View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical SharePoint RCE CVE-2026-50522 Actively Exploited After

🚨 ACTIVE EXPLOITATION

  • Critical SharePoint RCE CVE-2026-50522 Actively Exploited After Public PoC Release — thehackernews.com
    Attackers are actively exploiting CVE-2026-50522 to execute remote code on SharePoint servers.

    • Affects all supported on-premises Microsoft SharePoint Server versions including Subscription Edition, 2019, and 2016
    • Vulnerability is a critical deserialization of untrusted data allowing remote code execution (RCE) with CVSS score 9.8
    • Exploitation requires attacker to be authenticated as at least a Site Owner on the network
    • Attackers exploit via network remotely, stealing SharePoint machine keys to maintain persistent access
    • Active exploitation detected after public proof-of-concept (PoC) release, with exploitation assessed as 'More Likely'
  • Qilin Ransomware Exploits PAN-OS Auth Bypass for Initial Access — thehackernews.com
    Qilin ransomware attackers exploited a PAN-OS authentication bypass vulnerability for network access.

    • Targets Palo Alto Networks PAN-OS portal and gateway components
    • Exploits CVE-2026-0257, an authentication bypass flaw allowing VPN session establishment without credentials
    • Attackers use SSL VPN sessions to gain authenticated access and escalate privileges
    • Post-exploitation includes credential harvesting, lateral movement via PsExec, and log clearing
    • Ransomware deployment varies from encryption-only to double-extortion with data exfiltration
  • Exploitation of ServiceNow CVE-2026-6875 Remote Code Execution Flaw Seen Days After Patch — securityweek.com
    The ServiceNow CVE-2026-6875 vulnerability is being exploited in the wild shortly after disclosure.

    • Applies to ServiceNow AI platform, affecting both hosted and self-hosted instances
    • Vulnerability is a sandbox escape allowing unauthenticated remote code execution
    • Patch released on July 14, 2026; hosted instances updated by vendor, self-hosted require manual patching
    • Exploitation observed days after disclosure leveraging publicly released technical details
    • Exploit payload identical to proof-of-concept published by cybersecurity firm Searchlight Cyber

💥 BREACHES & INCIDENTS

  • No Title — mastodon.social/@zackwhittaker
    The Suno data breach disclosed last week affected over 55 million users, exposing names, physical addresses, and phone numbers.

    • Data breach occurred last year; disclosure delayed until July 2026
    • Source: Have I Been Pwned
  • Seoul's Ttareungi bike-sharing data breach exposed info of 4 million users — koreajoongangdaily.com
    A data breach exposed personal information of 4 million Seoul Ttareungi bike-sharing users.

    • Leaked data includes account IDs, phone numbers, addresses, birth dates, gender, and weight
    • Two teenagers hacked the service's server in June 2024 and leaked the data
    • Seoul Facilities Corporation is notifying users via text and offering a 30-day free bike pass
    • No evidence of data sharing with third parties or secondary damage reported

🕵️ RESEARCH & DEEP DIVES

  • DD-WRT UPnP Buffer Overflow CVE-2021-27137 Allows Remote Code Execution — ssd-disclosure.com
    DD-WRT routers have a stack-based buffer overflow in UPnP enabling remote code execution.

    • Applies to DD-WRT firmware versions before 45724 with UPnP enabled
    • Vulnerability is a stack-based buffer overflow in UPnP handling (ssdp_msearch)
    • Allows unauthenticated remote attackers to overflow an internal fixed buffer
    • Exploitation requires sending a crafted M-SEARCH request to the router
    • UPnP is off by default and listens only on internal interfaces by default
  • Critical RCE Vulnerability CVE-2026-0770 Found in Langflow 1.4.2 via exec_globals Parameter — zerodayinitiative.com
    Langflow 1.4.2 is vulnerable to remote code execution via untrusted control sphere inclusion.

    • Applies to Langflow version 1.4.2 installations
    • Vulnerability in exec_globals parameter at validate endpoint allows code execution
    • No authentication required to exploit the flaw
    • Attack enables remote arbitrary code execution with root privileges
    • Classified as CWE-829: Inclusion of Functionality from Untrusted Control Sphere
  • WordPress pre-auth RCE via chained SQL injection and REST API flaws (CVE-2026-60137, CVE-2026-63030) — github.com
    WordPress versions before 6.8.6, 6.9.5, and 7.0.2 are vulnerable to pre-auth remote code execution.

    • Vulnerability in WP_Query author__not_in parameter allows SQL injection when exploited by plugins or themes
    • REST API batch endpoint route confusion (CVE-2026-63030) can be chained with SQLi (CVE-2026-60137) for remote code execution
    • Attack requires no authentication and exploits input sanitization and API endpoint confusion
  • Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) — reddit.com
    Local privilege escalation vulnerability in Windows WalletService detailed with proof of concept.

📋 ADVISORIES

  • Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Four XSS Vulnerabilities — thehackernews.com
    Zimbra patched critical SNMP command injection and multiple XSS vulnerabilities in version 10.1.20.
    • Applies to Zimbra Collaboration Suite version 10.1.20
    • Critical command injection vulnerability in SNMP monitoring component when SNMP notifications are enabled
    • Four cross-site scripting (XSS) flaws in the Classic Web Client involving malicious attachment filenames and crafted fields
    • Mail forwarding restriction bypass (CVE-2026-50055) allowing authenticated users to exfiltrate email
    • No active exploitation reported; vulnerabilities discovered by Rapid7 researcher Jonah Burgess

⚠️ OTHER

  • Meta Paid $78K Bug Bounty for Vulnerability Exposing Customer Support Data — securityweek.com
    Meta paid a $78,000 bounty for a vulnerability exposing customer support data.

    • Applies to Meta's backend support infrastructure and Meta Horizon Managed Solutions
    • Vulnerability involved broken access control, missing authorization, and IDOR issues
    • Allowed enumeration of support case numbers and access to user-support email/chat data
    • Attackers could create/modify support requests and access personal/contact info
    • Discovered by researcher Rony K Roy, reported January 2026, patched by April 2026
  • Other: 20 CVEs (worst 7.5)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check