Data pipelines leaking credit card info and critical server exploits.

Daily Cybersecurity News - May 16, 2026

Funnel Builder Plugin Flaw Steals Credit Cards

Attackers are injecting malicious JavaScript into WooCommerce checkout pages through a Funnel Builder plugin flaw.

The bug lets unauthenticated users modify global settings to insert arbitrary scripts that capture card details on payment forms. Actively exploited in the wild.

Affects versions prior to 3.15.0.3 across any WordPress site running Funnel Builder with WooCommerce. Developers released a patch in version 3.15.0.3.

Pwn2Own Day Two Hands Out Cash for Exchange and Windows 11

Pwn2Own Berlin just paid out real money for zero days in Microsoft Exchange and Windows 11 on day two.

Teams chained browser flaws into Exchange RCE and used a Windows 11 sandbox escape. Fifteen unique zero days fell across the targets.

The wins cover Exchange on Windows 11 plus Red Hat Enterprise Linux for workstations.

Teams collected 385750 dollars total that day.

PoC Code Published for Critical NGINX Vulnerability

Attackers now have public code to target a long-hidden flaw in NGINX that has sat there since 2008. Tracked as CVE-2026-42945 (CVSS 9.2). The bug is a heap buffer overflow in the ngx_http_rewrite_module (URL rewriting). Remote unauthenticated users can trigger remote code execution under certain rewrite configurations. NGINX open source up to 1.30.0 and some NGINX Plus releases are exposed. The flaw was fixed in 1.30.1 (stable) / 1.31.0 (mainline) on May 13, but the public PoC dropped shortly after.

Source: SecurityWeek