Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-64638: Debian Linux: Unauthenticated Remote Code Execution

CVE-2026-64638 · published 28 days ago
Summary

A security issue in Debian Linux's package manager allows an attacker to run malicious code on a system without being authenticated. This could happen if a user installs a compromised package. To protect your system, ensure you only install packages from trusted sources and keep your Debian Linux up to date with the latest security patches.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian wordpress All versions
Debian:12 debian wordpress All versions
Debian:13 debian wordpress All versions
Debian:14 debian wordpress All versions
– wordpress wordpress All versions
Ubuntu:16.04:LTS canonical wordpress All versions
Ubuntu:18.04:LTS canonical wordpress All versions
Ubuntu:20.04:LTS canonical wordpress All versions
Ubuntu:22.04:LTS canonical wordpress All versions
Ubuntu:24.04:LTS canonical wordpress All versions
Ubuntu:26.04:LTS canonical wordpress All versions
Original advisory text
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be ...
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.

Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.

This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

Discovered and responsibly disclosed by [the team at pwn.ai](https://pwn.ai/).
Severity
9.4 Critical
CVSS 4.0: 8.9 (NVD)
CVSS 4.0: 9.4 (OSV)
Exploitation
EPSS 31%
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published7 Aug 2026
Updated2 Sep 2026
First seen7 Aug 2026
Monitor software like this
Free during beta