- Critical vulnerability chain in Avada theme and Fusion Builder plugin.
ThreatNoir Morning Brief — August 27
Morning Review in IT Security — August 27, 2026
The threat landscape continues to evolve with multiple critical vulnerabilities emerging across enterprise platforms and infrastructure components. Today's security briefing highlights urgent risks affecting WordPress installations, federal government networks, GPU systems, and Microsoft SharePoint deployments that require immediate attention from security teams.
Critical Avada WordPress Theme Flaw Enables Zero-Click RCE
A critical vulnerability chain has been discovered in the widely deployed Avada theme for WordPress that permits unauthenticated attackers to execute arbitrary PHP code directly on affected servers. The vulnerability, tracked as CVE-2026-18431, represents a severe risk to the thousands of websites relying on this popular theme. Source: Critical Avada WordPress theme flaw enables zero-click RCE
The zero-click nature of this exploit means attackers require no user interaction or authentication credentials to compromise affected systems. Organizations running Avada should prioritize immediate patching and review their WordPress installations for signs of exploitation.
Officials Disrupt Chinese Espionage Operation Targeting Federal Agencies
Law enforcement authorities have successfully disrupted a sophisticated Chinese government-funded espionage operation that maintained undetected access to multiple federal agency networks for more than eight years. The seized infrastructure and hacking suite provide insight into the advanced capabilities deployed by state-sponsored threat actors against sensitive U.S. government systems. Source: Officials disrupt Chinese espionage operation that hit multiple federal agencies
This operation demonstrates the persistent threat posed by nation-state actors who employ advanced techniques to maintain long-term access to critical infrastructure. The disruption represents a significant counterintelligence victory, though the extended duration of the campaign underscores the sophisticated evasion methods employed by such actors.
New GPUThor Attack Defeats NVIDIA ECC Protection for Root Access
Researchers have disclosed a novel Rowhammer attack designated GPUThor that successfully bypasses error-correcting code protections on NVIDIA GPUs, enabling attackers to achieve root-level privilege escalation and denial-of-service conditions. This attack methodology circumvents hardware-level security mechanisms previously considered robust defenses against memory-based attacks. Source: New GPUThor attack defeats NVIDIA ECC protection for root access
The implications of this vulnerability extend to data centers, high-performance computing environments, and any infrastructure relying on NVIDIA GPUs for critical operations. Organizations operating such systems should evaluate their exposure and monitor for potential mitigation strategies from NVIDIA.
Hackers Target Microsoft SharePoint RCE Chain with PoC Exploit
Active exploitation has commenced against a chained vulnerability in Microsoft SharePoint that permits remote code execution on unpatched servers. Threat intelligence firm Defused reports that attackers are leveraging publicly available proof-of-concept exploits targeting CVE-2026-32201, CVE-2026-45659, CVE-2026-55040, CVE-2026-56164, and CVE-2026-63520. Source: Hackers target Microsoft SharePoint RCE chain with PoC exploit
The availability of functional exploit code significantly accelerates the threat timeline for organizations operating unpatched SharePoint instances. Immediate patching of affected systems is critical, as the combination of multiple vulnerabilities creates a severe attack surface for both opportunistic and sophisticated threat actors.
Security teams should prioritize these emerging threats across their infrastructure, implementing patches and conducting threat hunting activities to identify any signs of compromise or exploitation attempts.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Authentication bypass flaw in JWT token validation
- Vulnerability in SharePoint's Business Connectivity Services (BCS) chained for RCE
- Previously warned about by CISA for SharePoint exploitation
- Previously warned about by CISA for SharePoint exploitation, now used in ransomware
- Previously warned about by CISA for SharePoint exploitation