🚨 ACTIVE EXPLOITATION
-
Critical SharePoint RCE CVE-2026-50522 Actively Exploited After Public PoC Release — thehackernews.com
Attackers are actively exploiting CVE-2026-50522 to execute remote code on SharePoint servers.- Affects all supported on-premises Microsoft SharePoint Server versions including Subscription Edition, 2019, and 2016
- Vulnerability is a critical deserialization of untrusted data allowing remote code execution (RCE) with CVSS score 9.8
- Exploitation requires attacker to be authenticated as at least a Site Owner on the network
- Attackers exploit via network remotely, stealing SharePoint machine keys to maintain persistent access
- Active exploitation detected after public proof-of-concept (PoC) release, with exploitation assessed as 'More Likely'
-
Qilin Ransomware Exploits PAN-OS Auth Bypass for Initial Access — thehackernews.com
Qilin ransomware attackers exploited a PAN-OS authentication bypass vulnerability for network access.- Targets Palo Alto Networks PAN-OS portal and gateway components
- Exploits CVE-2026-0257, an authentication bypass flaw allowing VPN session establishment without credentials
- Attackers use SSL VPN sessions to gain authenticated access and escalate privileges
- Post-exploitation includes credential harvesting, lateral movement via PsExec, and log clearing
- Ransomware deployment varies from encryption-only to double-extortion with data exfiltration
-
Exploitation of ServiceNow CVE-2026-6875 Remote Code Execution Flaw Seen Days After Patch — securityweek.com
The ServiceNow CVE-2026-6875 vulnerability is being exploited in the wild shortly after disclosure.- Applies to ServiceNow AI platform, affecting both hosted and self-hosted instances
- Vulnerability is a sandbox escape allowing unauthenticated remote code execution
- Patch released on July 14, 2026; hosted instances updated by vendor, self-hosted require manual patching
- Exploitation observed days after disclosure leveraging publicly released technical details
- Exploit payload identical to proof-of-concept published by cybersecurity firm Searchlight Cyber
💥 BREACHES & INCIDENTS
-
No Title — mastodon.social/@zackwhittaker
The Suno data breach disclosed last week affected over 55 million users, exposing names, physical addresses, and phone numbers.- Data breach occurred last year; disclosure delayed until July 2026
- Source: Have I Been Pwned
-
Seoul's Ttareungi bike-sharing data breach exposed info of 4 million users — koreajoongangdaily.com
A data breach exposed personal information of 4 million Seoul Ttareungi bike-sharing users.- Leaked data includes account IDs, phone numbers, addresses, birth dates, gender, and weight
- Two teenagers hacked the service's server in June 2024 and leaked the data
- Seoul Facilities Corporation is notifying users via text and offering a 30-day free bike pass
- No evidence of data sharing with third parties or secondary damage reported
🕵️ RESEARCH & DEEP DIVES
-
DD-WRT UPnP Buffer Overflow CVE-2021-27137 Allows Remote Code Execution — ssd-disclosure.com
DD-WRT routers have a stack-based buffer overflow in UPnP enabling remote code execution.- Applies to DD-WRT firmware versions before 45724 with UPnP enabled
- Vulnerability is a stack-based buffer overflow in UPnP handling (ssdp_msearch)
- Allows unauthenticated remote attackers to overflow an internal fixed buffer
- Exploitation requires sending a crafted M-SEARCH request to the router
- UPnP is off by default and listens only on internal interfaces by default
-
Critical RCE Vulnerability CVE-2026-0770 Found in Langflow 1.4.2 via exec_globals Parameter — zerodayinitiative.com
Langflow 1.4.2 is vulnerable to remote code execution via untrusted control sphere inclusion.- Applies to Langflow version 1.4.2 installations
- Vulnerability in exec_globals parameter at validate endpoint allows code execution
- No authentication required to exploit the flaw
- Attack enables remote arbitrary code execution with root privileges
- Classified as CWE-829: Inclusion of Functionality from Untrusted Control Sphere
-
WordPress pre-auth RCE via chained SQL injection and REST API flaws (CVE-2026-60137, CVE-2026-63030) — github.com
WordPress versions before 6.8.6, 6.9.5, and 7.0.2 are vulnerable to pre-auth remote code execution.- Vulnerability in WP_Query author__not_in parameter allows SQL injection when exploited by plugins or themes
- REST API batch endpoint route confusion (CVE-2026-63030) can be chained with SQLi (CVE-2026-60137) for remote code execution
- Attack requires no authentication and exploits input sanitization and API endpoint confusion
-
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) — reddit.com
Local privilege escalation vulnerability in Windows WalletService detailed with proof of concept.
📋 ADVISORIES
- Zimbra 10.1.20 Fixes Critical SNMP Command Injection and Four XSS Vulnerabilities — thehackernews.com
Zimbra patched critical SNMP command injection and multiple XSS vulnerabilities in version 10.1.20.- Applies to Zimbra Collaboration Suite version 10.1.20
- Critical command injection vulnerability in SNMP monitoring component when SNMP notifications are enabled
- Four cross-site scripting (XSS) flaws in the Classic Web Client involving malicious attachment filenames and crafted fields
- Mail forwarding restriction bypass (CVE-2026-50055) allowing authenticated users to exfiltrate email
- No active exploitation reported; vulnerabilities discovered by Rapid7 researcher Jonah Burgess
⚠️ OTHER
-
Meta Paid $78K Bug Bounty for Vulnerability Exposing Customer Support Data — securityweek.com
Meta paid a $78,000 bounty for a vulnerability exposing customer support data.- Applies to Meta's backend support infrastructure and Meta Horizon Managed Solutions
- Vulnerability involved broken access control, missing authorization, and IDOR issues
- Allowed enumeration of support case numbers and access to user-support email/chat data
- Attackers could create/modify support requests and access personal/contact info
- Discovered by researcher Rony K Roy, reported January 2026, patched by April 2026
-
Other: 20 CVEs (worst 7.5)