Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522

2026-07-22T02:51:41Zf4b387dfda7f96cd47d18c30224d21375b0e058bdb9ef3931f5d6bde44540b84
7-ZipNGINXPAN-OS/GlobalProtectServiceNowSharePointSonicWallVPNZimbraactive exploitationauthentication-bypasscommand-injectionespionagepatch availableproof-of-conceptransomwareremote code executionzero-day

What happened

Multiple critical vulnerabilities and active exploitation campaigns reported: public PoC has triggered active exploitation of SharePoint RCE CVE-2026-50522 (CVSS 9.8); Qilin ransomware affiliates are exploiting PAN-OS GlobalProtect auth-bypass CVE-2026-0257 to gain VPN access; ServiceNow pre-auth RCE CVE-2026-6875 is being exploited against self-hosted instances; and nginx heap-overflow CVE-2026-42533 can lead to crashes and potential RCE. Additional high-risk issues include a 7‑Zip XZ-handling RCE, a critical Zimbra SNMP command-injection, SonicWall SMA zero-days used to gain root on VPNs, as

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f4b387dfda7f96cd47d18c30224d21375b0e058bdb9ef3931f5d6bde44540b84
Enrichment time
2026-07-22T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.