tag: Active-Exploitation · 42 items
- Engineer — Act: If you run Sangoma Switchvox SMB Edition 8.3, patch immediately — a public PoC exists and active exploitation is reported. Restrict network access to the Switchvox admin interface as an interim control while a patch is applied.
- SOC/IR — Act: Active exploitation is deploying reverse shells from VoIP infrastructure; hunt for anomalous outbound connections originating from Switchvox hosts and sweep network logs for unexpected C2 traffic since the PoC went public.
- Leader — Skip
- Signals: CVE-2026-9586 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: PaperCut NG/MF was exploited as a zero-day and attacks are ongoing — patch to the latest released version immediately and audit server logs for signs of unauthorized access or data exfiltration.
- SOC/IR — Act: Active data theft via PaperCut exploitation means assume-breach posture for any organization running PaperCut — hunt for anomalous outbound traffic and lateral movement from PaperCut servers since before the patch date.
- Leader — Plan: PaperCut is widely used in enterprise and education; confirm whether the organization runs it and verify that engineering has applied the patch — brief leadership only if patch status is unconfirmed or delayed.
- Engineer — Act: CVE-2026-0768 in Langflow is a CVSS 9.8 RCE running as root with a public PoC and confirmed active exploitation — patch or take Langflow offline immediately; also audit Rails deployments for CVE-2026-66066 exposure and apply the latest Rails patch given the 0.28 EPSS and available PoC.
- SOC/IR — Act: Active exploitation includes credential-probing and C2 callback activity — hunt for anomalous outbound connections and lateral movement originating from Langflow or Rails app servers since these flaws became public, and build detections for post-exploitation behavior on those hosts.
- Leader — Skip
- Signals: CVE-2026-0768 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub · CVE-2026-66066 — CISA KEV: not listed, EPSS 0.28, public PoC on GitHub
- Engineer — Act: PaperCut NG and MF are actively exploited and the first fix was bypassed, meaning unpatched and initially-patched instances remain at risk; update to the latest emergency release immediately and verify the new version is applied end-to-end.
- SOC/IR — Plan: Active exploitation with a bypassed patch means print servers in the estate may already be compromised; build or tune detections for anomalous outbound connections and process spawning from PaperCut service accounts, and sweep logs back to the original disclosure date.
- Leader — Plan: If PaperCut is in the environment, confirm with engineering that the second emergency patch is deployed and request a status update — active exploitation plus a failed first fix is the kind of event that can escalate to a breach if patching is delayed.
- Engineer — Act: PaperCut NG and MF print management software is under active zero-day exploitation with confirmed customer incidents; apply PaperCut’s emergency patch for v25/v26 immediately and isolate unpatched instances from the network until patched.
- SOC/IR — Act: Confirmed active exploitation means assume-breach posture for any PaperCut server in the estate; sweep PaperCut application logs for anomalous requests and lateral movement indicators since PaperCut servers have been used as initial-access footholds in prior ransomware campaigns.
- Leader — Act: Active zero-day with confirmed customer incidents in widely deployed enterprise print software; this week confirm whether your organization runs PaperCut NG or MF, verify emergency patching is underway, and prepare a brief for leadership if exposure is confirmed.
- Engineer — Act: Unauthenticated RCE via chained flaws in PaperCut NG/MF is being actively exploited; apply the emergency patch immediately and audit PaperCut server logs for unexpected Java process execution or outbound connections predating the patch.
- SOC/IR — Act: Active exploitation of PaperCut print servers means assumed-breach posture is warranted — hunt for anomalous Java child processes or unusual network activity originating from PaperCut hosts since before the emergency patch date, and check EDR telemetry on any print-management systems.
- Leader — Plan: PaperCut NG/MF is common in enterprise and education environments; confirm with engineering that all instances are patched this week and verify no lateral movement occurred from print servers — prior PaperCut exploits (2023) drew board attention, so have a status update ready if asked.
- Engineer — Act: Zero-day active exploitation in PaperCut NG and MF means no waiting for a patch window; immediately check whether your organization runs either product, apply any vendor-published mitigations or workarounds, and monitor PaperCut’s advisory page for patch availability.
- SOC/IR — Act: Active exploitation of PaperCut servers creates an immediate assume-breach window; hunt for anomalous child-process spawning from PaperCut services, unusual outbound connections from print-management hosts, and review authentication logs on those servers going back at least two weeks.
- Leader — Act: PaperCut NG/MF is broadly deployed in enterprise environments and prior PaperCut vulnerabilities were rapidly weaponized by ransomware actors; confirm with your team this week whether either product is in use and verify that mitigations are being applied before a patch is available.
- Engineer — Act: Over 270 confirmed compromises signals mass exploitation of this Zimbra Collaboration Suite RCE flaw — immediately determine if you run ZCS and apply the available patch; treat any internet-exposed Zimbra instance as potentially compromised pending verification.
- SOC/IR — Act: Widespread active exploitation means assume-breach posture for any Zimbra environment: audit Zimbra server logs and web directories for web shells or anomalous POST requests since the campaign began, even without specific published IOCs.
- Leader — Act: Confirmed mass compromise of enterprise email infrastructure warrants same-week action — verify whether your organization or key SaaS/hosting vendors run on-premises Zimbra and direct your security team to assess exposure immediately before this surfaces as a board-level question.
- Engineer — Act: CISA KEV-listed RCE (CVSS 9.8) with public PoC requires only repository write access to execute arbitrary shell commands — patch Gitea immediately and audit server process trees and outbound connections for miner-related IOCs.
- SOC/IR — Act: Active exploitation with miner-like payload delivery gives a clear detection angle — hunt for anomalous child processes spawned by the Gitea process, unusual outbound connections from CI/Git infrastructure, and unexpected CPU spikes on self-hosted Git servers since the CVE was published.
- Leader — Plan: If your organization runs self-hosted Gitea, confirm with engineering teams this week whether the patch has been applied; a compromised source code host is a supply-chain risk that may warrant customer notification depending on your disclosure obligations.
- Signals: CVE-2026-60004 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: If you run a self-hosted Gitea instance, patch to the fixed version immediately — CISA-confirmed active exploitation of a critical code injection flaw means your CI/CD pipeline and source repositories are at direct risk.
- SOC/IR — Act: Audit any Gitea instances in your estate for signs of code injection compromise dating back to initial disclosure; a compromised source-code host can stage supply-chain attacks that require assume-breach investigation of downstream build artifacts.
- Leader — Plan: Direct your teams to inventory self-hosted Gitea deployments and validate patch status; a code injection flaw in source-code infrastructure carries supply chain risk worth confirming is closed before it surfaces in a customer security questionnaire.
- Engineer — Act: CISA KEV listing with active exploitation means immediate action: patch Zimbra Collaboration Suite to the vendor-recommended version within the 3-day federal window, or sooner if possible.
- SOC/IR — Act: Active exploitation is confirmed; hunt for anomalous Zimbra activity (unusual logins, webshell artifacts, outbound connections from ZCS hosts) dating back at least 30 days and tune detections for ZCS-specific abuse patterns.
- Leader — Plan: If your org runs Zimbra, confirm patching is underway and verify no compromise occurred; if Zimbra is a vendor dependency, request their remediation attestation this week.
- Engineer — Act: Active exploitation confirmed by CERT Polska plus a public PoC on GitHub makes this urgent regardless of the low EPSS score. Patch Zimbra Collaboration (ZCS) to the fixed release immediately; prioritize any internet-facing Zimbra instances.
- SOC/IR — Act: Active in-the-wild exploitation of an email server RCE creates an assume-breach exposure window. Hunt Zimbra SNMP and application logs for anomalous command execution patterns since the PoC publication date, and pull any IOCs published by CERT Polska for sweeping.
- Leader — Skip
- Signals: CVE-2026-73570 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: Max-severity flaw in Microsoft Entra ID with confirmed active exploitation makes this immediate-action territory regardless of missing EPSS/KEV signals. Apply Microsoft’s Entra ID patch now and review sign-in and audit logs for anomalous authentication activity around and before the disclosure date.
- SOC/IR — Act: Active exploitation of an IAM platform means compromise may have already occurred in unpatched environments. Hunt for anomalous Entra ID authentication events (unexpected sign-ins, token grants, role assignments) and check whether Microsoft has published associated IOCs or TTPs to tune detections.
- Leader — Act: Entra ID underpins identity for the vast majority of enterprise environments, and confirmed active exploitation of a maximum-severity flaw is a board-question-level event. Confirm patching status with your engineering team this week and be ready to brief leadership before customers or auditors raise it.
- Engineer — Act: Microsoft has applied a server-side fix requiring no customer patch, but active exploitation occurred before remediation — audit Entra ID sign-in and audit logs for anomalous authentication, new service principals, or privilege escalation events from the period prior to the fix, and verify no credential or token abuse persists.
- SOC/IR — Act: Confirmed in-the-wild exploitation of an identity provider with a public PoC warrants an immediate hunt — query Entra ID audit and sign-in logs for suspicious app registrations, delegated permission grants, and admin role assignments occurring in the exploitation window, and tune detections for anomalous OAuth consent flows.
- Leader — Act: A CVSS 10.0 actively exploited RCE on the organization’s cloud identity plane is a board-level event analogous to Log4Shell in blast radius — brief leadership this week on the pre-patch exposure window and confirm with the security team that no evidence of compromise was found in Entra ID logs before Microsoft’s server-side fix landed.
- Signals: CVE-2026-69836 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Zimbra Collaboration Suite is common enterprise mail infrastructure; active exploitation confirmed by a national CERT means patch immediately — update ZCS to the vendor’s latest patched release and audit web-accessible Zimbra instances for signs of prior compromise.
- SOC/IR — Act: Active exploitation of a Zimbra RCE means assume-breach posture for orgs running it — sweep Zimbra servers for web shells, anomalous child processes from the mail service, and unusual outbound connections; pull CERT Polska’s advisory for any published IOCs to run against SIEM.
- Leader — Act: Zimbra hosts enterprise email, so a critical RCE under active attack is a data-exposure risk — confirm whether Zimbra is in your environment, and if so direct teams to treat patching as priority-one this week and assess whether any compromise warrants customer or regulatory notification.
- Engineer — Act: CISA confirmed active exploitation of this critical Windows IKE RCE — patch all Windows systems running IPsec/VPN services immediately; treat as emergency patch given KEV-level signal from CISA warning.
- SOC/IR — Act: Active exploitation confirmed by CISA — hunt for anomalous IKE/IPsec traffic and suspicious activity originating from VPN-adjacent or edge Windows systems since the campaign began; assume-breach sweep warranted for internet-exposed IKE endpoints.
- Leader — Plan: Confirm with infrastructure teams that Windows IPsec/VPN systems are prioritized in the current patch cycle; active exploitation elevates this above routine cadence but it falls short of board-level disclosure unless a breach is discovered.
- Engineer — Act: Four KEV-listed critical vulns across platforms you likely run — patch macOS (CVE-2026-65400, CVSS 9.8), SharePoint, vCenter, and Microsoft IKE immediately; a public PoC exists for the macOS flaw, making exploitation trivial.
- SOC/IR — Act: Active exploitation of vCenter and SharePoint warrants an assume-breach sweep — hunt for post-exploitation activity (credential dumping, lateral movement) on these systems dating back at least 30 days, and tune detections for anomalous SharePoint API calls and vCenter admin actions.
- Leader — Act: KEV-listed active exploitation across macOS endpoints, SharePoint, and vCenter is a systemic risk event — confirm patch status and exposure scope with engineering this week, and be prepared to brief leadership if any of these systems host sensitive data or are business-critical.
- Signals: CVE-2026-65400 — CISA KEV: listed, EPSS 0.00, public PoC on GitHub
- Engineer — Act: A max-severity RCE in SAP Commerce Cloud is under active attack just days after patching — apply the SAP patch immediately and audit Commerce Cloud logs for signs of pre-patch compromise.
- SOC/IR — Act: Active exploitation is confirmed by threat intelligence, so sweep SAP Commerce Cloud application and access logs for anomalous activity indicative of RCE or post-exploitation behavior since the patch release date.
- Leader — Act: Confirm whether your organization runs SAP Commerce Cloud and verify the emergency patch has been applied; if patching is delayed, request an incident status from the team given active exploitation is already underway.
- Engineer — Act: vCenter is core infrastructure for most enterprise estates and active exploitation is deploying persistent reverse SSH tunnels — patch CVE-2026-59310 immediately and audit vCenter hosts for unexpected outbound SSH connections or new SSH tunnel processes.
- SOC/IR — Act: The campaign’s TTP is specific and huntable: sweep for outbound SSH sessions originating from vCenter server hosts, flag any reverse tunnel tools (socat, plink, autossh) running on hypervisor management nodes since the vulnerability’s disclosure date.
- Leader — Plan: Active exploitation of a critical vCenter RCE means full-estate exposure for organizations running VMware — confirm with engineering this sprint that patching is complete and request a status update before this surfaces in a customer security questionnaire.
- Signals: CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: SharePoint CVSS 9.1 authentication bypass is now under active exploitation following public PoC release; apply Microsoft’s July 2026 Patch Tuesday update to all on-premises and hybrid SharePoint instances immediately and verify patch status in your estate.
- SOC/IR — Act: Active exploitation of a SharePoint auth bypass means adversaries may already be inside unpatched tenants; hunt for anomalous SharePoint authentication events and unexpected file access patterns in audit logs dating back to the PoC release.
- Leader — Act: SharePoint is ubiquitous in enterprise environments and this critical auth bypass is under active attack; confirm patch completion with engineering this week and assess whether any exposure window existed that could trigger customer notification obligations.
- Signals: CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
- Engineer — Act: Active exploitation attempts against CVE-2026-71362 in Adobe Commerce and Magento have been observed despite low EPSS — if you run either platform, patch immediately and audit recent customer authentication logs for signs of account takeover.
- SOC/IR — Plan: No IOCs or ATT&CK-mapped TTPs are available yet, but active exploitation is reported; build or tune detections for anomalous authentication patterns and privilege changes on Commerce/Magento instances in your estate.
- Leader — Plan: If your organization or a key e-commerce vendor runs Adobe Commerce or Magento, confirm patching status this week and assess whether customer account data may have been exposed, given the reported exploitation activity.
- Signals: CVE-2026-71362 — CISA KEV: not listed, EPSS 0.00, no public PoC found
- Engineer — Act: Cisco ASA and FTD are cornerstone edge appliances in most enterprise environments; active exploitation confirmed by the vendor makes this urgent — apply available patches or workarounds immediately and verify your ASA/FTD version is not in the affected range.
- SOC/IR — Act: Active exploitation of edge VPN appliances means you should hunt for unexpected device crashes or reboots on your ASA/FTD fleet and monitor for anomalous inbound traffic targeting VPN endpoints consistent with DoS attempts since the disclosure date.
- Leader — Plan: A DoS against widely deployed VPN appliances carries real business-continuity risk; confirm your team is treating patching as priority-one this week and identify contingency plans (backup access paths) if appliances are targeted before patches are applied.
- Engineer — Act: vCenter is core infrastructure and a CVSS 9.8 directory-traversal-to-RCE with reported active exploitation warrants immediate patching despite weak enrichment signals (not KEV, EPSS 0.01). Apply Broadcom’s patch for CVE-2026-59310 and audit vCenter network access controls to reduce exposure while rolling out.
- SOC/IR — Plan: Active exploitation is reported by a single vendor (QUIRSO) but no IOCs or ATT&CK-mapped TTPs are published yet, leaving no sweep surface today. Build or tune detections for post-exploitation behavior originating from vCenter hosts (unusual process spawning, outbound connections from vCenter management IPs) in anticipation of broader disclosure.
- Leader — Plan: A 9.8-severity RCE in widely deployed VMware vCenter with reported exploitation is worth a prompt check-in with the engineering team to confirm patch status, but the single-source report and absence of a KEV listing mean this does not yet require board escalation or a customer-facing statement.
- Signals: CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, no public PoC found
- Engineer — Act: CISA KEV-listed, EPSS 0.99, public PoC, and 792 confirmed exploit attempts make this an emergency patch. Apply the Progress Kemp LoadMaster patch immediately or isolate the appliance from untrusted networks until patched.
- SOC/IR — Act: Active exploitation of a perimeter load balancer warrants an assume-breach sweep — hunt for command injection patterns in LoadMaster access logs since the first reported attempts, and check downstream hosts for lateral movement indicators.
- Leader — Act: CISA KEV listing plus confirmed active exploitation makes this a board-question-level appliance vulnerability; confirm this week whether LoadMaster is in your environment and verify engineering has patched or isolated affected instances.
- Signals: CVE-2026-8037 — CISA KEV: listed, EPSS 0.99, public PoC on GitHub
- Engineer — Act: Active exploitation of N-central is confirmed, with attackers persisting on managed endpoints — a full-estate compromise risk. Apply N-central Hotfix 2 immediately and audit N-central activity logs for unauthorized sessions or lateral movement to managed systems.
- SOC/IR — Act: Attackers are persisting on N-central-managed systems, meaning compromise may predate the patch. Hunt for anomalous RMM-initiated process execution or new scheduled tasks/services on managed endpoints since the original vulnerability disclosure, and look for unexpected outbound connections from N-central infrastructure.
- Leader — Act: RMM compromise is a systemic risk — if your MSP or internal team runs N-central, attackers may already have access to managed endpoints. Confirm Hotfix 2 deployment status with your MSP or internal team this week and request attestation of any anomalous access findings.
- Engineer — Act: Actively exploited zero-day in Metabase with a 10.0 CVSS allows unauthenticated SQL injection leading to full admin takeover — apply the vendor patch immediately or take any internet-exposed Metabase instance offline until patched.
- SOC/IR — Act: Confirmed in-the-wild exploitation means assume-breach posture for any Metabase instance in your estate: hunt for unauthorized admin logins and anomalous SQL activity in application logs since the disclosure date, and sweep for lateral movement from those hosts.
- Leader — Act: Confirm whether the organization runs Metabase — BI tools commonly hold access to sensitive operational data, and a CVSS 10.0 actively exploited vulnerability elevates this to a same-week check; if exposed, brief leadership on potential data access risk and request remediation status from the engineering team.
- Engineer — Act: All three products are KEV-listed with confirmed active exploitation and a 72-hour federal patch deadline — check your inventory for Langflow, N-able N-central, and Apache Tomcat instances and apply vendor patches immediately, prioritizing any internet-exposed deployments.
- SOC/IR — Act: Actively exploited RMM (N-central) and Java servlet (Tomcat) instances are high-value footholds; hunt for web shells on Tomcat endpoints and audit N-central for unauthorized agent activity or lateral-movement artifacts since the CISA advisory date.
- Leader — Plan: Confirm with engineering whether the organization runs Langflow, N-able N-central, or Apache Tomcat and ensure the patch sprint is underway; the federal 3-day deadline signals regulator attention and may surface in upcoming audit or customer questionnaire conversations.
- Engineer — Act: CVE-2026-18577 is CISA KEV-listed with a public PoC and confirmed active exploitation — patch N-central immediately to the vendor-specified fixed version, and audit logs for unauthorized access since the vulnerability affects both hosted and on-premises deployments.
- SOC/IR — Act: Active exploitation of N-central means assume-breach posture for any org running it — sweep for anomalous authentication events on N-central servers and hunt for lateral movement originating from managed endpoints, as compromise of an RMM tool gives attackers broad access to managed devices.
- Leader — Act: N-central is an RMM platform used by MSPs; if your organization or any MSP managing your environment runs it, request an immediate attestation of patch status and review whether threat actors could have used it as a pivot into your estate — this is the type of systemic MSP-chain risk worth a brief to leadership this week.
- Signals: CVE-2026-18577 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: CVE-2026-18577 is CISA KEV-listed with a public PoC and confirmed in-the-wild exploitation; if you run N-able N-central, apply the latest patch immediately and treat any N-central host as potentially compromised pending verification.
- SOC/IR — Act: Confirmed customer compromises via an RMM platform mean privileged agent access may already be weaponized; hunt for anomalous lateral movement or command execution originating from N-central agents since the disclosure date and sweep admin audit logs for unauthorized access.
- Leader — Act: RMM platforms have privileged access across entire client estates — if your organization uses an MSP that runs N-able N-central, this week confirm whether they are patched and request a written attestation, as confirmed customer compromises indicate active supply-chain risk through managed-service relationships.
- Signals: CVE-2026-18556 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub · CVE-2026-18577 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: Active exploitation is confirmed and a public PoC exists; patch N-central to build 2026.3.1.7 immediately, then audit server and managed-endpoint logs for unauthorized admin sessions or lateral movement originating from N-central.
- SOC/IR — Act: Compromised N-central servers give attackers a pivot into every managed customer environment; hunt for anomalous RMM-originated connections and unexpected privileged actions on managed endpoints, sweeping back to at least early August 2026.
- Leader — Act: If your organization runs N-central or relies on an MSP that does, confirm patch status and request a compromise-assessment attestation this week — an RMM breach exposes all downstream managed environments and may carry disclosure obligations.
- Signals: CVE-2026-18577 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Fastjson 1.x is embedded in many Spring Boot applications; unauthenticated RCE with a public PoC and confirmed active attacks means immediate action is required — audit all services for Fastjson 1.x dependencies, apply WAF rules to block the malicious JSON chain, and isolate or rate-limit exposed endpoints until a patch is available.
- SOC/IR — Act: Multi-source confirmation of active exploitation gives a detection mandate now — hunt for anomalous JSON deserialization patterns in HTTP request logs to Spring Boot services and monitor for unexpected outbound connections or process spawning from Java app servers since the earliest confirmed attack date.
- Leader — Plan: A critical, unpatched RCE in a widely-used Java library under active attack warrants commissioning an urgent Fastjson 1.x exposure inventory across development teams this week; if use is confirmed, allocate engineering time for compensating controls and track remediation until a vendor patch is released.
- Signals: CVE-2026-16723 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
- Engineer — Act: Active Cl0p data-extortion campaign exploiting internet-exposed PTC Windchill and FlexPLM via chained pre-auth flaws; immediately audit for internet-exposed instances, apply available patches, and if patching is delayed, restrict Windchill login servlet and FlexPLM WSDL endpoint from external access.
- SOC/IR — Act: Active Cl0p campaign with a concrete exploit chain (pre-auth FlexPLM WSDL disclosure chained into Windchill login servlet); hunt for anomalous pre-authenticated requests to these endpoints since campaign start and sweep for Cl0p-associated IOCs in PLM server logs and EDR telemetry.
- Leader — Plan: Cl0p affiliates are running a targeted data-extortion campaign against manufacturing and engineering organizations using PTC Windchill/FlexPLM; if your org or key suppliers use these platforms, assess exposure now and be prepared to brief leadership on potential data theft risk before it surfaces in the press.
- Engineer — Act: Active in-the-wild exploitation confirmed by VulnCheck and a public PoC is available; if you self-host Windmill, patch immediately and audit web server logs for unauthenticated requests to the
/api/w/{workspace}/jobs_u/get_log_file/endpoint containing traversal sequences. - SOC/IR — Act: Active exploitation with public PoC means opportunistic scanning is already underway; hunt web proxy and WAF logs for path traversal patterns (e.g.,
../) in requests to Windmill’sget_log_fileendpoint, and sweep for unusual file reads on any Windmill hosts since the PoC dropped. - Leader — Skip
- Signals: CVE-2026-29059 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub
- Engineer — Act: Active exploitation confirmed with a public GitHub PoC; patch SharePoint immediately AND regenerate machine keys — patching alone does not evict attackers who already exfiltrated them, so key rotation is the critical second step.
- SOC/IR — Act: Stolen machine keys enable persistent, post-patch impersonation attacks — hunt SharePoint IIS logs for exploitation artifacts since the vulnerability became public, and write detections for anomalous ViewState or token-forging activity tied to mismatched machine keys.
- Leader — Plan: Confirm SharePoint is in scope, then ensure your engineering team understands that patching alone is insufficient — key rotation and a post-exploitation sweep are required; flag this as a two-step remediation so it isn’t closed prematurely in the ticket queue.
- Signals: CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: CVSS 9.8 deserialization RCE with public PoC and confirmed active exploitation — patch SharePoint Server to the July 2026 Patch Tuesday build immediately; do not wait for CISA KEV confirmation given exploitation is already underway.
- SOC/IR — Act: Active exploitation predating your patch window means assume-breach posture is warranted — hunt for anomalous deserialization or code execution activity on SharePoint servers back to at least the PoC publication date, and review watchTowr’s reporting for any available IOCs or behavioral signatures.
- Leader — Act: A CVSS 9.8 unauthenticated RCE in widely-deployed enterprise SharePoint under active exploitation requires a same-week exposure check — confirm whether the org runs on-premises SharePoint Server and verify the engineering team has prioritized the July Patch Tuesday update.
- Signals: CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: Both CVEs have public PoCs and exploitation is already underway with mass scanning — patch all WordPress instances to the fixed versions immediately and audit exposed sites for webshell artifacts, especially any unexpected PHP files or modified themes.
- SOC/IR — Act: Active exploitation confirmed since early Saturday UTC; hunt for webshell uploads and anomalous POST requests targeting WordPress endpoints across your estate, and sweep for post-compromise persistence on any internet-facing WordPress hosts.
- Leader — Plan: Active exploitation with mass scanning is in progress but hasn’t reached Log4Shell-scale board attention yet; confirm whether WordPress appears in your web portfolio and ensure it’s on your engineering team’s immediate patching queue this week.
- Signals: CVE-2026-60137 — CISA KEV: not listed, EPSS 0.04, public PoC on GitHub · CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: Public PoC exists and in-the-wild exploitation is reported for this unauthenticated sandbox-escape RCE (CVSS 9.5) in the ServiceNow AI Platform. Confirm your ServiceNow instance has the available patch applied via the admin console, and audit platform logs for anomalous code execution since the disclosure date.
- SOC/IR — Act: Active exploitation of unauthenticated RCE on a widely deployed enterprise ITSM platform creates immediate detection work. Hunt for anomalous outbound connections, unusual process spawning, or lateral movement originating from ServiceNow infrastructure since the vulnerability was disclosed, and tune EDR/SIEM for post-exploitation behavior on hosts that ServiceNow agents touch.
- Leader — Act: A critical unauthenticated RCE in ServiceNow with confirmed in-the-wild exploitation could expose ITSM data and integrated systems. This week, confirm with your ServiceNow admin that the patch is applied to your instance and assess whether any sensitive data (HR, IT credentials, integrations) in the platform warrants a precautionary leadership or customer notification.
- Signals: CVE-2026-6875 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: CISA KEV listing with active exploitation means patch FortiSandbox to the vendor-fixed version immediately — treat this as a critical-priority change with a days-level window, not weeks.
- SOC/IR — Act: Active exploitation of FortiSandbox warrants an assume-breach sweep on any FortiSandbox instances in the estate; hunt for anomalous outbound connections or config changes on those appliances since the vulnerability window opened.
- Leader — Act: Confirm whether FortiSandbox is deployed anywhere in your environment, verify the patching timeline with your engineering team, and be prepared to brief leadership if you are a federal agency facing CISA’s Sunday deadline.
- Engineer — Act: CISA KEV listing with confirmed active exploitation and an imminent Saturday deadline; audit your environment for Oracle E-Business Suite deployments and apply Oracle’s patch immediately.
- SOC/IR — Act: Active exploitation is underway against Oracle EBS financial systems; initiate a hunt for anomalous EBS access patterns and monitor threat intel feeds for IOCs to sweep across relevant log sources.
- Leader — Act: A CISA-mandated Saturday deadline on actively exploited financial software warrants same-week confirmation from your engineering team that Oracle E-Business Suite is either patched or absent from your environment.
- Engineer — Act: CISA warning indicates KEV-level active exploitation against internet-exposed on-premises SharePoint Server. Apply Microsoft’s patches immediately and verify no externally reachable SharePoint instances remain unpatched.
- SOC/IR — Act: Active exploitation of internet-facing SharePoint means assume-breach posture is warranted; hunt for post-exploitation activity (lateral movement, credential access) on SharePoint hosts since the earliest known exploitation date and review IIS/ULS logs for anomalous request patterns.
- Leader — Act: Confirm whether the organization runs on-premises SharePoint Server exposed to the internet, and get a patching status update from engineering this week — active exploitation with a CISA advisory is the kind of event that surfaces in board or customer security reviews.
- Engineer — Act: CISA warning signals KEV-level active exploitation — update or disable the iCagenda and Balbooa Forms Joomla extensions immediately, and audit web roots for unexpectedly uploaded files that may indicate prior compromise.
- SOC/IR — Act: Active exploitation via arbitrary file upload means webshells may already be in place — hunt Joomla web directories for recently uploaded executables and review web server logs for POST requests targeting these extension upload endpoints.
- Leader — Plan: Confirm whether any company-owned or vendor-hosted web properties run Joomla with these extensions and verify engineering teams have patch SLAs in motion; this does not yet rise to board-briefing level.
- Engineer — Act: GoAnywhere MFT is a common enterprise managed-file-transfer appliance; CISA KEV listing plus EPSS 1.00 plus a public GitHub PoC means exploitation is active now. Patch to the vendor-fixed release immediately or take the instance offline until patching is complete.
- SOC/IR — Act: Prior GoAnywhere exploitation by Cl0p hit hundreds of organizations; treat any unpatched instance as potentially compromised. Hunt for anomalous outbound transfers, newly created admin accounts, and lateral movement originating from GoAnywhere servers since the PoC became public.
- Leader — Act: The 2023 Cl0p GoAnywhere campaign was a marquee supply-chain breach; this CVE matches or exceeds that severity signal (EPSS 1.00, KEV-listed). Confirm this week whether your org or critical MFT vendors run GoAnywhere and obtain patch attestations before history repeats.
- Signals: CVE-2025-10035 — CISA KEV: listed, EPSS 1.00, public PoC on GitHub