Nextcloud, the European open-source collaboration suite increasingly adopted by governments as a Microsoft 365 alternative, has suffered a cyberattack that took down its main website. The company confirmed the incident in a statement to Dutch tech outlet Tweakers, while its official forum continues to describe the situation as a normal infrastructure problem without further details. The site went dark on Sunday, and before the outage, users on Reddit reported that links from nextcloud.com were redirecting to a site called Cloudbox. Nextcloud is restoring the site from a backup, but as of Tweakers' report on Monday, it had not yet returned.
The attack only affects the website, not services
The company maintains that the damage is limited to the website only. According to Nextcloud, there has been no impact on updates or downloads, and no data related to operational processes resides on the compromised server, so there should be no consequences for users or customers. However, this is the company's internal assessment, with no independent confirmation available. The cybersecurity community awaits further details, while concerns grow about possible connected vulnerabilities.
Sponsored Protocol
Possible link to the WordPress wp2shell flaw
The cause of the hack has not been officially disclosed. Nextcloud's site runs WordPress, and the intrusion could be linked to the critical wp2shell vulnerability, a pre-authentication remote code execution chain that exploits two flaws in WordPress: CVE-2026-63030 and CVE-2026-60137. The patch was released on July 17, 2026 in versions 6.9.5 and 7.0.2. Public exploits for wp2shell began circulating over the weekend, and researchers have reported early signs of in-the-wild exploitation. While the connection to Nextcloud remains unconfirmed, the timing is suspicious. For a comparison with another recent security incident, see the article on the autonomous AI agent that breached Hugging Face.
Sponsored Protocol
Implications for users and businesses using Nextcloud
Nextcloud is widely used by public and private organizations seeking greater data control compared to external cloud solutions. The hack raises questions about the security of open-source platforms and their ability to withstand targeted attacks. Although Nextcloud has assured that user data has not been compromised, the incident highlights the importance of keeping content management systems updated. WordPress, in particular, is a frequent target: for more information, see the Wikipedia entry on WordPress. Businesses should verify that they have applied the latest security patches and consider additional measures such as web application firewalls.
Sponsored Protocol
The situation is evolving, and official updates from Nextcloud are expected. Meanwhile, the security community is monitoring the development of attacks based on wp2shell. To stay informed about other vulnerabilities and incidents, it is recommended to follow the official WordPress and Nextcloud channels.
Source: https://www.internationalcyberdigest.com/nextcloud-hacked