Exchange, WordPress and FortiGate Under Active Attack: What K-12 IT Teams Should Patch Today
Exchange CVE-2026-96940, exploited WordPress plugin XSS, and FortiBleed attacks on FortiGate VPNs: what K-12 IT teams must patch now.
- Microsoft shipped out-of-band Exchange Server updates for CVE-2026-96940, a high-severity privilege-escalation flaw (CVSS reported in the 8 range) that Redmond says is more likely to be exploited.
- Attackers are actively exploiting stored XSS in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to plant backdoors and create rogue administrator accounts; WordPress 7.1.3 also carries 7 security fixes.
- The FBI and U.S. Secret Service warn that FortiBleed credential harvesting against internet-facing FortiGate firewalls and SSL VPN gateways is still ongoing — roughly 86,644 credentials amassed, with some administrators locked out of their own devices.
What to do now
- 1) Patch in this order: apply Microsoft's out-of-band Exchange Server updates for CVE-2026-96940 to every on-premises server, then update all WordPress sites to 7.1.3, then update Ninja Forms and WPC Product Bundles for WooCommerce to their latest patched releases. If a plugin has no fix yet, deactivate it and tell the site owner why.
- 2) Cut management access off the public internet. Put FortiGate management and SSL VPN portals behind a trusted management VLAN or a jump host, disable unused remote-management services, and do the same for any building-automation controllers such as Johnson Controls EasyIO FG (firmware up to 2.0b52, CVE-2026-27872 and CVE-2026-27873, CVSS 7.7).
- 3) Enforce MFA and rotate credentials everywhere: FortiGate admin and VPN accounts, Exchange service and privileged accounts, and all WordPress administrator accounts. Invalidate WordPress sessions and rotate salts, then remove unknown or stale accounts.
- 4) Hunt for persistence before you declare victory. On WordPress, diff core, plugin and theme files against clean copies and inspect uploads, mu-plugins, wp-config.php, scheduled tasks and database options for backdoors. On Exchange and FortiGate, review logs for unexpected privilege changes, deleted admin accounts, configuration edits and impossible-travel VPN logins.
- 5) Fix recovery before you need it. Confirm backups are isolated or immutable, test a restore of at least one critical system, and keep offline copies of FortiGate configurations plus out-of-band console access so a lockout does not become an outage.
Related items
- Ninja Forms plugin flaw exploited to hack WordPress sites
- CVE-2026-96940: Microsoft Fixes Exchange Server Flaw For Which Exploitation Is More Likely
- FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
- Ransomware has a new target. Is your backup ready?
- WordPress 7.1.3 Maintenance and Security Release
- Johnson Controls EasyIO FG
- FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
- FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins