> cd .. / HUB_EDITORIALE
News

Nextcloud Hacked: Main Website Redirects Visitors to Cloudbox Over the Weekend

[2026-07-21] Author: Meteora Web Redazione
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

Nextcloud, the European open-source collaboration suite increasingly adopted by governments as a Microsoft 365 alternative, has suffered a cyberattack that took down its main website. The company confirmed the incident in a statement to Dutch tech outlet Tweakers, while its official forum continues to describe the situation as a normal infrastructure problem without further details. The site went dark on Sunday, and before the outage, users on Reddit reported that links from nextcloud.com were redirecting to a site called Cloudbox. Nextcloud is restoring the site from a backup, but as of Tweakers' report on Monday, it had not yet returned.

The attack only affects the website, not services

The company maintains that the damage is limited to the website only. According to Nextcloud, there has been no impact on updates or downloads, and no data related to operational processes resides on the compromised server, so there should be no consequences for users or customers. However, this is the company's internal assessment, with no independent confirmation available. The cybersecurity community awaits further details, while concerns grow about possible connected vulnerabilities.

Sponsored Protocol

Possible link to the WordPress wp2shell flaw

The cause of the hack has not been officially disclosed. Nextcloud's site runs WordPress, and the intrusion could be linked to the critical wp2shell vulnerability, a pre-authentication remote code execution chain that exploits two flaws in WordPress: CVE-2026-63030 and CVE-2026-60137. The patch was released on July 17, 2026 in versions 6.9.5 and 7.0.2. Public exploits for wp2shell began circulating over the weekend, and researchers have reported early signs of in-the-wild exploitation. While the connection to Nextcloud remains unconfirmed, the timing is suspicious. For a comparison with another recent security incident, see the article on the autonomous AI agent that breached Hugging Face.

Sponsored Protocol

Implications for users and businesses using Nextcloud

Nextcloud is widely used by public and private organizations seeking greater data control compared to external cloud solutions. The hack raises questions about the security of open-source platforms and their ability to withstand targeted attacks. Although Nextcloud has assured that user data has not been compromised, the incident highlights the importance of keeping content management systems updated. WordPress, in particular, is a frequent target: for more information, see the Wikipedia entry on WordPress. Businesses should verify that they have applied the latest security patches and consider additional measures such as web application firewalls.

Sponsored Protocol

The situation is evolving, and official updates from Nextcloud are expected. Meanwhile, the security community is monitoring the development of attacks based on wp2shell. To stay informed about other vulnerabilities and incidents, it is recommended to follow the official WordPress and Nextcloud channels.

Source: https://www.internationalcyberdigest.com/nextcloud-hacked

> share
Meteora Web Redazione

> AUTHOR_EXTRACTED

Meteora Web Redazione

La redazione di Meteora Web Agency: ingegneri informatici e professionisti del digitale che pubblicano ogni giorno news e approfondimenti su tecnologia, software, marketing e innovazione.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()