FAIL › dossier
Core
PRODUCT· dossier confidence 20%
Core Natural Resources has experienced significant security vulnerabilities, particularly in its use of Drupal and WordPress, which have been exploited in ransomware attacks. The company needs to improve its security posture and processes.
PROFILE
CategoryProduct/ServiceWhat they doCore Natural Resources, Inc. (CNR) is a company that produces, sells, and exports metallurgical and thermal coals in the United States and internationally.
Websitehttps://www.stockanalysis.com/stocks/cnr/company/ ↗
SECURITY POSTURE
The company has faced multiple security vulnerabilities, indicating a need for improved security measures.
Notable failures
- CVE-2018-7602 (RCE): Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications.
- CVE-2026-63030 (RCE): WordPress 6.6.11 exposed to RCE via unhandled input.
- CVE-2026-60137 (RCE): WordPress 6.6.11 exposed to RCE via unhandled input.
- CVE-2026-9082 (RCE): Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API.
- CVE-2019-6340 (RCE): In Drupal Core, some field types do not properly sanitize data from non-form sources, leading to arbitrary PHP code execution in some cases.
Patterns: Repeated unpatched edge-device RCEs.; Vulnerabilities in widely used platforms like Drupal and WordPress.
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-04-13 | CVE-2018-7602 | critical | Drupal Core suffered a critical remote code execution vulnerability actively exploited in ransomware attacks, impacting DIB organizations using the platform for web applications and content management. |
| 2026-07-21 | CVE-2026-63030 | high | WordPress 6.6.11 exposed to RCE via unhandled input |
| 2022-03-25 | CVE-2019-6340 | high | Drupal Core's improper data sanitization allowed arbitrary PHP code execution via non-form sources. |
| 2026-07-21 | CVE-2026-60137 | high | WordPress 6.6.11 exposed to RCE via unhandled input |
| 2026-05-22 | CVE-2026-9082 | high | Drupal Core SQL injection vulnerability enables remote code execution and privilege escalation via database API. |
DOSSIER SOURCES
- Core Natural Resources (CNR) Company Profile & Description · stockanalysis.com
- CoreWeave (CRWV) Company Profile & Description - Stock Analysis · stockanalysis.com
- Allbridge Core Hit by $1.65M Solana Flash-Loan Exploit, Its Second ... · www.cryptotimes.io
- wp2shell WordPress Core Vulnerability Could Let Unauthenticated ... · www.lemon-web.net
- Core Natural Resources (CNR) Company Profile & Description · stockanalysis.com
- Core Natural Resources Inc, CNR:NYQ profile - FT.com · markets.ft.com
- Core Natural Resources Inc, C9X0:MUN profile - FT.com · markets.ft.com
Open questions: What is the exact size and headquarters location of Core Natural Resources?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:39:07.095819+00:00