Skip to content
COOEY

FAIL › dossier

Core

PRODUCT

· dossier confidence 20%

Core Natural Resources has experienced significant security vulnerabilities, particularly in its use of Drupal and WordPress, which have been exploited in ransomware attacks. The company needs to improve its security posture and processes.

PROFILE
CategoryProduct/ServiceWhat they doCore Natural Resources, Inc. (CNR) is a company that produces, sells, and exports metallurgical and thermal coals in the United States and internationally. Websitehttps://www.stockanalysis.com/stocks/cnr/company/ ↗
SECURITY POSTURE

The company has faced multiple security vulnerabilities, indicating a need for improved security measures.

Notable failures
  • CVE-2018-7602 (RCE): Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications.
  • CVE-2026-63030 (RCE): WordPress 6.6.11 exposed to RCE via unhandled input.
  • CVE-2026-60137 (RCE): WordPress 6.6.11 exposed to RCE via unhandled input.
  • CVE-2026-9082 (RCE): Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API.
  • CVE-2019-6340 (RCE): In Drupal Core, some field types do not properly sanitize data from non-form sources, leading to arbitrary PHP code execution in some cases.
Patterns: Repeated unpatched edge-device RCEs.; Vulnerabilities in widely used platforms like Drupal and WordPress.
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-04-13 CVE-2018-7602 critical Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications and content management.
2026-07-21 CVE-2026-63030 high WordPress 6.6.11 exposed to RCE via unhandled input
2022-03-25 CVE-2019-6340 high Drupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources.
2026-07-21 CVE-2026-60137 high WordPress 6.6.11 exposed to RCE via unhandled input
2026-05-22 CVE-2026-9082 high Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API.
Open questions: What is the exact size and headquarters location of Core Natural Resources?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:39:07.095819+00:00