Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522
2026-07-22T02:51:41Z•f4b387dfda7f96cd47d18c30224d21375b0e058bdb9ef3931f5d6bde44540b84
7-ZipNGINXPAN-OS/GlobalProtectServiceNowSharePointSonicWallVPNZimbraactive exploitationauthentication-bypasscommand-injectionespionagepatch availableproof-of-conceptransomwareremote code executionzero-day
What happened
Multiple critical vulnerabilities and active exploitation campaigns reported: public PoC has triggered active exploitation of SharePoint RCE CVE-2026-50522 (CVSS 9.8); Qilin ransomware affiliates are exploiting PAN-OS GlobalProtect auth-bypass CVE-2026-0257 to gain VPN access; ServiceNow pre-auth RCE CVE-2026-6875 is being exploited against self-hosted instances; and nginx heap-overflow CVE-2026-42533 can lead to crashes and potential RCE. Additional high-risk issues include a 7‑Zip XZ-handling RCE, a critical Zimbra SNMP command-injection, SonicWall SMA zero-days used to gain root on VPNs, as
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f4b387dfda7f96cd47d18c30224d21375b0e058bdb9ef3931f5d6bde44540b84
- Enrichment time
- 2026-07-22T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.