View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical unauthenticated RCE in SharePoint CVE-2026-50522 expected

🚨 ACTIVE EXPLOITATION

  • Critical unauthenticated RCE in SharePoint CVE-2026-50522 expected to see mass exploitation — cyberplace.social
    CVE-2026-50522 is a critical unauthenticated remote code execution vulnerability in SharePoint, a widely exposed internet technology.
    • Applies to SharePoint, a widely exposed internet technology
    • Vulnerability is unauthenticated remote code execution (RCE)
    • Exploit code for CVE-2026-50522 has been publicly posted
    • Experts warn of imminent mass exploitation

🔓 CVEs & KEV

  • CVE-2026-60369 — CVSS 9.9 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60372 — CVSS 9.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-61246 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60455 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60439 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60373 — CVSS 8.8 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60371 — CVSS 8.0 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60370 — CVSS 7.5 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-16632 — WebSocket Frame vulnerability in facil.io
  • CVE-2026-16631 — OS command injection in publint package-manager
  • CVE-2026-60368 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60367 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-60366 — Oracle Platform Security for Java product of Oracle Fusion Middleware
  • CVE-2026-16630 — OS command injection in syncfusion ej2-javascript-ui-controls

🕵️ RESEARCH & DEEP DIVES

  • GitHub pays $100,000 bounty for critical unauthenticated RCE vulnerability CVE-2026-3854 — runtimewire.com
    GitHub awarded a $100,000 bounty for a critical unauthenticated remote code execution flaw affecting all public and private repositories.

    • Vulnerability allows unauthenticated RCE via specially crafted repository URLs
    • Attackers could gain shell access, read secrets, and alter code in transit
    • GitHub patched the flaw within 48 hours and publicly acknowledged the issue and bounty
    • The payout is among the largest in GitHub's Vulnerability Reward Program
  • Russian Hacker Arrested in Thailand; Suno AI Music Generator Hacked Exposing Copyright Data — grahamcluley.com
    A Russian intelligence-linked hacker was arrested in Thailand, and Suno AI's music generator was hacked exposing copyrighted training data.

    • Hacker linked to Russian government arrested during a beach holiday
    • Evidence included 14 separate McNuggets orders
    • Stolen data reveals extent of copyrighted music used to train AI models

📋 ADVISORIES

  • Check Point patches CVE-2026-16232 authentication bypass in SmartConsole — support.checkpoint.com
    Check Point fixed an authentication bypass vulnerability in SmartConsole under active exploitation.
    • Affects Security Management Server and Multi-Domain Security Management Server
    • Allows unauthenticated attackers to obtain login tokens and full admin privileges
    • Affected versions include R77.30 through R82.10 and intermediate releases
    • Exploitation requires internet access to Management Server IP and unrestricted Trusted Clients
    • Known attacker IPs include 151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check