ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
Summary
Hide ▲
Show ▼
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code execution on vulnerable WordPress sites. The patched versions are Avada 7.16.1 and Fusion Builder 3.16.1, closing the issue for sites running the vulnerable combination of both products. Administrators still on older releases face the same unauthenticated zero-click RCE risk until they update. "ThemeFusion acknowledged the report on August 10 and released fixes in Avada 7.16.1 and Fusion Builder 3.16.1 yesterday."
Related Happenings
Vercel security patch release for CVE-2026-75604
Security Patch Release
H score33
First: 27.08.2026 18:13
Last: 27.08.2026 18:13
Sources 1
About this happening:
Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixe...
Vercel security patch release for CVE-2026-75604
Security Patch ReleaseAbout this happening: Vercel released Next.js security patches for two critical vulnerabilities that could permit unauthenticated remote code execution in affected deployments. The fixe...
Ubiquiti UniFi Protect Application patch for CVE-2026-77537
Security Patch Release
H score25
First: 26.08.2026 16:17
Last: 26.08.2026 16:17
Sources 1
About this happening:
Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...
Ubiquiti UniFi Protect Application patch for CVE-2026-77537
Security Patch ReleaseAbout this happening: Ubiquiti released security patches for CVE-2026-77537 in UniFi Protect Application, fixing an improper input validation flaw that could let unauthenticated a...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Adobe security patch release for CVE-2026-48362
Security Patch Release
H score43
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-48362
Security Patch ReleaseAbout this happening: Adobe shipped a priority 1 update for ColdFusion that fixes 15 security defects, including flaws that could enable arbitrary code execution and application D...
Adobe security patch release for CVE-2026-71398
Security Patch Release
H score37
First: 11.08.2026 19:50
Last: 11.08.2026 19:50
Sources 1
About this happening:
Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Adobe security patch release for CVE-2026-71398
Security Patch ReleaseAbout this happening: Adobe released a Priority 1 security update for Campaign Classic to address multiple critical vulnerabilities, including CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381. The fl...
Latest development: 12.08.2026 14:13
Adobe shipped updates for ColdFusion, Commerce, and Campaign Classic to fix multiple critical flaws that could enable arbitrary code execution, privilege escalation, and application denial-of-service. The highest-severity issues include CVE-2026-48362, CVE-2026-48273, CVE-2026-71384, CVE-2026-71362, CVE-2026-71398, CVE-2026-27302, and CVE-2026-48381, with the Campaign Classic fixes tied to ACC v7 7.4.4 build 9400. The ColdFusion and Campaign Classic updates have a Priority 1 rating; the Campaign Classic changes apply only to fully on-premise deployments and on-premise components of hybrid deployments, while Adobe-hosted instances have already been remediated and require no customer action.
Timeline
-
27.08.2026 00:33 1 articles · 14d ago
Wordfence's Argus reproduces CVE-2026-18431
Technical Analysis UpdateWordfence's internal Argus framework finds and successfully reproduces the six-step CVE-2026-18431 chain affecting Avada and Fusion Builder, and the team generates proof-of-concept exploit code for a zero-click path that can reach arbitrary PHP code execution on a target server.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 14d ago
Wordfence shares CVE-2026-18431 details with ThemeFusion
Initial DisclosureWordfence shares the full CVE-2026-18431 details with ThemeFusion, the developer behind Avada and Fusion Builder, after confirming the vulnerability chain that requires vulnerable versions of both products to be active on the target website.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 1 articles · 14d ago
ThemeFusion acknowledges the CVE-2026-18431 report
Untyped PhaseThemeFusion acknowledges the CVE-2026-18431 report covering Avada and Fusion Builder after receiving the vulnerability details from Wordfence.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
-
27.08.2026 00:33 2 articles · 14d ago
ThemeFusion releases Avada 7.16.1 and Fusion Builder 3.16.1 fixes
Mitigation Patch UpdateThemeFusion releases fixes for CVE-2026-18431 in Avada 7.16.1 and Fusion Builder 3.16.1, closing the unauthenticated zero-click PHP code execution path for affected WordPress sites.
Show sources
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33
- Critical Avada WordPress theme flaw enables zero-click RCE — www.bleepingcomputer.com — 27.08.2026 00:33