August 25, 2026
- Rapid7 published analysis of SharePoint RCE CVE-2026-63520. CERT-EU's updated advisory covers the wider on-prem SharePoint chain, noting public PoC code and observed exploitation of CVE-2026-50522 alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — and recommends rotating credentials on any exposed server, not just patching (Rapid7, CERT-EU).
· Vulnerabilities & Exploits
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 4, 2026
- SharePoint on-prem RCE chain remains actively exploited. CERT-EU updated its advisory noting WatchTowr PoC code and in-the-wild exploitation of CVE-2026-50522, part of an ongoing series alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644; patch immediately and rotate credentials on exposed servers (CERT-EU).
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
July 23, 2026
- SharePoint CVE-2026-50522 exploitation widening. Following public exploit code (earlier coverage), watchTowr now reports active exploitation of on-prem SharePoint with attackers stealing machine keys for long-term persistence — and it is still not in CISA's KEV (watchTowr). Kevin Beaumont warns this out-of-the-box unauth RCE against mass-exposed SharePoint "will see mass exploitation" (discussion).
· Vulnerabilities & Exploits
in "Every Frontier Model Tried to Cheat": UK Safety Institute Puts Numbers Behind the OpenAI–Hugging Face Incident
July 22, 2026
- A third SharePoint RCE, CVE-2026-50522 (CVSS 9.8), is under active exploitation following public PoC release. watchTowr reports attackers hitting on-prem SharePoint deployments and stealing machine keys for long-term persistence; the deserialization flaw was patched in July's Patch Tuesday and credited to DEVCORE. Notably it was still not in CISA KEV at time of reporting. The Hacker News, BleepingComputer.
· Vulnerabilities & Exploits
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face