Find notable cyber news and cases, enriched with sources, timelines, and signals.

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code execution on vulnerable WordPress sites. The patched versions are Avada 7.16.1 and Fusion Builder 3.16.1, closing the issue for sites running the vulnerable combination of both products. Administrators still on older releases face the same unauthenticated zero-click RCE risk until they update. "ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday."

Related Happenings

Vercel security patch release for CVE-2026-75604

Security Patch Release
H score33 First: 27.08.2026 18:13 Last: 27.08.2026 18:13 Sources 1

About this happening: Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixe...

Ubiquiti UniFi Protect Application patch for CVE-2026-77537

Security Patch Release
H score25 First: 26.08.2026 16:17 Last: 26.08.2026 16:17 Sources 1

About this happening: Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Adobe security patch release for CVE-2026-48362

Security Patch Release
H score43 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...

Adobe security patch release for CVE-2026-71398

Security Patch Release
H score37 First: 11.08.2026 19:50 Last: 11.08.2026 19:50 Sources 1

About this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...

Latest development: 12.08.2026 14:13

Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.

Timeline

  1. 27.08.2026 00:33 1 articles · 14d ago

    Wordfence's Argus reproduces CVE-2026-18431

    Technical Analysis Update

    Wordfence's internal Argus framework finds and successfully reproduces the six-step CVE-2026-18431 chain affecting Avada and Fusion Builder, and the team generates proof-of-concept exploit code for a zero-click path that can reach arbitrary PHP code execution on a target server.

    Show sources
  2. 27.08.2026 00:33 1 articles · 14d ago

    Wordfence shares CVE-2026-18431 details with ThemeFusion

    Initial Disclosure

    Wordfence shares the full CVE-2026-18431 details with ThemeFusion, the developer behind Avada and Fusion Builder, after confirming the vulnerability chain that requires vulnerable versions of both products to be active on the target website.

    Show sources
  3. 27.08.2026 00:33 1 articles · 14d ago

    ThemeFusion acknowledges the CVE-2026-18431 report

    Untyped Phase

    ThemeFusion acknowledges the CVE-2026-18431 report covering Avada and Fusion Builder after receiving the vulnerability details from Wordfence.

    Show sources
  4. 27.08.2026 00:33 2 articles · 14d ago

    ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes

    Mitigation Patch Update

    ThemeFusion releases fixes for CVE-2026-18431 in Avada 7.16.1 and Fusion Builder 3.16.1, closing the unauthenticated zero-click PHP code execution path for affected WordPress sites.

    Show sources