the passage of incident reporting requirements into law, it is apparent that much more work remains to be done to combat the ransomware epidemic.
Ransomware gangs flourish because they usually attack genuinely easy weaknesses in software that serve as the basis for critical operations and services.
Various vulnerabilities in open source video platforms YouPHPTube and AVideo could be utilized to accomplish remote code execution (RCE) on a client's gadget. It can take an average of more than four years for vulnerabilities in open-source software to be detected, an area in the security community that needs to be addressed, researchers say. Experts from Synacktiv found various vulnerabilities in the source code-shared by the ventures that were because of an absence of client input sanitization, a related write-up reads. The issues incorporate an unauthenticated SQL injection vulnerability, multiple cross-site scripting (XSS) flaws, and a file write vulnerability.
A German multinational software corporation SAP ( Systems Applications and Products in Data Processing ) is known for developing software solutions that work on managing business operations as well as customer relations. SAP is the name of their software as well as of the company that works on this technology. SAP provides “future-proof Cloud ERP (Enterprise Resource Planning) solutions that will power the next generation of business.” With its advanced capabilities, SAP can boost your organization's efficiency and productivity by automating repetitive tasks, making better use of your time, money, and resources.
![]() |
| Nullcrew chatting with Bell support team |
![]() |
| Post-based SQL Injection in Bell Canada |