Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
2026-07-22T08:51:50Z•f0f9d69815b01996773a780b7b8bd2ae01db3d720e50cb10d46f7f9175bbc2d5
7-ZipGlobalProtectHugging-FaceNGINXPAN-OSQilinSaaS-securityServiceNowSharePointSonicWallVPN-compromiseVolexityZimbraactive-exploitationauthentication-bypasscommand-injectionespionageincident-responseip-cameraspatch-releasedproof-of-conceptransomwarercesupply-chain-riskzero-day
What happened
Multiple high-impact vulnerabilities and active attacks reported: a public PoC has triggered active exploitation of critical Microsoft SharePoint RCE CVE-2026-50522 (CVSS 9.8); Qilin ransomware affiliates are abusing PAN-OS GlobalProtect authentication bypass CVE-2026-0257 to gain VPN access; attackers are exploiting pre-auth ServiceNow RCE CVE-2026-6875 against self-hosted instances; F5 released fixes for a critical nginx bug CVE-2026-42533 that can crash or lead to RCE; Zimbra 10.1.20 fixes a critical SNMP command injection; 7-Zip patched an XZ-handling RCE; Volexity disclosed zero-day intru
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f0f9d69815b01996773a780b7b8bd2ae01db3d720e50cb10d46f7f9175bbc2d5
- Enrichment time
- 2026-07-22T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.