Nextcloud Website Defaced in Suspected wp2shell Attack
Nextcloud’s showcase website, the open source alternative to Microsoft 365, was unreachable for several hours last weekend. After initially describing the incident as a simple infrastructure problem, Nextcloud eventually admitted that an attack had led to nextcloud.com being defaced. The leading theory at this stage: the critical wp2shell flaw at the heart of WordPress. Here is what we know.
An "infrastructure problem" that turned out to be a defacement
It all began on Sunday, July 19, 2026, when nextcloud.com became unreachable. Before it even went offline, some users noticed unusual behavior: certain links on the site redirected to a third-party service called "Cloudbox." This information was also reported on Reddit.
On Mastodon, Nextcloud first spoke of a simple "infrastructure problem" and said the site would be restored from a backup. In parallel, a post-mortem analysis was carried out to identify the cause of this so-called infrastructure issue. Then, on Tuesday, July 21, 2026, Netcloud finally confirmed that it was indeed a cyberattack that led to a defacement of its site. Nextcloud also said the affected server was isolated.

As a reminder, a defacement refers to the unauthorized modification of a website’s appearance by an attacker, who replaces all or part of its content.
Nextcloud says only nextcloud.com was affected by this cyberattack, with no impact on updates, downloads, customer Netcloud servers, or other services. But how can the compromise of Nextcloud’s website be explained?
wp2shell, the WordPress flaw Nextcloud cannot rule out
The exact cause of the intrusion has not been officially established. However, one early lead has been mentioned: the wp2shell security flaw, patched last Friday in WordPress. Asked by heise, Nextcloud said it could not rule out wp2shell as the source of the intrusion, and the investigation is indeed heading in that direction. This suggests that nextcloud.com relies, at least in part, on WordPress.
As a reminder, if you missed it: the wp2shell flaw urgently fixed by WordPress is a critical RCE vulnerability disclosed on July 17, 2026. Located in the WordPress Core, it can be exploited without any account, any third-party plugin, or any specific interaction: a single specially crafted anonymous request is enough on a default installation. Versions 6.9.x and 7.0.x are vulnerable, with fixes available in versions 6.9.5 and 7.0.2 respectively.
The timeline is fueling suspicion, especially since public exploits began circulating as early as last weekend. The vulnerability is also considered exploited in the wild (it has been added to the CISA catalog), and several cybersecurity vendors have also observed active exploitation of wp2shell.

