ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
Summary
Hide ▲
Show ▼
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code execution on vulnerable WordPress sites. The patched versions are Avada 7.16.1 and Fusion Builder 3.16.1, closing the issue for sites running the vulnerable combination of both products. Administrators still on older releases face the same unauthenticated zero-click RCE risk until they update. "ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday."
Related Happenings
Ubiquiti UniFi Protect Application patch for CVE-2026-77537
Security Patch Release
H score25
First: 26.08.2026 16:17
Last: 26.08.2026 16:17
Sources 1
About this happening:
Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...
Ubiquiti UniFi Protect Application patch for CVE-2026-77537
Security Patch ReleaseAbout this happening: Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Timeline
-
27.08.2026 00:33 1 articles · 1h ago
Wordfence's Argus reproduces CVE-2026-18431
Technical Analysis UpdateWordfence's internal Argus framework finds and successfully reproduces the six-step CVE-2026-18431 chain affecting Avada and Fusion Builder, and the team generates proof-of-concept exploit code for a zero-click path that can reach arbitrary PHP code execution on a target server.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 1h ago
Wordfence shares CVE-2026-18431 details with ThemeFusion
Initial DisclosureWordfence shares the full CVE-2026-18431 details with ThemeFusion, the developer behind Avada and Fusion Builder, after confirming the vulnerability chain that requires vulnerable versions of both products to be active on the target website.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 1h ago
ThemeFusion acknowledges the CVE-2026-18431 report
Untyped PhaseThemeFusion acknowledges the CVE-2026-18431 report covering Avada and Fusion Builder after receiving the vulnerability details from Wordfence.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 2 articles · 1h ago
ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes
Mitigation Patch UpdateThemeFusion releases fixes for CVE-2026-18431 in Avada 7.16.1 and Fusion Builder 3.16.1, closing the unauthenticated zero-click PHP code execution path for affected WordPress sites.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33