vulnerability Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC A critical SharePoint vulnerability (CVE-2026-50522) is currently being actively exploited, allowing attackers to execute code remotely and steal machine keys. Microsoft released a patch last month, but attackers are lev… The Hacker News · Jul 21, 2026 Critical CVE-2026-50522CVE-2026-56164CVE-2026-58644sharepointvulnerabilityrce
vulnerability Siemens IAM Client Siemens has identified a critical unquoted search path vulnerability in its IAM Client SDK, potentially allowing an authenticated local attacker to escalate privileges. Multiple Siemens products, including COMOS, Designc… CISA Advisories · Jul 21, 2026 Critical CVE-2025-40945cwe-426unquoted search pathiam client
vulnerability Tycon Systems TPDIN-Monitor-WEB2 Tycon Systems TPDIN-Monitor-WEB2 versions 2.3.9 are vulnerable to a critical authentication bypass flaw, allowing unauthenticated remote attackers to gain full administrative access to the device. This could lead to disr… CISA Advisories · Jul 21, 2026 Critical CVE-2026-61884CVE-2026-55985authentication bypasscwe-288cwe-312
vulnerability Siemens Opcenter X Siemens Opcenter X versions prior to V2604 contain a critical authentication bypass vulnerability, allowing an unauthenticated attacker to gain full unauthorized access to the application. Siemens has released a new vers… CISA Advisories · Jul 21, 2026 Critical CVE-2026-56451DEauthenticationjwtcwe-347
vulnerability Rockwell Automation ThinManager Rockwell Automation has issued a security advisory regarding a path traversal vulnerability in its ThinManager software. This vulnerability allows an authenticated attacker to write arbitrary files to restricted system d… CISA Advisories · Jul 21, 2026 Critical CVE-2026-11917path traversalicsindustrial control systems
vulnerability Zimbra Update Patches Critical Vulnerabilities Zimbra has released a critical security update to address several vulnerabilities, including a command injection flaw and XSS defects, that could allow attackers to execute commands and steal emails. The update is essent… SecurityWeek · Jul 21, 2026 Critical CVE-2026-50055CVE-2026-10631CVE-2026-50054command injectionxssssrf
vulnerability Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution A critical security vulnerability in ServiceNow's AI Platform is being actively exploited, allowing unauthenticated code execution and potentially a complete compromise of ServiceNow instances. ServiceNow has released p… The Hacker News · Jul 21, 2026 Critical CVE-2026-6875vulnerabilitycode executionsandbox
vulnerability ISC Stormcast For Tuesday, July 21st, 2026 https://isc.sans.edu/podcastdetail/10016, (Tue, Jul 21st) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 21, 2026 Critical apachestrutsvulnerability
threat-intel WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th) A critical WordPress webshell vulnerability (CVE-2026-63030) is being actively exploited. This vulnerability, stemming from a SQL injection flaw in the WordPress Core REST API, allows unauthenticated remote code executio… SANS Internet Storm Center · Jul 20, 2026 Critical CVE-2026-63030sql injectionwebshellwordpress
vulnerability New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code A critical vulnerability (RCE) exists in WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1, allowing unauthenticated attackers to execute code via a batch request. While no CVE has been assigned yet, WordPr… The Hacker News · Jul 17, 2026 Critical wordpressrcevulnerability
threat-intel Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy A collaborative research effort between Palo Alto Networks and Siemens has uncovered a critical, chained exploit within the Siemens ROX II operational technology (OT) switches. The vulnerability chain consists of three z… Palo Alto Unit 42 · Jul 17, 2026 Critical CVE-2025-40948CVE-2025-40947CVE-2025-40949otvulnerabilitycommand-injection
vulnerability Fresh SharePoint Vulnerability Exploited Soon After Disclosure A critical remote code execution vulnerability in Microsoft SharePoint has been actively exploited by threat actors shortly after its disclosure. Microsoft has released patches to address the issue, but CISA has added it… SecurityWeek · Jul 17, 2026 Critical CVE-2026-58644CVE-2026-56164CVE-2026-55040rcesharepointvulnerability
vulnerability CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV CISA has added a critical, actively exploited vulnerability in Microsoft SharePoint Server to its KEV list, forcing federal agencies to address it immediately. This zero-day flaw, CVE-2026-58644, allows for remote code e… The Hacker News · Jul 17, 2026 Critical CVE-2026-58644sharepointvulnerabilitydeserialization
vulnerability ISC Stormcast For Friday, July 17th, 2026 https://isc.sans.edu/podcastdetail/10012, (Fri, Jul 17th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Log4j, potentially allowing attackers to execute arbitrary code through a specially crafted log message. This vulnerability, along… SANS Internet Storm Center · Jul 17, 2026 Critical log4jjndivulnerability
vulnerability SALTO ProAccess Space A critical vulnerability (CVE-2026-11889) exists in SALTO ProAccess Space versions prior to 6.13, allowing an authenticated attacker to escalate privileges and gain unauthorized access to spaces beyond their assigned par… CISA Advisories · Jul 16, 2026 Critical CVE-2026-11889WOvulnerabilityprivilege escalationcve-2026-11889
vulnerability Rockwell Automation FactoryTalk DataMosaix Rockwell Automation has issued a security advisory regarding a critical vulnerability (CVE-2026-9292) in its FactoryTalk DataMosaix Private Cloud software. An authenticated attacker can inject malicious scripts that are… CISA Advisories · Jul 16, 2026 Critical CVE-2026-9292cve-2026-9292xsscwe-79
vulnerability Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide A researcher discovered a critical vulnerability in Shark robot vacuums due to a flawed certificate policy on Amazon's AWS cloud platform. Attackers can exploit this to gain remote control of vacuums across an entire AWS… The Hacker News · Jul 16, 2026 Critical awsiotcertificate
vulnerability Unpatched Cursor Vulnerability Exposes Users to Code Execution A critical, unpatched vulnerability in Cursor, a popular AI-assisted development environment, allows for code execution simply by opening a project containing a malicious git.exe binary. Despite being reported to Cursor… SecurityWeek · Jul 15, 2026 Critical cursorgitcode execution
vulnerability Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands SonicWall has warned of active exploitation of two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. One vulnerability allows unauthenticated attackers to make requests to unintended loca… The Hacker News · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode injection
threat-intel SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits SonicWall has issued an urgent patch warning due to two newly exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances. Threat actors are actively leveraging these flaws, and CISA has added them… SecurityWeek · Jul 15, 2026 Critical CVE-2026-15409CVE-2026-15410zero-dayssrfcode_injection