⚠ exploit status: CVE-2025-5777 · KEV·R CVE-2026-45659 · KEV
Info  2026-07-03 06:08Z · last 24h · 46 findings · glm-5.2:cloud

Threat Brief — 2026-07-03 — Exploitation Escalation Across SharePoint, Fortinet, and Citrix

Executive Summary

The most urgent development is active exploitation of a Microsoft SharePoint RCE (CVE-2026-45659KEV), now in CISA's KEV catalog. Cisco has also confirmed in-the-wild exploitation of a patched Unified Communications Manager flaw. Ransomware operators are rotating quickly between perimeter appliance vulnerabilities — FortiBleed credentials are now directly feeding INC and Lynx ransomware, while Anubis affiliates are leveraging Citrix Bleed 2 (CVE-2025-5777KEV·R). Separately, a new attack pattern has emerged where AI agents are being used to autonomously execute ransomware end-to-end via Langflow RCE, marking a notable escalation in adversary automation.

Top items

Themes

Microsoft cloud and identity attack surface — a broad target. Five new Microsoft elevation-of-privilege CVEs land alongside active exploitation of SharePoint RCE, a Copilot Outlook bug, and ConsentFix/ClickFix M365 token-theft campaigns. The concentration suggests adversaries are intensively targeting Microsoft identity, email, and collaboration infrastructure. Prioritise Microsoft patching, review OAuth consent grants, and audit Exchange/SharePoint exposure.

Ransomware diversifying initial-access vectors. INC, Lynx, and Anubis ransomware affiliates are simultaneously exploiting FortiBleed, Citrix Bleed 2, and supply-chain credentials. The pattern emphasises that perimeter appliance hygiene — especially Fortinet and Citrix — remains the critical first gate for ransomware prevention.

Adversarial AI moves from concept to observed use. The JADEPUFFER autonomous ransomware agent and the targeting of AI infrastructure (Langflow RCE, Azure OpenAI SSRF) indicate threat actors are operationalising AI agents for full attack-chain automation. Security teams should inventory exposed AI/ML services and treat them as internet-facing attack surface.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb