August 4, 2026
- SharePoint on-prem RCE chain remains actively exploited. CERT-EU updated its advisory noting WatchTowr PoC code and in-the-wild exploitation of CVE-2026-50522, part of an ongoing series alongside CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644; patch immediately and rotate credentials on exposed servers (CERT-EU).
· Vulnerabilities & Exploits
in Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short
July 18, 2026
- "wp2shell" pre-auth RCE in WordPress core chains CVE-2026-63030 (REST
/batch/v1 route-confusion SQL injection) and CVE-2026-60137 (author__not_in SQLi in WP_Query) to unauthenticated code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, per reporter searchlight cyber/assetnote (SL Cyber, Rapid7, The Hacker News). A public PoC and a non-destructive detector + Docker lab are already out; watchTowr says it is "rapidly reacting" across its client base. Patch to the fixed releases immediately per the WordPress advisory.
· Vulnerabilities & Exploits
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 11, 2026
- Progress Software emailed ShareFile customers urging them to immediately power down Windows servers running Storage Zone Controllers after identifying a "credible external security threat," and has temporarily disabled affected accounts. watchTowr says it is tracking rumors of active zero-day exploitation against exposed on-prem controllers and has notified clients with internet-facing instances. Treat any exposed Storage Zone Controller as potentially compromised. The Hacker News, BleepingComputer
· Vulnerabilities & Exploits
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
July 1, 2026
- Citrix patched six NetScaler ADC/Gateway flaws, led by CVE-2026-8451 (CVSS 8.8), a pre-auth memory overread in SAML IdP handling that leaks memory and can crash appliances — the latest entry in the "CitrixBleed" lineage. watchTowr Labs, which reported it in March, published its analysis and hinted more is coming. The Hacker News, watchTowr
· Vulnerabilities & Exploits
in CitrixBleed Returns: watchTowr Discloses a New NetScaler Pre-Auth Memory Overread