Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

2026-07-22T08:51:50Zf0f9d69815b01996773a780b7b8bd2ae01db3d720e50cb10d46f7f9175bbc2d5
7-ZipGlobalProtectHugging-FaceNGINXPAN-OSQilinSaaS-securityServiceNowSharePointSonicWallVPN-compromiseVolexityZimbraactive-exploitationauthentication-bypasscommand-injectionespionageincident-responseip-cameraspatch-releasedproof-of-conceptransomwarercesupply-chain-riskzero-day

What happened

Multiple high-impact vulnerabilities and active attacks reported: a public PoC has triggered active exploitation of critical Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8); Qilin ransomware affiliates are abusing PAN-OS GlobalProtect authentication bypass CVE-2026-0257 to gain VPN access; attackers are exploiting pre-auth ServiceNow RCE CVE-2026-6875 against self-hosted instances; F5 released fixes for a critical nginx bug CVE-2026-42533 that can crash or lead to RCE; Zimbra 10.1.20 fixes a critical SNMP command injection; 7-Zip patched an XZ-handling RCE; Volexity disclosed zero-day intru

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f0f9d69815b01996773a780b7b8bd2ae01db3d720e50cb10d46f7f9175bbc2d5
Enrichment time
2026-07-22T08:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.