tag: Rce · 69 items
- Engineer — Act: If you run Sangoma Switchvox SMB Edition 8.3, patch immediately — a public PoC exists and active exploitation is reported. Restrict network access to the Switchvox admin interface as an interim control while a patch is applied.
- SOC/IR — Act: Active exploitation is deploying reverse shells from VoIP infrastructure; hunt for anomalous outbound connections originating from Switchvox hosts and sweep network logs for unexpected C2 traffic since the PoC went public.
- Leader — Skip
- Signals: CVE-2026-9586 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: Actively exploited RCE zero-days on an edge appliance demand immediate response: apply SonicWall’s emergency mitigations or patches as soon as available, and treat any internet-exposed SMA1000 as potentially compromised pending confirmation.
- SOC/IR — Act: Active exploitation of an edge SSL VPN device means compromise may predate any patch; sweep SMA1000 appliances for anomalous outbound connections and lateral movement indicators from the appliance’s IP, and initiate assume-breach review of adjacent segments.
- Leader — Act: If SonicWall SMA1000 is in the estate, confirm remediation is underway this week and request a vendor statement on exposure scope; actively exploited RCE on a remote-access gateway is the kind of incident that surfaces in board and customer conversations.
- Engineer — Plan: If you run GeoNetwork, upgrade to 4.4.12 (4.x branch) or 4.2.17 (4.2 branch) — the chained unauthenticated RCE is severe but no KEV listing, public PoC, or active exploitation is reported, so patch this sprint rather than emergency-tonight.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: Active exploitation of an unauthenticated RCE in Langflow (public PoC available) is being used to exfiltrate API keys and cloud credentials. Patch Langflow to the latest fixed release immediately, rotate any OpenAI and AWS keys accessible from Langflow instances, and review Langflow access logs for signs of unauthorized execution.
- SOC/IR — Act: Confirmed active exploitation with credential theft as the objective creates a detection and hunt opportunity now. Identify any Langflow instances in the environment, hunt for anomalous outbound requests or process spawning from those hosts, and monitor for unusual OpenAI or AWS API activity that could indicate stolen key use.
- Leader — Plan: If AI application development is underway internally, Langflow may be present in engineer pipelines — AWS key theft from a development tool is a material cloud-spend and data-exposure risk. Direct engineering teams this week to audit Langflow deployments and confirm no keys were exposed.
- Signals: CVE-2026-0768 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub, reported by 2 collected sources
- Engineer — Learn: CVE-2021-31886 is a 2021 vulnerability with EPSS 0.03 and no KEV listing — exploitation pressure is low. WAGO PLCs are niche OT hardware outside most cloud/AppSec stacks, but the research technique (AI-accelerated exploit porting to embedded ARM targets) is worth understanding if you maintain any OT/ICS-adjacent environments.
- SOC/IR — Learn: No IOCs, no active campaign, and no new detection surface are introduced by this research. The demonstrated method of using LLMs to port PLC exploits is context worth knowing for OT-adjacent threat hunting, but there is nothing actionable to write rules or run sweeps against today.
- Leader — Learn: This research is a concrete signal that AI tooling is meaningfully lowering the barrier for porting ICS/OT exploits — relevant if you have OT exposure on your risk register or are shaping a position on AI in offensive security for a board or customer briefing.
- Signals: CVE-2021-31886 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub
- Engineer — Act: CVE-2026-0768 in Langflow is a CVSS 9.8 RCE running as root with a public PoC and confirmed active exploitation — patch or take Langflow offline immediately; also audit Rails deployments for CVE-2026-66066 exposure and apply the latest Rails patch given the 0.28 EPSS and available PoC.
- SOC/IR — Act: Active exploitation includes credential-probing and C2 callback activity — hunt for anomalous outbound connections and lateral movement originating from Langflow or Rails app servers since these flaws became public, and build detections for post-exploitation behavior on those hosts.
- Leader — Skip
- Signals: CVE-2026-0768 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub · CVE-2026-66066 — CISA KEV: not listed, EPSS 0.28, public PoC on GitHub
- Engineer — Act: CVSS 9.8 authentication bypass and RCE affecting commonly deployed plugins (Avada, GiveWP, TranslatePress, Pods, WPMU DEV Dashboard), with a public PoC already on GitHub; patch all five to their latest patched releases before the PoC accelerates exploitation.
- SOC/IR — Plan: No active exploitation confirmed (EPSS 0.00, not on KEV), but the public PoC shortens the window; build or tune detections for anomalous WordPress admin account creation and unauthenticated POST requests targeting these plugin endpoints this sprint.
- Leader — Skip
- Signals: CVE-2026-76581 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
- Engineer — Plan: If your environment uses Unitree G1 EDU robots, review network segmentation and disable unnecessary BLE/network services; no KEV listing and near-zero EPSS suggest limited active exploitation pressure, but public PoCs exist so schedule patching.
- SOC/IR — Skip
- Leader — Skip
- Signals: CVE-2026-76639 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub · CVE-2026-76640 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
- Engineer — Plan: Three unauthenticated RCE/SQLi flaws at maximum severity demand prompt action, but no KEV listing or public PoC elevates this to Act yet. If running self-hosted ServiceNow, apply the patch this week and verify hosted instances received the automated update.
- SOC/IR — Skip
- Leader — Plan: Three CVSS 10.0 flaws in a widely deployed ITSM platform warrant confirming whether your organization runs self-hosted ServiceNow and ensuring the patch was applied; hosted tenants should receive confirmation from ServiceNow that their instances were updated.
- Engineer — Plan: Maximum-severity unauthenticated RCE in GiveWP is serious, but no KEV listing, public PoC, or active exploitation is confirmed in the signals; update GiveWP to the patched version this sprint and audit any WordPress instances running it.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: A public PoC exists for a root-level RCE in cPanel and WHM affecting all supported versions — update cPanel/WHM to the patched release immediately and verify no unauthorized access occurred on any exposed panels.
- SOC/IR — Plan: With a public PoC now available, write or enable detections for anomalous root-process spawning from cPanel/WHM processes and unusual web requests to the cPanel/WHM management interfaces before exploitation campaigns begin.
- Leader — Skip
- Signals: CVE-2026-65643 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Public PoC on GitHub for unauthenticated RCE in a ubiquitous web framework clears the bar for immediate action — upgrade Next.js to the patched release now, prioritizing any Windows-hosted deployments and any apps accepting untrusted image uploads.
- SOC/IR — Plan: With a public PoC and no KEV listing yet, build detections for suspicious AVIF uploads and Windows-style path traversal sequences (e.g. ..) in HTTP requests targeting Next.js routes before active exploitation begins.
- Leader — Plan: Two critical unauthenticated RCE flaws with public PoC in a widely-deployed framework warrant confirming this quarter that your engineering teams have inventoried Next.js usage and applied patches — flag for a status check if any customer-facing apps are affected.
- Signals: CVE-2026-75604 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Plan: Avada is among the most widely deployed commercial WordPress themes, and unauthenticated PHP code execution is a maximum-severity primitive — update Avada to the patched release this sprint. No KEV listing or public PoC is confirmed yet, so this is urgent but not emergency-weekend work.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: CISA KEV listing with active exploitation across NetScaler ADC/Gateway, Linux, and SQL Server — all plausible in enterprise environments; patch affected NetScaler and SQL Server instances immediately and verify Linux kernel versions against the KEV entries.
- SOC/IR — Act: NetScaler edge devices are a prime assume-breach target when exploitation precedes patching; hunt for post-exploitation activity on NetScaler appliances and any lateral movement from SQL Server hosts since these vulnerabilities entered active exploitation.
- Leader — Plan: Six KEV additions spanning widely-deployed infrastructure signal a broad active-exploitation wave; confirm your engineering teams are tracking patch timelines for NetScaler, Linux, and SQL Server against CISA’s binding operational directive deadlines.
- Signals: CVE-2019-1068 — CISA KEV: listed, EPSS 0.53, public PoC on GitHub
- Engineer — Act: Citrix NetScaler is a common edge appliance; active exploitation of an RCE with a CISA KEV order makes this immediate. Identify all NetScaler instances in your environment and apply the vendor patch now — Saturday deadline applies to federal agencies but exploitation is not sector-limited.
- SOC/IR — Act: Active exploitation of an edge RCE means attackers may already be inside before patching occurs; initiate an assume-breach sweep on NetScaler appliances, reviewing management-plane logs and lateral movement indicators since the vulnerability became public.
- Leader — Act: CISA’s mandatory patch order with a Saturday deadline signals systemic exploitation — confirm whether your organization runs Citrix NetScaler, verify remediation is in progress, and brief leadership if you operate federal systems or customer-facing NetScaler infrastructure.
- Engineer — Act: Over 270 confirmed compromises signals mass exploitation of this Zimbra Collaboration Suite RCE flaw — immediately determine if you run ZCS and apply the available patch; treat any internet-exposed Zimbra instance as potentially compromised pending verification.
- SOC/IR — Act: Widespread active exploitation means assume-breach posture for any Zimbra environment: audit Zimbra server logs and web directories for web shells or anomalous POST requests since the campaign began, even without specific published IOCs.
- Leader — Act: Confirmed mass compromise of enterprise email infrastructure warrants same-week action — verify whether your organization or key SaaS/hosting vendors run on-premises Zimbra and direct your security team to assess exposure immediately before this surfaces as a board-level question.
- Engineer — Act: CISA KEV-listed RCE (CVSS 9.8) with public PoC requires only repository write access to execute arbitrary shell commands — patch Gitea immediately and audit server process trees and outbound connections for miner-related IOCs.
- SOC/IR — Act: Active exploitation with miner-like payload delivery gives a clear detection angle — hunt for anomalous child processes spawned by the Gitea process, unusual outbound connections from CI/Git infrastructure, and unexpected CPU spikes on self-hosted Git servers since the CVE was published.
- Leader — Plan: If your organization runs self-hosted Gitea, confirm with engineering teams this week whether the patch has been applied; a compromised source code host is a supply-chain risk that may warrant customer notification depending on your disclosure obligations.
- Signals: CVE-2026-60004 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Active exploitation confirmed by CERT Polska plus a public PoC on GitHub makes this urgent regardless of the low EPSS score. Patch Zimbra Collaboration (ZCS) to the fixed release immediately; prioritize any internet-facing Zimbra instances.
- SOC/IR — Act: Active in-the-wild exploitation of an email server RCE creates an assume-breach exposure window. Hunt Zimbra SNMP and application logs for anomalous command execution patterns since the PoC publication date, and pull any IOCs published by CERT Polska for sweeping.
- Leader — Skip
- Signals: CVE-2026-73570 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Learn: Gogs 10.0 RCE and n8n workflow-to-RCE are worth tracking if you run either tool, but no enrichment signals (no KEV, PoC, or EPSS) are present and the summary is too thin to drive patching prioritization; read the underlying advisories directly for specifics.
- SOC/IR — Learn: The roundup references signed-driver abuse against defenses (BYOVD pattern) and legitimate-app blending techniques, but supplies no IOCs, ATT&CK mappings, or detection guidance — useful for threat-landscape awareness only.
- Leader — Skip
- Engineer — Act: Microsoft has applied a server-side fix requiring no customer patch, but active exploitation occurred before remediation — audit Entra ID sign-in and audit logs for anomalous authentication, new service principals, or privilege escalation events from the period prior to the fix, and verify no credential or token abuse persists.
- SOC/IR — Act: Confirmed in-the-wild exploitation of an identity provider with a public PoC warrants an immediate hunt — query Entra ID audit and sign-in logs for suspicious app registrations, delegated permission grants, and admin role assignments occurring in the exploitation window, and tune detections for anomalous OAuth consent flows.
- Leader — Act: A CVSS 10.0 actively exploited RCE on the organization’s cloud identity plane is a board-level event analogous to Log4Shell in blast radius — brief leadership this week on the pre-patch exposure window and confirm with the security team that no evidence of compromise was found in Entra ID logs before Microsoft’s server-side fix landed.
- Signals: CVE-2026-69836 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Plan: Any Node.js service using isolated-vm to run untrusted code (plugins, user-submitted scripts, multi-tenant eval) is exposed to host RCE; no public PoC or KEV listing yet, but the impact ceiling is high — audit your dependency tree and upgrade isolated-vm to a version above 7.0.0 this sprint.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Plan: Update Elementor Pro to the patched version immediately; no active exploitation or PoC confirmed in signals, but RCE via file upload on a widely-deployed WordPress plugin warrants prompt patching within your normal critical window.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: Zimbra Collaboration Suite is common enterprise mail infrastructure; active exploitation confirmed by a national CERT means patch immediately — update ZCS to the vendor’s latest patched release and audit web-accessible Zimbra instances for signs of prior compromise.
- SOC/IR — Act: Active exploitation of a Zimbra RCE means assume-breach posture for orgs running it — sweep Zimbra servers for web shells, anomalous child processes from the mail service, and unusual outbound connections; pull CERT Polska’s advisory for any published IOCs to run against SIEM.
- Leader — Act: Zimbra hosts enterprise email, so a critical RCE under active attack is a data-exposure risk — confirm whether Zimbra is in your environment, and if so direct teams to treat patching as priority-one this week and assess whether any compromise warrants customer or regulatory notification.
- Engineer — Act: CISA confirmed active exploitation of this critical Windows IKE RCE — patch all Windows systems running IPsec/VPN services immediately; treat as emergency patch given KEV-level signal from CISA warning.
- SOC/IR — Act: Active exploitation confirmed by CISA — hunt for anomalous IKE/IPsec traffic and suspicious activity originating from VPN-adjacent or edge Windows systems since the campaign began; assume-breach sweep warranted for internet-exposed IKE endpoints.
- Leader — Plan: Confirm with infrastructure teams that Windows IPsec/VPN systems are prioritized in the current patch cycle; active exploitation elevates this above routine cadence but it falls short of board-level disclosure unless a breach is discovered.
- Engineer — Act: A public PoC exists for this unauthenticated file upload RCE (CVSS 9.8) affecting 600,000+ WordPress installs; update Forminator Forms to the patched version immediately and verify no malicious PHP files were uploaded to wp-content directories.
- SOC/IR — Plan: With a public PoC available, exploitation attempts are likely imminent; build or tune WAF/SIEM rules to detect unauthenticated multipart file upload requests to Forminator endpoints and alert on unexpected PHP file creation under wp-content.
- Leader — Skip
- Signals: CVE-2026-15748 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: CISA KEV listing confirms active exploitation of a critical RCE in Ray, a widely-used Python distributed computing framework for AI/ML workloads; patch Ray immediately and, if patching is delayed, restrict external access to Ray dashboard and cluster endpoints.
- SOC/IR — Act: Active exploitation confirmed via KEV; hunt for unauthorized code execution originating from Ray cluster nodes and sweep for internet-exposed Ray dashboards in your environment, prioritizing ML infrastructure that may not be covered by standard EDR.
- Leader — Plan: If your organization runs AI/ML workloads, ask engineering to confirm whether Ray is deployed and to report patch status; KEV listing makes this likely to surface in auditor or customer questionnaires about your ML infrastructure security posture.
- Engineer — Act: A max-severity RCE in SAP Commerce Cloud is under active attack just days after patching — apply the SAP patch immediately and audit Commerce Cloud logs for signs of pre-patch compromise.
- SOC/IR — Act: Active exploitation is confirmed by threat intelligence, so sweep SAP Commerce Cloud application and access logs for anomalous activity indicative of RCE or post-exploitation behavior since the patch release date.
- Leader — Act: Confirm whether your organization runs SAP Commerce Cloud and verify the emergency patch has been applied; if patching is delayed, request an incident status from the team given active exploitation is already underway.
- Engineer — Act: vCenter is core infrastructure for most enterprise estates and active exploitation is deploying persistent reverse SSH tunnels — patch CVE-2026-59310 immediately and audit vCenter hosts for unexpected outbound SSH connections or new SSH tunnel processes.
- SOC/IR — Act: The campaign’s TTP is specific and huntable: sweep for outbound SSH sessions originating from vCenter server hosts, flag any reverse tunnel tools (socat, plink, autossh) running on hypervisor management nodes since the vulnerability’s disclosure date.
- Leader — Plan: Active exploitation of a critical vCenter RCE means full-estate exposure for organizations running VMware — confirm with engineering this sprint that patching is complete and request a status update before this surfaces in a customer security questionnaire.
- Signals: CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: Public PoC on GitHub for a CVSS 10.0 unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter makes exploitation practical now; apply SAP’s patch for CVE-2026-58231 immediately and verify no unauthorized access to the Data Hub Adapter endpoint prior to patching.
- SOC/IR — Act: With a public PoC available for unauthenticated RCE, sweep web access logs for anomalous requests to SAP Commerce Cloud Data Hub Adapter endpoints and hunt for post-exploitation activity (unusual process spawns, lateral movement) on Commerce Cloud hosts since the disclosure date.
- Leader — Act: Confirm whether your organization runs SAP Commerce Cloud and, if so, verify the engineering team has emergency-patched CVE-2026-58231; a public PoC for a max-severity unauthenticated RCE on an e-commerce platform warrants a same-week status check and potential customer notification if the platform handles transaction data.
- Signals: CVE-2026-58231 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Public PoC on GitHub for a CVSS 9.1 unauthenticated RCE across SharePoint Server Subscription Edition, 2019, and 2016 means exploitation risk is immediate even without KEV listing; apply Microsoft’s patch for CVE-2026-55040 across all affected on-prem SharePoint instances this week.
- SOC/IR — Plan: No confirmed in-the-wild exploitation yet (EPSS 0.02, no KEV), but a public PoC for unauthenticated RCE warrants building SharePoint-specific detections now — hunt for anomalous unauthenticated requests to SharePoint REST/SOAP endpoints and tune alerts on privilege escalation patterns in SharePoint audit logs before active campaigns emerge.
- Leader — Plan: A CVSS 9.1 unauthenticated RCE with public PoC against widely deployed SharePoint Server warrants confirming on-prem SharePoint scope with your team and ensuring patch prioritization this sprint — escalate to Act if exploitation is observed in the wild.
- Signals: CVE-2026-55040 — CISA KEV: not listed, EPSS 0.02, public PoC on GitHub
- Engineer — Act: vCenter is core infrastructure and a CVSS 9.8 directory-traversal-to-RCE with reported active exploitation warrants immediate patching despite weak enrichment signals (not KEV, EPSS 0.01). Apply Broadcom’s patch for CVE-2026-59310 and audit vCenter network access controls to reduce exposure while rolling out.
- SOC/IR — Plan: Active exploitation is reported by a single vendor (QUIRSO) but no IOCs or ATT&CK-mapped TTPs are published yet, leaving no sweep surface today. Build or tune detections for post-exploitation behavior originating from vCenter hosts (unusual process spawning, outbound connections from vCenter management IPs) in anticipation of broader disclosure.
- Leader — Plan: A 9.8-severity RCE in widely deployed VMware vCenter with reported exploitation is worth a prompt check-in with the engineering team to confirm patch status, but the single-source report and absence of a KEV listing mean this does not yet require board escalation or a customer-facing statement.
- Signals: CVE-2026-59310 — CISA KEV: not listed, EPSS 0.01, no public PoC found
- Engineer — Act: Public PoC exists on GitHub for a flaw affecting every WordPress version; update WordPress core to the patched release immediately, as the chain to server-side PHP execution is demonstrated even though it requires an admin to visit an attacker page.
- SOC/IR — Plan: With a public PoC but EPSS of 0.01 and no KEV listing, active exploitation is not yet confirmed; build or tune a detection for anomalous reflected XSS patterns hitting the WordPress login endpoint and alert on unexpected admin-session activity following external link clicks.
- Leader — Skip
- Signals: CVE-2026-64638 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Plan: If your team runs Paperclip for AI agent orchestration, two unpatched RCE paths via malicious agent imports are real exposure; check for a patched release and restrict which agent sources are trusted in your control plane.
- SOC/IR — Learn: The malicious-agent-import-to-RCE attack pattern is an emerging TTP as AI orchestration tooling spreads in dev environments — no IOCs or active exploitation to hunt for now, but worth building familiarity with the attack surface.
- Leader — Skip
- Engineer — Act: Patch on-premise JetBrains TeamCity to the fixed version immediately — CISA KEV listing confirms active exploitation, a public PoC is on GitHub, and the unauthenticated deserialization flaw carries a 9.8 CVSS score. Also audit TeamCity for unauthorized admin accounts or altered build configurations.
- SOC/IR — Act: TeamCity servers are pre-authentication targets; assume-breach sweep is warranted — hunt for anomalous build jobs, new admin accounts, or outbound connections from CI/CD hosts since patch disclosure. Map exploitation behavior to ATT&CK T1190 (Exploit Public-Facing Application) and tune EDR/SIEM rules for post-exploitation on build agents.
- Leader — Act: On-premise TeamCity RCE under active exploitation carries supply-chain risk comparable to prior CI/CD incidents — confirm this quarter whether your organization runs on-premise TeamCity instances and verify patch status with engineering before end of week.
- Signals: CVE-2026-63077 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
- Engineer — Plan: If you run TP-Link Omada for network management, schedule patching of the ZTP component this sprint — 15 chainable vulns with RCE potential are high severity, though no KEV listing or public PoC currently raises the urgency to emergency status.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2026-9198 in Langflow is a CVSS 9.8 unauthenticated RCE with a public PoC — patch Langflow, Apache Tomcat, and N-central to current vendor-recommended versions immediately, prioritizing any internet-exposed instances.
- SOC/IR — Act: Active exploitation of Langflow (unauthenticated RCE) and Tomcat creates immediate hunt obligations — sweep logs for exploitation attempts against these services since August 5, check for post-exploitation indicators (new processes, outbound connections) on hosts running any of the three products.
- Leader — Plan: Three simultaneous KEV additions including a critical AI-workflow tool (Langflow) warrant confirming your team’s KEV remediation SLA is on track and verifying whether N-central (an RMM platform) is in scope — RMM compromise can enable broad lateral movement across managed endpoints.
- Signals: CVE-2026-9198 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub
- Engineer — Plan: Active Storage is a core Rails component widely used for file handling, so any Rails-backed app is likely exposed; no public PoC or KEV listing yet, but the critical severity and unauthenticated file-read-to-RCE path make this a patch-this-sprint priority — update Rails to the fixed version.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Plan: If your pipelines load Hugging Face Diffusers models, audit which model repos are consumed and pin to reviewed/trusted sources; check whether you are on the patched Diffusers version once fixes land, as these flaws bypass the trust_remote_code safeguard.
- SOC/IR — Learn: No active exploitation or IOCs reported; understand that model-loading in ML pipelines can be a code-execution vector and begin thinking about detection coverage for anomalous process spawning from Python ML workloads.
- Leader — Learn: Illustrates that AI/ML supply chain risk is not theoretical — if your teams consume external model repositories, ask whether a policy governing approved model sources exists before a control is needed.
- Engineer — Act: Pre-auth RCE with a public exploit in vBulletin’s template renderer is actively exploitable right now — patch vBulletin to the vendor-released fixed version immediately if you run any internet-facing vBulletin instance.
- SOC/IR — Act: A public exploit for pre-auth PHP code execution means exploitation is likely in progress — sweep vBulletin access logs for anomalous template-rendering requests and hunt for web shells or unexpected PHP processes on any vBulletin host since the disclosure date.
- Leader — Skip
- Engineer — Act: Any authenticated repo contributor can plant a malicious Git hook and execute arbitrary commands as the Gitea service account — a very low exploitation bar with a public PoC already on GitHub. Upgrade all Gitea instances from 1.17–1.27.0 to 1.27.1 immediately.
- SOC/IR — Plan: No KEV listing or confirmed in-the-wild exploitation yet, but the public PoC makes opportunistic attacks likely soon. Build a detection for unexpected process spawning from the Gitea service account and audit recent git hook creation events on any self-hosted Gitea instances.
- Leader — Plan: Self-hosted Gitea instances are common in engineering orgs and often sit inside CI/CD pipelines where a service-account RCE could enable supply-chain compromise. Confirm whether internal Gitea deployments exist and verify they are on the patching roadmap before the public PoC drives active exploitation.
- Signals: CVE-2026-60004 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: A public PoC exists for this CVSS 9.8 unauthenticated stack overflow in odhcpd, which is enabled by default. Upgrade all OpenWrt devices to 24.10.8 immediately, or disable DHCPv6/odhcpd on devices that don’t need it.
- SOC/IR — Plan: With a public PoC now available, exploitation of internet- or LAN-exposed OpenWrt edge devices is imminent. Build detections for anomalous DHCPv6 traffic volumes and unexpected child processes from odhcpd, and queue a sweep of managed OpenWrt-based appliances for signs of prior compromise.
- Leader — Skip
- Signals: CVE-2026-53921 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: A public PoC on GitHub combined with a CVSS 9.8 unauthenticated RCE makes exploitation imminent — patch all on-premises TeamCity instances to 2025.11.7 or 2026.1.3 immediately; Cloud instances are already remediated.
- SOC/IR — Act: With a public PoC now available, begin hunting for unauthenticated requests to TeamCity build/run endpoints and review build agent logs for unexpected OS command execution patterns since the PoC publication date.
- Leader — Plan: Confirm whether your organization runs TeamCity On-Premises and verify the engineering team has prioritized emergency patching this week — a compromise of CI/CD pipelines carries supply-chain risk that could generate customer or board questions if exploitation is later confirmed.
- Signals: CVE-2026-63077 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: A public exploit now makes unauthenticated code execution against vBulletin 6.2.1 and earlier trivially accessible to any attacker. Patch to the fixed release immediately; if no patch is available for your branch, take the instance offline or block external access until patched.
- SOC/IR — Plan: With a public exploit in the wild, opportunistic scanning and exploitation attempts are likely imminent. Build or tune web application attack detections for anomalous unauthenticated POST requests to vBulletin PHP endpoints and PHP child-process spawning indicative of eval() abuse.
- Leader — Skip
- Engineer — Act: FastJson is widely used in Java applications; if your codebase or dependencies include it, audit immediately and apply any available patch or mitigations — if no patch exists, consider disabling unsafe deserialization features or replacing the library.
- SOC/IR — Act: Active exploitation is underway against US firms; hunt for anomalous outbound connections or process spawning from Java application servers since this week, and tune detections for RCE post-exploitation behavior (e.g., web shells, unexpected child processes).
- Leader — Plan: Active zero-day targeting US organizations warrants asking your engineering team this week whether FastJson is in use and what the mitigation timeline is — this may generate customer questions if it widens.
- Engineer — Act: CVE-2026-16812 (CVSS 10.0) is CISA KEV-listed with a public PoC and confirmed active exploitation — patch on-premises VeloCloud Orchestrator to the vendor-fixed version immediately and treat any unpatched instance as potentially compromised.
- SOC/IR — Act: Active exploitation of this RCE means on-prem VCO hosts should be treated as assume-breach candidates; hunt for anomalous process execution or outbound connections originating from VeloCloud Orchestrator nodes and sweep for IOCs since the date public PoC became available.
- Leader — Act: Confirm whether the organization runs on-premises VeloCloud Orchestrator and if so escalate to an emergency patch cycle this week; a CVSS 10.0 SD-WAN orchestration flaw on the CISA KEV list under active exploitation is a board-question-level event for enterprises relying on it for network management.
- Signals: CVE-2026-16812 — CISA KEV: listed, EPSS n/a, public PoC on GitHub
- Engineer — Act: Public PoC is on GitHub and this is a bypass of a prior February patch, indicating active research interest; if you self-host n8n, upgrade to 2.31.5 or 2.32.1 immediately to close authenticated RCE exposure.
- SOC/IR — Plan: No KEV listing and EPSS is low (0.09), but the public PoC raises the practical risk; build a detection for unexpected child processes or OS command execution spawned by the n8n service account to cover in-estate exposure.
- Leader — Skip
- Signals: CVE-2026-27577 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub
- Engineer — Act: Fastjson 1.x is embedded in many Spring Boot applications; unauthenticated RCE with a public PoC and confirmed active attacks means immediate action is required — audit all services for Fastjson 1.x dependencies, apply WAF rules to block the malicious JSON chain, and isolate or rate-limit exposed endpoints until a patch is available.
- SOC/IR — Act: Multi-source confirmation of active exploitation gives a detection mandate now — hunt for anomalous JSON deserialization patterns in HTTP request logs to Spring Boot services and monitor for unexpected outbound connections or process spawning from Java app servers since the earliest confirmed attack date.
- Leader — Plan: A critical, unpatched RCE in a widely-used Java library under active attack warrants commissioning an urgent Fastjson 1.x exposure inventory across development teams this week; if use is confirmed, allocate engineering time for compensating controls and track remediation until a vendor patch is released.
- Signals: CVE-2026-16723 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
- Engineer — Act: A working public exploit now exists for this six-week-old GitLab flaw; any authenticated user with push access on an unpatched self-managed instance can achieve RCE. Upgrade to the patched version released June 10 immediately and verify no self-managed GitLab instances remain on 18.11.3.
- SOC/IR — Act: PoC publication on July 24 makes exploitation imminent; hunt for anomalous Jupyter notebook pushes followed by commit-diff access on self-managed GitLab instances, and look for unexpected git-process child execution in EDR telemetry as of that date.
- Leader — Plan: A public exploit for GitLab RCE elevates CI/CD pipeline compromise risk this week; confirm with engineering that all self-managed GitLab instances are on the June 10 patched release before this becomes an active incident requiring notification.
- Engineer — Act: Active Cl0p data-extortion campaign exploiting internet-exposed PTC Windchill and FlexPLM via chained pre-auth flaws; immediately audit for internet-exposed instances, apply available patches, and if patching is delayed, restrict Windchill login servlet and FlexPLM WSDL endpoint from external access.
- SOC/IR — Act: Active Cl0p campaign with a concrete exploit chain (pre-auth FlexPLM WSDL disclosure chained into Windchill login servlet); hunt for anomalous pre-authenticated requests to these endpoints since campaign start and sweep for Cl0p-associated IOCs in PLM server logs and EDR telemetry.
- Leader — Plan: Cl0p affiliates are running a targeted data-extortion campaign against manufacturing and engineering organizations using PTC Windchill/FlexPLM; if your org or key suppliers use these platforms, assess exposure now and be prepared to brief leadership on potential data theft risk before it surfaces in the press.
- Engineer — Learn: The vulnerability sat in Microsoft’s own infrastructure and is already patched, but the technique — crafted SVG triggering RCE in a server-side image processing pipeline — is directly generalizable. Audit any service that accepts user-submitted SVGs and processes them server-side (ImageMagick, librsvg, Inkscape CLI, etc.) for equivalent exposure.
- SOC/IR — Skip
- Leader — Learn: A research disclosure showing critical RCE in a major cloud vendor’s production infrastructure; Microsoft has issued CVEs and presumably patched. No action required but it’s a useful data point on shared-responsibility boundaries when cloud vendors process user-submitted content.
- Signals: CVE-2026-32194 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: Public authenticated-RCE PoCs exist for Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0; upgrade to Redis 6.2.23, 7.2.15, or 7.4.10 immediately, and audit whether RESTORE, EVAL, or XGROUP are accessible to untrusted clients in your environment.
- SOC/IR — Plan: No confirmed in-the-wild exploitation yet, but public PoCs accelerate that timeline; build detections for anomalous Redis command sequences involving RESTORE combined with EVAL or XGROUP, and baseline normal Redis command usage now so deviations surface quickly.
- Leader — Plan: Redis is pervasive in enterprise stacks; confirm all internal deployments and any SaaS vendors running Redis are targeting the patched versions (6.2.23/7.2.15/7.4.10), and track remediation completion — the authenticated-only attack surface limits immediate board escalation but warrants this-quarter tracking.
- Engineer — Act: Active exploitation confirmed with a public GitHub PoC; patch SharePoint immediately AND regenerate machine keys — patching alone does not evict attackers who already exfiltrated them, so key rotation is the critical second step.
- SOC/IR — Act: Stolen machine keys enable persistent, post-patch impersonation attacks — hunt SharePoint IIS logs for exploitation artifacts since the vulnerability became public, and write detections for anomalous ViewState or token-forging activity tied to mismatched machine keys.
- Leader — Plan: Confirm SharePoint is in scope, then ensure your engineering team understands that patching alone is insufficient — key rotation and a post-exploitation sweep are required; flag this as a two-step remediation so it isn’t closed prematurely in the ticket queue.
- Signals: CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: CVSS 9.8 deserialization RCE with public PoC and confirmed active exploitation — patch SharePoint Server to the July 2026 Patch Tuesday build immediately; do not wait for CISA KEV confirmation given exploitation is already underway.
- SOC/IR — Act: Active exploitation predating your patch window means assume-breach posture is warranted — hunt for anomalous deserialization or code execution activity on SharePoint servers back to at least the PoC publication date, and review watchTowr’s reporting for any available IOCs or behavioral signatures.
- Leader — Act: A CVSS 9.8 unauthenticated RCE in widely-deployed enterprise SharePoint under active exploitation requires a same-week exposure check — confirm whether the org runs on-premises SharePoint Server and verify the engineering team has prioritized the July Patch Tuesday update.
- Signals: CVE-2026-50522 — CISA KEV: not listed, EPSS 0.20, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: CISA KEV listing confirms active exploitation of this RCE in Langflow, a framework increasingly adopted by AI development teams. Audit all environments for Langflow deployments and patch to the fixed version immediately — days-level urgency, not weeks.
- SOC/IR — Act: Active exploitation of a Langflow RCE means any instance in your estate should be treated as potentially compromised; initiate an assume-breach sweep of Langflow hosts for post-exploitation artifacts (new processes, outbound connections, credential access) and hunt for inbound exploitation attempts in web/proxy logs since the vulnerability became public.
- Leader — Plan: Langflow is niche enough that board escalation is unlikely unless your AI engineering teams are actively using it — confirm with engineering whether Langflow is deployed anywhere in the environment and ensure it lands in the emergency patch queue this week.
- Engineer — Act: Both CVEs have public PoCs and exploitation is already underway with mass scanning — patch all WordPress instances to the fixed versions immediately and audit exposed sites for webshell artifacts, especially any unexpected PHP files or modified themes.
- SOC/IR — Act: Active exploitation confirmed since early Saturday UTC; hunt for webshell uploads and anomalous POST requests targeting WordPress endpoints across your estate, and sweep for post-compromise persistence on any internet-facing WordPress hosts.
- Leader — Plan: Active exploitation with mass scanning is in progress but hasn’t reached Log4Shell-scale board attention yet; confirm whether WordPress appears in your web portfolio and ensure it’s on your engineering team’s immediate patching queue this week.
- Signals: CVE-2026-60137 — CISA KEV: not listed, EPSS 0.04, public PoC on GitHub · CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: Unauthenticated RCE in WordPress Core (not a plugin) is being actively exploited with a public PoC on GitHub — patch all WordPress Core installations to the latest fixed release immediately and audit web server and DB logs for SQLi patterns.
- SOC/IR — Act: Active exploitation is confirmed; sweep any WordPress-hosting infrastructure for webshells, unexpected file writes, and anomalous database query patterns tied to wp2shell activity since last week’s disclosure.
- Leader — Plan: Confirm whether WordPress is present in the company’s web estate and verify engineering has prioritized patching this week; not yet at board-briefing scale but unauthenticated RCE with active exploitation warrants prompt follow-up with the engineering team.
- Signals: CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: Public PoC exists and in-the-wild exploitation is reported for this unauthenticated sandbox-escape RCE (CVSS 9.5) in the ServiceNow AI Platform. Confirm your ServiceNow instance has the available patch applied via the admin console, and audit platform logs for anomalous code execution since the disclosure date.
- SOC/IR — Act: Active exploitation of unauthenticated RCE on a widely deployed enterprise ITSM platform creates immediate detection work. Hunt for anomalous outbound connections, unusual process spawning, or lateral movement originating from ServiceNow infrastructure since the vulnerability was disclosed, and tune EDR/SIEM for post-exploitation behavior on hosts that ServiceNow agents touch.
- Leader — Act: A critical unauthenticated RCE in ServiceNow with confirmed in-the-wild exploitation could expose ITSM data and integrated systems. This week, confirm with your ServiceNow admin that the patch is applied to your instance and assess whether any sensitive data (HR, IT credentials, integrations) in the platform warrants a precautionary leadership or customer notification.
- Signals: CVE-2026-6875 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
- Engineer — Act: A public Docker lab with a working one-payload exploit now exists for fastjson 1.2.66–1.2.83; critically, autoType=OFF and parseObject binding are not effective mitigations. Audit your dependency tree for fastjson in this range and upgrade to 1.2.84+ (or fastjson2), treating autoType-disabled deployments as unprotected.
- SOC/IR — Plan: The public exploit lab lowers the bar for threat actors to weaponize this Spring Boot class-loading RCE chain. Build or tune detections for unexpected outbound SSRF from Java application hosts followed by remote class loading activity; the SSRF→defineClass pattern is a distinct behavioral signal to hunt for in proxy and EDR telemetry.
- Leader — Skip
- Engineer — Plan: ServiceNow is widely deployed in enterprise environments and a critical RCE warrants patch prioritization, but enrichment signals are very weak (EPSS 0.01, no CISA KEV, no public PoC) and exploitation is claimed by a single vendor source. If you run ServiceNow AI Platform, confirm your version and apply the available patch this sprint rather than treating it as a drop-everything emergency.
- SOC/IR — Learn: Exploitation is asserted by one threat-intel vendor (Defused) with no corroborating IOCs, ATT&CK mappings, or multi-source confirmation — there is no concrete detection surface to act on yet. Monitor for published IOCs or behavioral signatures before opening a hunt.
- Leader — Plan: ServiceNow is a core ITSM platform at many enterprises; confirm with engineering whether your organization runs the affected AI Platform version and verify patching is prioritized this sprint. The single-source exploitation claim without CISA KEV listing does not yet warrant a board-level communication, but exposure should be checked proactively.
- Signals: CVE-2026-6875 — CISA KEV: not listed, EPSS 0.01, no public PoC found
- Engineer — Act: NGINX is near-universal in cloud stacks and a public PoC already exists on GitHub, lowering the bar for exploitation despite low EPSS. Upgrade to nginx 1.30.4 (stable) or 1.31.3 (mainline), or NGINX Plus 37.0.3.1, before the PoC matures into a weaponized exploit.
- SOC/IR — Skip
- Leader — Skip
- Signals: CVE-2026-42533 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: Public exploits for critical WordPress Core RCE make this urgent regardless of absent KEV/EPSS data — update WordPress Core to the latest patched release immediately and verify any managed hosting environments are also updated.
- SOC/IR — Plan: No IOCs or TTPs are provided to hunt on now, but given public exploits exist for a widely-deployed web platform, build or tune detections for WordPress exploit traffic (e.g., anomalous POST patterns, webshell indicators in web access logs) before active campaigns arrive.
- Leader — Plan: This is an engineering-track issue, not board-level — confirm your team has inventoried WordPress instances across the estate and that patching is tracked to completion this week.
- Engineer — Plan: Update 7-Zip to v26.02 on any systems or pipelines that process untrusted archives; no KEV listing or public PoC confirmed yet, but RCE via user-opened files is a practical threat in build environments or developer workstations.
- SOC/IR — Skip
- Leader — Skip
- Engineer — Act: Public PoC is available for an unauthenticated RCE in WordPress core affecting 6.9 and 7.0 with no plugins required — patch every WordPress instance to the fixed version immediately and audit web server file systems for newly dropped shells or unexpected PHP files.
- SOC/IR — Act: A public PoC for unauthenticated RCE in WordPress core means active exploitation is likely underway; sweep web access logs for anomalous POST patterns against wp-admin and wp-includes endpoints, and hunt for new or modified PHP files and unexpected child processes spawned by the web server process since the disclosure date.
- Leader — Act: Unauthenticated RCE in WordPress core with a working public exploit is a systemic exposure for any org running WordPress-powered properties; confirm inventory of WordPress versions across customer-facing and internal sites, verify engineering has prioritized emergency patching, and assess whether key SaaS or media vendors in your supply chain are exposed.
- Engineer — Act: SharePoint Server CVE-2026-58644 (CVSS 9.8) is KEV-listed with active exploitation and a public GitHub PoC — patch immediately; federal deadline is July 19, 2026, so treat this as emergency priority regardless of your organization type.
- SOC/IR — Act: With active exploitation confirmed and a public PoC live, treat any on-prem SharePoint Server as potentially compromised — sweep SharePoint ULS/IIS logs for deserialization anomalies and unusual POST requests to SharePoint endpoints since the vulnerability was disclosed.
- Leader — Act: A CVSS 9.8 SharePoint RCE is actively exploited and KEV-listed with a two-day federal remediation deadline — confirm this week whether your environment runs SharePoint Server on-prem and verify the engineering team has emergency patching underway before the July 19 deadline.
- Signals: CVE-2026-58644 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
- Engineer — Act: CISA warning signals KEV-level active exploitation — update or disable the iCagenda and Balbooa Forms Joomla extensions immediately, and audit web roots for unexpectedly uploaded files that may indicate prior compromise.
- SOC/IR — Act: Active exploitation via arbitrary file upload means webshells may already be in place — hunt Joomla web directories for recently uploaded executables and review web server logs for POST requests targeting these extension upload endpoints.
- Leader — Plan: Confirm whether any company-owned or vendor-hosted web properties run Joomla with these extensions and verify engineering teams have patch SLAs in motion; this does not yet rise to board-briefing level.
- Engineer — Plan: A public PoC exists for this GitHub RCE, raising urgency even though EPSS is 0.24 and KEV is not listed. If running GitHub Enterprise Server, apply available patches now and review CI/CD pipeline logs for anomalous workflow executions.
- SOC/IR — Plan: Public PoC availability makes pre-emptive detection work worthwhile before confirmed active exploitation. Build or tune rules around anomalous GitHub API calls, unexpected workflow triggers, and unusual code execution patterns in CI/CD infrastructure.
- Leader — Plan: GitHub is core infrastructure for most engineering orgs; confirm whether your deployment is GitHub.com or self-hosted Enterprise Server, and request GitHub’s remediation status — a public PoC with no KEV listing still warrants a near-term vendor risk check.
- Signals: CVE-2026-3854 — CISA KEV: not listed, EPSS 0.24, public PoC on GitHub
- Engineer — Plan: GitHub Copilot is broadly deployed on developer workstations; a public PoC exists for this RCE-via-prompt-injection path, but EPSS is 0.03 and it is not KEV-listed. Check for an available Copilot update and audit whether your pipelines or editors process untrusted file content through Copilot without sandboxing.
- SOC/IR — Learn: Prompt injection as an RCE delivery mechanism in AI coding assistants is a novel developer-endpoint attack class worth adding to your threat model, but the summary provides no IOCs or ATT&CK-mappable TTPs to act on for detection tuning today.
- Leader — Plan: If your organization deploys GitHub Copilot to developers (very common), a demonstrated RCE path represents a developer-workstation supply-chain risk; confirm with engineering whether a patched version is available and assess exposure this quarter before exploitation pressure rises.
- Signals: CVE-2025-53773 — CISA KEV: not listed, EPSS 0.03, public PoC on GitHub
- Engineer — Act: Unauthenticated RCE on a widely-deployed internet-facing MTA with a public PoC on GitHub demands immediate action regardless of low EPSS — Exim has a history of mass exploitation. Patch Exim to the version addressing CVE-2026-45185; if no patch is yet available, restrict SMTP exposure at the network layer while tracking vendor advisory.
- SOC/IR — Plan: No active exploitation confirmed in enrichment signals, but a public PoC for pre-auth RCE on an internet-facing mail server shortens the window — build or stage Exim-specific detections (unusual child processes spawned from the Exim process, unexpected outbound connections from mail servers) before exploitation ramps up.
- Leader — Skip
- Signals: CVE-2026-45185 — CISA KEV: not listed, EPSS 0.01, public PoC on GitHub
- Engineer — Plan: If OpenClaw is deployed in your environment, verify you are running a patched version addressing all three CVEs (GHSA-hjr6-g723-hmfm and siblings); no public PoC or KEV listing present, so patch within normal cycle but prioritize given CVSS 8.8 and the RCE/privilege-escalation chain.
- SOC/IR — Learn: No published IOCs or active exploitation reported; the attack chain description (WhatsApp input → credential theft → privilege escalation → host RCE) is worth understanding to recognize behavioral indicators if OpenClaw is in scope, but no detection work is actionable today.
- Leader — Skip