🚨 ACTIVE EXPLOITATION
- Critical unauthenticated RCE in SharePoint CVE-2026-50522 expected to see mass exploitation — cyberplace.social
CVE-2026-50522 is a critical unauthenticated remote code execution vulnerability in SharePoint, a widely exposed internet technology.- Applies to SharePoint, a widely exposed internet technology
- Vulnerability is unauthenticated remote code execution (RCE)
- Exploit code for CVE-2026-50522 has been publicly posted
- Experts warn of imminent mass exploitation
🔓 CVEs & KEV
- CVE-2026-60369 — CVSS 9.9 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60372 — CVSS 9.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-61246 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60455 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60439 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60373 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60371 — CVSS 8.0 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60370 — CVSS 7.5 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-16632 — WebSocket Frame vulnerability in facil.io
- CVE-2026-16631 — OS command injection in publint package-manager
- CVE-2026-60368 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60367 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-60366 — Oracle Platform Security for Java product of Oracle Fusion Middleware
- CVE-2026-16630 — OS command injection in syncfusion ej2-javascript-ui-controls
🕵️ RESEARCH & DEEP DIVES
-
GitHub pays $100,000 bounty for critical unauthenticated RCE vulnerability CVE-2026-3854 — runtimewire.com
GitHub awarded a $100,000 bounty for a critical unauthenticated remote code execution flaw affecting all public and private repositories.- Vulnerability allows unauthenticated RCE via specially crafted repository URLs
- Attackers could gain shell access, read secrets, and alter code in transit
- GitHub patched the flaw within 48 hours and publicly acknowledged the issue and bounty
- The payout is among the largest in GitHub's Vulnerability Reward Program
-
Russian Hacker Arrested in Thailand; Suno AI Music Generator Hacked Exposing Copyright Data — grahamcluley.com
A Russian intelligence-linked hacker was arrested in Thailand, and Suno AI's music generator was hacked exposing copyrighted training data.- Hacker linked to Russian government arrested during a beach holiday
- Evidence included 14 separate McNuggets orders
- Stolen data reveals extent of copyrighted music used to train AI models
📋 ADVISORIES
- Check Point patches CVE-2026-16232 authentication bypass in SmartConsole — support.checkpoint.com
Check Point fixed an authentication bypass vulnerability in SmartConsole under active exploitation.- Affects Security Management Server and Multi-Domain Security Management Server
- Allows unauthenticated attackers to obtain login tokens and full admin privileges
- Affected versions include R77.30 through R82.10 and intermediate releases
- Exploitation requires internet access to Management Server IP and unrestricted Trusted Clients
- Known attacker IPs include 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250