Exchange, WordPress and FortiGate Under Active Attack: What K-12 IT Teams Should Patch Today

Exchange CVE-2026-96940, exploited WordPress plugin XSS, and FortiBleed attacks on FortiGate VPNs: what K-12 IT teams must patch now.

  • Microsoft shipped out-of-band Exchange Server updates for CVE-2026-96940, a high-severity privilege-escalation flaw (CVSS reported in the 8 range) that Redmond says is more likely to be exploited.
  • Attackers are actively exploiting stored XSS in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to plant backdoors and create rogue administrator accounts; WordPress 7.1.3 also carries 7 security fixes.
  • The FBI and U.S. Secret Service warn that FortiBleed credential harvesting against internet-facing FortiGate firewalls and SSL VPN gateways is still ongoing — roughly 86,644 credentials amassed, with some administrators locked out of their own devices.

What to do now

  1. 1) Patch in this order: apply Microsoft's out-of-band Exchange Server updates for CVE-2026-96940 to every on-premises server, then update all WordPress sites to 7.1.3, then update Ninja Forms and WPC Product Bundles for WooCommerce to their latest patched releases. If a plugin has no fix yet, deactivate it and tell the site owner why.
  2. 2) Cut management access off the public internet. Put FortiGate management and SSL VPN portals behind a trusted management VLAN or a jump host, disable unused remote-management services, and do the same for any building-automation controllers such as Johnson Controls EasyIO FG (firmware up to 2.0b52, CVE-2026-27872 and CVE-2026-27873, CVSS 7.7).
  3. 3) Enforce MFA and rotate credentials everywhere: FortiGate admin and VPN accounts, Exchange service and privileged accounts, and all WordPress administrator accounts. Invalidate WordPress sessions and rotate salts, then remove unknown or stale accounts.
  4. 4) Hunt for persistence before you declare victory. On WordPress, diff core, plugin and theme files against clean copies and inspect uploads, mu-plugins, wp-config.php, scheduled tasks and database options for backdoors. On Exchange and FortiGate, review logs for unexpected privilege changes, deleted admin accounts, configuration edits and impossible-travel VPN logins.
  5. 5) Fix recovery before you need it. Confirm backups are isolated or immutable, test a restore of at least one critical system, and keep offline copies of FortiGate configurations plus out-of-band console access so a lockout does not become an outage.

Related items