Crit
2026-07-21 15:50Z · last 24h · 60 findings
· glm-5.2:cloud
Threat Brief — 2026-07-21 — SharePoint Zero-Day, KEV Cascade, AI Agents Under Fire
Executive summary: A second critical SharePoint Server deserialization RCE (CVE-2026-50522KEV, CVSS 9.8) is now exploited in the wild after a public PoC — distinct from the CVE-2026-58644KEV SharePoint flaw reported last week. CISA added four vulnerabilities to the KEV catalog, including the WordPress wp2shell chain and a Langflow RCE tied to new ENCFORGE ransomware targeting AI model files. ServiceNow AI platform exploitation has been independently confirmed by a second firm. Free unofficial patches for the Windows LegacyHive privilege escalation zero-day are now available.
Top items
- SharePoint CVE-2026-50522KEV — third critical SharePoint RCE now exploited. A CVSS 9.8 deserialization flaw in SharePoint Server, patched in July 2026 Patch Tuesday, is under active exploitation after watchTowr published a PoC. This is a separate vulnerability from CVE-2026-58644KEV reported on 2026-07-18. Organisations running unpatched SharePoint Server should treat this as emergency-patch priority. (src: The Hacker News)
- WordPress wp2shell: CISA KEV addition accelerates mass scanning. The two WordPress Core vulnerabilities (CVE-2026-63030KEV interpretation conflict + CVE-2026-60137KEV SQLi) that enable unauthenticated RCE on clean installations have been added to CISA's KEV catalog. Public PoC exploits are fueling internet-scale mass scanning. WordPress released emergency updates 6.9.5 and 7.0.2. This story was first reported 2026-07-18 by BleepingComputer; the KEV addition and scanning escalation are new developments. (src: CISA KEV) · The Hacker News · Xakep
- Langflow CVE-2026-0770KEV KEV'd — ENCFORGE ransomware targets AI model files. The Langflow inclusion-of-functionality RCE has been added to CISA KEV. Sysdig links a second attack on the same Langflow server to JADEPUFFER, now deploying ENCFORGE, a compiled Go ransomware that encrypts AI model files. JadePuffer was first reported 2026-07-18 by Mandiant/GTIG; the KEV addition and ENCFORGE variant are new. (src: CISA KEV · The Hacker News)
- DD-WRT CVE-2021-27137KEV added to CISA KEV. A stack-based buffer overflow in DD-WRT's UPnP handler, exploitable by unauthenticated attackers for remote code execution, has been added to the KEV catalog based on evidence of active exploitation. Despite being a 2021 CVE, embedded router fleets remain widely unpatched. (src: CISA KEV)
- ServiceNow AI platform exploitation independently confirmed. Defused Cyber reports in-the-wild exploitation of a critical unauthenticated code execution flaw in the ServiceNow AI Platform. ServiceNow maintains its SaaS infrastructure was not breached but self-hosted customers remain exposed. This follows initial reporting on 2026-07-20 by BleepingComputer; third-party confirmation is a new development. (src: The Hacker News · SecurityLab)
- Windows LegacyHive zero-day: free unofficial patches released. The 0patch team has published free unofficial micropatches for the Windows registry privilege escalation zero-day that allows unprivileged users to access admin registry hives on fully patched systems. Microsoft has not yet issued an official fix. First reported 2026-07-18 by Xakep; patch availability is new. (src: BleepingComputer)
- Zimbra patches critical SNMP command injection + four XSS. Nine vulnerabilities patched, including a critical command injection in the SNMP monitoring component that could allow remote attackers to execute commands on Zimbra servers. Self-hosted Zimbra deployments should patch immediately. (src: The Hacker News)
- Qilin ransomware exploits PAN-OS authentication bypass for initial access. Arctic Wolf Labs confirms Qilin (Agenda) ransomware operators are using a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point. Multiple incident engagements show this as a repeatable initial-access vector. (src: The Hacker News)
- Bit2Watt: cloud GPU tenants can disrupt data center power grids without an exploit. Zhejiang University researchers describe an attack where ordinary GPU access lets a cloud tenant rapidly oscillate power draw, threatening the electrical grid feeding the data center — no exploit or break-in required. This extends the "AI destabilizing infrastructure" threat model to physical power systems. (src: The Hacker News · SecurityLab)
- AI agent invisible-text attack: Android overlay apps can run code on host PCs. Researchers demonstrate that an Android app with overlay permissions can inject invisible text instructions into open-source AI agents, which then execute commands on the PC driving the agent. The attack chain requires no exploit — only standard permissions that many apps already request. (src: The Hacker News)
Themes
- AI infrastructure is now a primary attack surface. Langflow RCE → ENCFORGE ransomware encrypting model files, Hugging Face breach via autonomous agents, AI agent invisible-text injection, Bit2Watt grid disruption via GPU pools, and AI connector permission drift — all reported within 48 hours. Security teams should treat AI training pipelines, agent orchestration layers, and GPU resource isolation as first-class perimeter.
- N-day is compressing to N-hour. The gap between patch release and working exploit is collapsing as diff analysis automation accelerates. SharePoint CVE-2026-50522KEV went from Patch Tuesday to active exploitation within days. Patch cadence alone is no longer a viable defense — compensating controls and exploit-path monitoring matter more.
- Signed-driver abuse escalating. Both the DigiCert certificate theft (75 stolen signatures) and the Cruciferra signed-driver antivirus-killer service show threat actors weaponizing valid code-signing chains faster than revocation can keep up. EDR solutions that trust signed drivers by default are exposed.
