August 25, 2026
- Rapid7 published analysis of SharePoint RCE CVE-2026-63520. CERT-EU's updated advisory covers the wider on-prem SharePoint chain, noting public PoC code and observed exploitation of CVE-2026-50522 alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — and recommends rotating credentials on any exposed server, not just patching (Rapid7, CERT-EU).
· Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 4, 2026
- SharePoint on-prem RCE chain remains actively exploited. CERT-EU updated its advisory noting WatchTowr PoC code and in-the-wild exploitation of CVE-2026-50522, part of an ongoing series alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644; patch immediately and rotate credentials on exposed servers (CERT-EU).
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
July 16, 2026
in Relay Chains, Bind-Link Blindspots, and a Wave of Live Zero-Days
July 3, 2026
- CISA added CVE-2026-45659, a SharePoint Server RCE via untrusted-data deserialization (CVSS 8.8), to the KEV catalog after confirming active exploitation — despite Microsoft's earlier "exploitation less likely" assessment. BleepingComputer, The Register.
· Vulnerabilities & Exploits
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire