From a single line of code to a shield for over 100,000 websites: Galaxy One expert makes his mark in cybersecurity

A Critical security vulnerability with a CVSS score of 9.8, more than 100,000 potentially affected websites, and recognition from Wordfence – a globally trusted name in WordPress security. Behind this achievement is the dedicated research of Trần Văn Nhân, Offensive Security Specialist, working alongside Nhiên Phạm, Security Engineer at Galaxy One – a member of the Galaxy Holdings Digital Ecosystem.

 

When a small detail can create risk at scale

 

While analyzing Pods – Custom Content Types and Fields, a WordPress plugin actively installed on more than 100,000 websites, Trần Văn Nhân discovered a critical security vulnerability that was subsequently assigned the identifier CVE-2026-19598.

Officially disclosed by Wordfence on August 21, 2026, CVE-2026-19598 was rated Critical with a CVSS score of 9.8/10, placing it among vulnerabilities with an exceptionally high severity level. The vulnerability could allow unauthenticated attackers to bypass authorization mechanisms and perform actions normally restricted to administrators, including changing the password of any user account, potentially resulting in a complete website takeover.

At the heart of the vulnerability was a subtle paradox that could easily go unnoticed: although the system incorporated authentication, nonce verification and authorization checks, under a specific error condition, the program failed to terminate execution as intended. As a result, multiple layers of security could potentially be bypassed at once.

To put it simply, imagine a website as a building. A stranger swipes an invalid access card, the scanner correctly displays “Access Denied,” yet the security door still opens. From there, the intruder could enter the “control room,” grant themselves access privileges and ultimately take control of the entire building. With more than 100,000 active installations, the widespread use of Pods meant that the timely discovery and remediation of this vulnerability carried significance far beyond any single website or organization.

 

Behind every CVE are hours spent asking “Why?”

 

The discovery of CVE-2026-19598 was the result of an extensive research process combining source code analysis with hands-on security testing. Nhân traced individual data-processing flows, examined authentication and authorization mechanisms, built a dedicated testing environment, and developed a Proof of Concept (PoC) to demonstrate that the vulnerability could be exploited in real-world conditions.

According to the timeline published by Wordfence, the vulnerability report was received on August 10, 2026. Just two days later, Wordfence validated the PoC, shared the full details with the Pods development team, and deployed a firewall rule to protect users of its premium products. By August 14, 2026, Wordfence had reviewed and approved the completed patch, and the Pods team officially released a fixed version. Wordfence also coordinated with WordPress.org to help accelerate updates across affected websites.

 

Proud of Galaxy Troopers Creating Impact Beyond Organizational Boundaries

 

This achievement represents far more than another entry on an international cybersecurity record. Trần Văn Nhân’s contribution at Galaxy One reflects the team’s in-depth research capabilities, strong sense of ownership and perseverance – qualities embodied by Galaxy Troopers who continuously challenge assumptions, delve deeply into complex problems, and turn their expertise into contributions with impact beyond the organization.

Beyond the significance of an individual achievement, this journey also serves as an inspiration for young engineers pursuing their path in cybersecurity. Because sometimes, an impact that reaches hundreds of thousands of systems begins with the persistence to never overlook a single detail hidden among thousands of lines of code.

Tin tức

Tin tức liên quan

News & Events

Related news

Contact with
Galaxy Holdings

Contact Us