Skip to content
Signals
NVD · CVE-2026-7726 · 6.5 · The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync(NVD · CVE-2026-7693 · 7.2 · The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization oNVD · CVE-2026-7520 · 8.1 · The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` anNVD · CVE-2026-7444 · 8.1 · The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missinCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-7726 · 6.5 · The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync(NVD · CVE-2026-7693 · 7.2 · The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization oNVD · CVE-2026-7520 · 8.1 · The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` anNVD · CVE-2026-7444 · 8.1 · The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missinCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07
← Campaigns
HistoricalTLP:CLEARConfidence: Medium

Operation OpenGate

First seen November 15, 2025 · Last seen April 30, 2026

Public preview

Summary and targeting visible. Pro adds TTP and actor context, Pro+ adds IOC exports and enrichment.

Plans →

Summary

Hacktivist campaign combining DDoS attacks and website defacement with data leak threats against government and energy organizations.

Target Sectors

GovernmentEnergy

Target Regions

Global

Safety Note

Fictional hacktivist campaign. No real defacement targets, leaked data or DDoS targets referenced.

MITRE ATT&CK Techniques

T1491.002External Defacement

Impact

Implement file integrity monitoring on web content. Deploy web application firewalls. Maintain content backups for rapid restoration. Monitor for unauthorized content changes.