View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published

๐Ÿšจ ACTIVE EXPLOITATION

  • UPDATE: Hackers Probe Microsoft SharePoint RCE Chain After PoCs Published
    Attackers are probing a publicly exposed Microsoft SharePoint RCE chain.

    • Microsoft SharePoint Server deployments are affected, including more than 8,700 exposed online.
    • CVE-2026-55040 allows unauthenticated JWT authentication bypass and privilege abuse.
    • CVE-2026-63520 affects Business Connectivity Services and enables remote code execution when chained.
    • Public PoCs for both flaws were released in August, and attackers are probing the chain in honeypots; no code execution has been observed.
      ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer
  • UPDATE: CISA: Hackers Targeted More Than 100 U.S. Water Systems in July
    Hackers targeted more than 100 U.S. water and wastewater systems during July.

    • U.S. water and wastewater facilities in more than a dozen states were targeted.
    • Attackers locked out operators and disrupted pumps, causing pressure loss, flooding and boil-water advisories.
    • The campaign affected more than 30 Minnesota systems and caused no reported illnesses.
    • Iran-linked CyberAv3ngers claimed responsibility, but the U.S. government has not publicly attributed the attacks.
    • The actors scanned internet-exposed PLCs and used unchanged default credentials.
      ๐Ÿ“Ž Coverage: techcrunch.com ยท ๐Ÿ‘ via @zackwhittaker@mastodon.social, @metacurity@infosec.exchange

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Bishop Fox Demonstrates Unauthenticated RCE in Veeam Service Provider Console
    Bishop Fox demonstrated unauthenticated remote code execution in Veeam Service Provider Console.
    • Managed service providers using Veeam Service Provider Console are affected.
    • VSPC versions 9.2.1.33875 and earlier 9.x builds are vulnerable.
    • CVE-2026-58073 lets an unauthenticated network attacker impersonate a connected backup agent and obtain its certificate.
    • CVE-2026-58072 lets an attacker with an agent certificate write files anywhere on the server.
    • Chaining the flaws enables remote code execution on the multi-tenant management console.
      ๐Ÿ“Ž Coverage: bishopfox.com ยท ๐Ÿ‘ via Bishop Fox Blog

๐Ÿ”“ CVEs & KEV

  • CVE-2026-54569 โ€” CVSS 9.8 โ€” SENAITE.CORE: Improper Neutralization of Directives in Dynamically Evaluated ...

  • CVE-2026-45018 โ€” CVSS 9.8 โ€” Chainlit Unauthenticated RCE via MCP Endpoint (CVE-2026-45018)

  • CVE-2026-81032 โ€” CVSS 9.3 โ€” NebulaGraph through 3.8.0 Unauthenticated Read and Modification of Runtime Co...

  • CVE-2026-80428 โ€” CVSS 9.3 โ€” ILIAS before 9.22, 10.10 and 11.3 Unauthenticated PHP Object Injection via Sh...

  • CVE-2026-75062 โ€” CVSS 9.2 โ€” Eval Injection in google/langfun via default lf.query protocolImproper Neutra...

  • CVE-2026-81031 โ€” CVSS 8.6 โ€” IDURAR ERP CRM through 4.1.1 Account Takeover via Unverified Identifier on Pa...

  • CVE-2026-54511 โ€” CVSS 8.6 โ€” LogTape Syslog Structured Data Injection (CVE-2026-54511)

  • CVE-2026-81036 โ€” CVSS 8.5 โ€” Stalwart Mail Server through 0.16.19 Authorization Code Disclosure via Unvali...

  • CVE-2026-81029 โ€” CVSS 8.5 โ€” OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redire...

  • CVE-2026-81030 โ€” CVSS 7.1 โ€” Mage AI through 0.9.79 Arbitrary File Read via Unvalidated Path in browser_it...

  • CVE-2026-81028 โ€” CVSS 6.9 โ€” ZLMediaKit downloadFile Root-Directory Confinement Bypass via Prefix Collisio...

๐Ÿ“‹ ADVISORIES

  • ๐Ÿ“„ Source for FBI disrupts QTFY proxy network used in China-linked cyberespionage โ€” justice.gov

  • ๐Ÿ“„ Source for Suspected Chinese-Speaking Operator Targeted Philippine Nuclear, Naval Entities โ€” hunt.io

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check