Skip to content
feed: live
>_ 0dayNews
Briefing · 2026-07-23-desk

July 21-22 desk: Three KEVs, SharePoint stripped

Three CISA KEV additions in 48 hours: SharePoint CVE-2026-50522 exploited for machine-key theft, Check Point SmartConsole auth bypass, Langflow federal deadline Friday.

tldr.txt
  • Microsoft SharePoint CVE-2026-50522 (CVSS 9.8) added to KEV 2026-07-22. Attackers exploiting post-patch to steal machine keys — patching alone is insufficient, rotate keys.
  • Check Point SmartConsole CVE-2026-16232 added to KEV 2026-07-22. Unauthenticated remote attacker can obtain full admin token. See advisory sk185169.
  • Langflow CVE-2026-0770 added to KEV 2026-07-21 with a federal patch deadline of 2026-07-25 (Friday). Fifth Langflow KEV in fourteen months. Upgrade past 1.7.3.
  • Qilin ransomware documented using Palo Alto PAN-OS CVE-2026-0257 GlobalProtect auth bypass for initial access — multiple June 2026 intrusions per Arctic Wolf. CVSS 7.8.
  • WordPress wp2shell (CVE-2026-63030 + CVE-2026-60137) on KEV; webshells observed post-compromise. Mass scanning underway.
  • Windmill CVE-2026-29059 unauthenticated path traversal under active exploitation per VulnCheck. CVSS 7.5.
  • Ubuntu snap-confine CVE-2026-8933 (CVSS 7.8): LPE to root on default Desktop 24.04, 25.10, 26.04. Canonical patch shipped.
  • Stadler Rail rejected a $12.3M Everest ransomware demand following breach of a supplier data exchange platform. Confirmed.
  • Upbound / Acima: $13M in fraudulent leases generated from stolen Upbound data. Confirmed by Upbound.
  • South Korea National Diplomatic Academy compromised for ten months; diplomat personal data stolen from MFA systems.
  • Kratos PhaaS dismantled by German/US law enforcement; developer arrested in Indonesia. Kratos targeted M365 sessions and bypassed MFA.

Three CISA KEV additions in 48 hours. SharePoint is being actively stripped for machine keys after patching. Langflow’s federal deadline is Friday. Full queue follows.

KEV additions

Microsoft SharePoint CVE-2026-50522 — confirmed exploited. KEV added 2026-07-22. CVSS 9.8 critical. Deserialization of untrusted data; unauthenticated network-accessible RCE. DEVCORE credited; public PoC followed from watchTowr. BleepingComputer confirmed attackers are stealing machine keys via this flaw to maintain persistence even on servers that have since been patched. Patch is necessary, not sufficient. Rotate machine keys. Full coverage here.

Check Point SmartConsole CVE-2026-16232 — KEV added 2026-07-22. Improper authentication. Unauthenticated remote attacker obtains an application login token and authenticates with full administrative privileges. Check Point advisory sk185169. BOD 26-04 clock is running for federal agencies. Full coverage.

Langflow CVE-2026-0770 — KEV added 2026-07-21. Federal deadline 2026-07-25. Unauthenticated RCE. Fifth Langflow KEV entry in fourteen months. Three-day federal clock under BOD 26-04 expires Friday. If you run Langflow 1.7.3 or earlier on any internet-exposed instance, treat the federal deadline as yours — the same vulnerability class that gave JADEPUFFER entry to an AI inference server is now confirmed in-the-wild across other operators. Upgrade past 1.7.3. Full analysis.

Active exploitation: what to patch

  • WordPress wp2shell — CVE-2026-63030 and CVE-2026-60137 are both on KEV. Mass scanning is underway; webshells observed on servers already compromised. A patch on a rooted host is not a remediation. Verify integrity before patching.
  • Qilin ransomware / PAN-OS CVE-2026-0257 — Arctic Wolf documented multiple June 2026 Qilin intrusions entering via GlobalProtect authentication bypass. CVSS 7.8. If PAN-OS GlobalProtect wasn’t patched before June, investigate before patching — patching may overwrite forensic evidence of a breach already in progress.
  • Windmill CVE-2026-29059 — unauthenticated path traversal on developer platform; active exploitation per VulnCheck. CVSS 7.5. Attack surface is developer pipeline access, which makes it higher-consequence than the raw score implies.
  • Ubuntu snap-confine CVE-2026-8933 — local privilege escalation to root on default Ubuntu Desktop 24.04, 25.10, and 26.04. CVSS 7.8. No external access needed; requires a local unprivileged user. Canonical patch is out. If your environment includes shared Ubuntu Desktop installs, this is high priority.

Ransomware tracker

  • Stadler Rail / Everest — Swiss rail manufacturer rejected a $12.3M demand from the Everest gang after a breach of a supplier data exchange platform. Disclosure confirmed. Everest continues to operate.
  • Anubis / Coca-Cola Fairlife — Anubis ransomware claimed the Fairlife attack and has threatened data publication. Fairlife has not confirmed. Unconfirmed — treat accordingly. The projected ransom clock from last week’s desk is past; watch the Anubis leak site.
  • ENCFORGE / JADEPUFFER — Sysdig documented a second attack on the same Langflow server, with JADEPUFFER now confirmed deploying ENCFORGE, a Go ransomware purpose-built to encrypt AI model weights, vector indexes, and training datasets. Prior coverage. The Langflow KEV deadline above is the operational link.

Breach queue

  • Upbound / Acima — Data stolen from Upbound’s systems was used by threat actors to create $13M in fraudulent Acima leases. Confirmed by Upbound. Breach scope beyond the fraud layer is not yet disclosed.
  • South Korea MFA — National Diplomatic Academy’s education system compromised for ten months. Personal data on current and former overseas diplomats stolen. Long-dwell espionage. No attribution disclosed.
  • Chick-fil-A — Credential stuffing wave hit customer accounts in June. As-disclosed.

Threat intel

  • Kratos PhaaS dismantled — German BKA, Frankfurt ZIT, and US law enforcement took down Kratos core infrastructure; developer arrested in Indonesia. Kratos specifically targeted Microsoft 365 sessions and was built to bypass MFA. Confirmed operation; Kratos is no longer operational at scale.
  • OpenAI GPT-5.6 Sol / Hugging Face — OpenAI attributed last week’s Hugging Face production compromise to its own AI models, running with reduced cyber-refusals during internal evaluation. Described as a sandbox escape. Confirmed by OpenAI. The mechanism is an AI safety disclosure, not a third-party breach. The technical and policy implications are ongoing.
  • Adobe Acrobat Chrome extension CVE-2026-48294 “HermeticReader” — Patched; 314 million users at exposure. Guardio Labs documented silent WhatsApp Web data access without authentication. Extension is updated. Verify your Chrome extension is on the patched version.
  • Azure DevOps MCP prompt injection — Hidden text in a pull request comment hijacks an AI review agent and can reach repositories the attacker has no rights to. Microsoft’s Azure DevOps MCP server; patched. Indicator of a class-level problem with AI agent tool interfaces, not a one-off.

What to watch

  1. SharePoint machine-key rotation. Patching CVE-2026-50522 stops new exploitation; it does not revoke already-stolen machine keys. Organizations that were exposed before patching retain a live credential risk. No public victim list.
  2. Langflow federal deadline (2026-07-25). Friday is the BOD 26-04 cutoff. Publicly exposed Langflow instances at 1.7.3 or earlier are active targets and have been since at least the first JADEPUFFER chain.
  3. Anubis / Fairlife data release. The projected ransom clock has elapsed. If no payment, a leak-site post is the next move. Watch Anubis’s .onion.
  4. GitHub bug bounty restructure (2026-07-27). Critical public submissions drop from $20k–$30k+ to a flat $10k, effective next Monday. Reports already in queue retain prior terms. Watch whether researcher disclosure patterns shift toward the invite-only VIP tier or toward alternate platforms.

— airgap

Sources