Find notable cyber news and cases, enriched with sources, timelines, and signals.

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code execution on vulnerable WordPress sites. The patched versions are Avada 7.16.1 and Fusion Builder 3.16.1, closing the issue for sites running the vulnerable combination of both products. Administrators still on older releases face the same unauthenticated zero-click RCE risk until they update. "ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday."

Related Happenings

Ubiquiti UniFi Protect Application patch for CVE-2026-77537

Security Patch Release
H score25 First: 26.08.2026 16:17 Last: 26.08.2026 16:17 Sources 1

About this happening: Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Adobe security patch release for CVE-2026-71398

Security Patch Release
H score37 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...

Latest development: 12.08.2026 14:13

Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

Timeline

  1. 27.08.2026 00:33 1 articles · 1h ago

    Wordfence's Argus reproduces CVE-2026-18431

    Technical Analysis Update

    Wordfence's internal Argus framework finds and successfully reproduces the six-step CVE-2026-18431 chain affecting Avada and Fusion Builder, and the team generates proof-of-concept exploit code for a zero-click path that can reach arbitrary PHP code execution on a target server.

    Show sources
  2. 27.08.2026 00:33 1 articles · 1h ago

    Wordfence shares CVE-2026-18431 details with ThemeFusion

    Initial Disclosure

    Wordfence shares the full CVE-2026-18431 details with ThemeFusion, the developer behind Avada and Fusion Builder, after confirming the vulnerability chain that requires vulnerable versions of both products to be active on the target website.

    Show sources
  3. 27.08.2026 00:33 1 articles · 1h ago

    ThemeFusion acknowledges the CVE-2026-18431 report

    Untyped Phase

    ThemeFusion acknowledges the CVE-2026-18431 report covering Avada and Fusion Builder after receiving the vulnerability details from Wordfence.

    Show sources
  4. 27.08.2026 00:33 2 articles · 1h ago

    ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes

    Mitigation Patch Update

    ThemeFusion releases fixes for CVE-2026-18431 in Avada 7.16.1 and Fusion Builder 3.16.1, closing the unauthenticated zero-click PHP code execution path for affected WordPress sites.

    Show sources