← All briefings

Microsoft SharePoint Server · Palo Alto Networks PAN-OS GlobalProtect · Langflow

Date: 2026-07-22 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Three high-priority developments dominate today’s briefing: CVE-2026-50522 (Microsoft SharePoint deserialization RCE, CVSS 9.8) has moved to active exploitation with attackers stealing machine keys to maintain persistent access post-patch. The Qilin ransomware group is confirmed exploiting CVE-2026-0257 (PAN-OS authentication bypass) for initial access. A new ENCFORGE ransomware targeting AI infrastructure files is being deployed via the Langflow RCE (CVE-2026-0770), now on the CISA KEV. German and US authorities have dismantled the Kratos phishing-as-a-service platform.


Critical Vulnerabilities

CVE-2026-50522 — Microsoft SharePoint Server (Unauthenticated RCE)

  • Severity: CVSS 9.8
  • Technical detail: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthenticated, network-adjacent attacker to execute arbitrary code. Critically, attackers are observed stealing machine keys from compromised servers — enabling persistent forged ViewState payloads that survive patching and allow re-exploitation of already-patched systems. Credited to DEVCORE; a public PoC is now circulating.
  • Exploitation status: Actively exploited in the wild. Machine key theft confirmed as a post-exploitation persistence technique.
  • Remediation: Apply July 2026 Patch Tuesday SharePoint updates immediately. After patching, rotate machine keys and audit web.config for unauthorized key material. Review IIS logs for deserialization-pattern requests. Note: patching alone is insufficient if machine keys have already been exfiltrated.

CVE-2026-0257 — Palo Alto Networks PAN-OS GlobalProtect (Authentication Bypass → Ransomware)

  • Severity: CVSS 7.8
  • Technical detail: Authentication bypass affecting the PAN-OS GlobalProtect portal and gateway. Arctic Wolf Labs investigated multiple intrusions in June 2026 where this flaw served as the initial access vector, with Qilin (aka Agenda) ransomware deployed as the final payload. The vulnerability requires no credentials and is network-exploitable against internet-facing VPN infrastructure.
  • Exploitation status: Actively exploited by Qilin ransomware operators. Multiple confirmed intrusions documented.
  • Remediation: Apply available PAN-OS patches immediately. Review GlobalProtect access logs from June 2026 onward for signs of unauthorized authentication. Treat unpatched internet-facing GlobalProtect instances as potentially compromised.

CVE-2026-0770 — Langflow (Unauthenticated RCE / ENCFORGE Ransomware Delivery)

  • Severity: Critical (CWE-829: Inclusion of Functionality from Untrusted Control Sphere)
  • Technical detail: Langflow’s inclusion of functionality from an untrusted control sphere allows remote attackers to execute arbitrary code without authentication. Sysdig researchers have linked active exploitation to the JADEPUFFER threat operator, which is now deploying ENCFORGE — a compiled Go ransomware specifically designed to encrypt AI model weights, vector indexes, training datasets, and other AI infrastructure files. This represents a novel ransomware targeting pattern for AI/ML environments.
  • Exploitation status: Actively exploited. CISA KEV added 2026-07-21; due date 2026-07-24.
  • Remediation: Patch Langflow immediately. Isolate Langflow instances from production AI infrastructure. Audit for ENCFORGE indicators; inventory AI model file storage locations as high-value targets.

CVE-2026-63030 / CVE-2026-60137 — WordPress Core (“wp2shell”)

  • STATUS CHANGE: Both CVEs added to CISA KEV on 2026-07-21 (due dates: CVE-2026-63030 by 2026-07-24; CVE-2026-60137 by 2026-08-04). Exploitation is confirmed to include persistent webshell installation and malicious plugin deployment. Mass scanning activity is accelerating following public PoC release.
  • Patch to WordPress 6.9.5 / 7.0.2 immediately; verify manually. Scan for webshells and unauthorized plugins on all WordPress installations.

CVE-2026-6875 — ServiceNow AI Platform (Unauthenticated RCE)

  • STATUS CHANGE: No new technical detail, but exploitation activity continues to be observed in the wild. Full entry covered in yesterday’s report.
  • Patch immediately; restrict external access; review logs for anomalous sandbox-escape activity.

ONGOING:

  • CVE-2026-12341 (SailPoint IdentityIQ): unauthenticated OAuth bypass; patch to 8.3p6/8.4p5/8.5p2 — no confirmed exploitation yet.
  • CVE-2026-64620 (FreeRDP): pre-auth heap overflow; upgrade to 3.28.0.
  • CVE-2026-50528 (Microsoft .NET): security feature bypass, EPSS 0.44; apply July 2026 updates.
  • CVE-2021-27137 (DD-WRT): stack-based buffer overflow added to CISA KEV 2026-07-21 (due 2026-07-24); patch or replace affected routers.
  • CVE-2026-42533 (NGINX): heap buffer overflow; patch to 1.30.4/1.31.3/Plus R37.0.3.1.
  • CVE-2026-15409 (SonicWall SMA 1000): treat unpatched deployments as compromised.
  • CVE-2026-44747 (SAP NetWeaver ABAP, CVSS 9.9): patch immediately if not done.

European Advisories

BSI — Synacor Zimbra: Multiple Vulnerabilities `WID-SEC-2026-2429` (NEW, rated *hoch*): BSI has published a new advisory covering multiple Zimbra vulnerabilities patched in version 10.1.20. The most critical is a command injection flaw in the SNMP monitoring component, exploitable when SNMP notifications are enabled. Additional issues include four XSS vulnerabilities, security control bypasses, and information disclosure. Zimbra is widely deployed in European public-sector and enterprise email environments. Apply the Zimbra 10.1.20 update immediately; disable SNMP notifications as a compensating control if patching is delayed.

BSI UPDATE advisories — GNU libc and Samba (rated *kritisch*): BSI updated advisories `WID-SEC-2026-1190` (GNU libc: file manipulation, DoS, unspecified attacks) and `WID-SEC-2026-1686` (Samba: arbitrary code execution, DoS, file manipulation, security bypass). Both rated critical. Apply available distribution-level patches for glibc and Samba packages promptly.

BSI UPDATE advisories — Linux Kernel (multiple, rated *hoch*): BSI updated eleven Linux Kernel advisories covering DoS, privilege escalation, code execution, and memory corruption across multiple kernel branches. Apply current distribution kernel updates. No new CVEs introduced in these updates.

BSI UPDATE advisories — NGINX Plus, GnuTLS, Rsync, Golang Go, Red Hat (python-pip, Ansible Automation Platform), vllm: Routine updates to existing advisories; apply vendor patches per prior guidance.

Oracle Critical Patch Update — July 2026 (EUVD): Oracle published a large batch of critical and high-severity advisories covering Oracle Commerce Platform/Guided Search/Experience Manager, Oracle WebCenter Sites, Oracle Identity Manager (12.2.1.4.0 / 14.1.2.1.0), Oracle Agile PLM (9.3.6), Oracle Agile PLM for Process (6.2.4), Oracle Database Server (19.x / 23.x), PeopleSoft Enterprise (multiple modules, versions 9.1/9.2), Oracle Communications products, and Oracle Product Lifecycle Analytics. Multiple entries carry CVSS scores of 9.8–9.9 with unauthenticated network attack vectors. Apply Oracle July 2026 CPU patches across all affected product lines. Prioritize Oracle Identity Manager and Oracle Database Server given their privileged roles in enterprise environments.


Active Threats and Campaigns

NEW — Qilin Ransomware via PAN-OS (`CVE-2026-0257`): Arctic Wolf Labs has confirmed Qilin ransomware operators are exploiting the PAN-OS GlobalProtect authentication bypass as an initial access vector. Multiple intrusions were investigated in June 2026. Full detail in Critical Vulnerabilities above.

NEW — ENCFORGE Ransomware Targeting AI Infrastructure (via Langflow): The JADEPUFFER operator is deploying ENCFORGE — a Go-compiled ransomware targeting AI model weights, vector indexes, and training datasets — via CVE-2026-0770. This is a novel targeting pattern for AI/ML infrastructure. Full detail in Critical Vulnerabilities above.

NEW — FakeGit Campaign (SmartLoader / StealC via GitHub): Approximately 7,600 malicious GitHub repositories — over 800 masquerading as AI tools or MCP servers — have accumulated more than 14 million downloads and are distributing SmartLoader and StealC malware. Primarily targets developers and AI practitioners. Enforce repository vetting; block execution of code from unverified GitHub sources. Bleeping Computer

NEW — Kratos PhaaS Dismantled: German and US authorities dismantled the Kratos phishing-as-a-service platform and arrested its developer in Indonesia. Kratos enabled thousands of attacks monthly against hundreds of thousands of victims globally. Bleeping Computer

ONGOING — AI-Assisted WebDAV Malware Delivery (PureRAT / JADEPUFFER): No material new developments; maintain IOC blocks and detections per yesterday’s report.

ONGOING — HollowGraph (M365 Calendar C2): No new developments; continue hunting for anomalous Graph API calls and calendar events dated 2050.

ONGOING — UAC-0145 (Sandworm) ClickFix campaign: No material change; maintain detections.


Security News and Context

SharePoint machine key theft: Attackers exploiting CVE-2026-50522 are stealing machine keys to maintain persistent access even after patching — organizations should treat key rotation as a mandatory post-patch step. Bleeping Computer

Anubis ransomware claims Coca-Cola Fairlife attack: The Anubis ransomware group has claimed responsibility for an attack on Coca-Cola’s Fairlife subsidiary, which has halted production; a data leak is threatened. Heise Security

Nextcloud cyberattack confirmed: Nextcloud confirmed a cyberattack on its web servers caused a temporary outage on July 20; investigation ongoing. Heise Security

Suno data breach — 55 million accounts: Have I Been Pwned has added 55 million accounts from the Suno AI music platform breach. Heise Security

BaFin fines TeamViewer €240,000 following the 2024 cyberattack, citing inadequate security controls. Heise Security


  1. Patch SharePoint immediately and rotate machine keysCVE-2026-50522 is actively exploited; patching alone is insufficient if keys were already stolen. Audit web.config for unauthorized key material.
  2. Patch PAN-OS GlobalProtectCVE-2026-0257 is being exploited by Qilin ransomware; review access logs from June 2026 onward for unauthorized authentication.
  3. Patch Langflow and isolate AI infrastructureCVE-2026-0770 (CISA KEV, due 2026-07-24) is being used to deploy ENCFORGE ransomware targeting AI model files.
  4. Apply Zimbra 10.1.20 update — SNMP command injection and XSS vulnerabilities; disable SNMP notifications if patching is delayed (BSI WID-SEC-2026-2429).
  5. Apply Oracle July 2026 CPU patches — prioritize Oracle Identity Manager and Oracle Database Server (CVSS 9.8–9.9, unauthenticated network vectors).
  6. Patch DD-WRTCVE-2021-27137 added to CISA KEV (due 2026-07-24); replace end-of-life devices where patching is not possible.
  7. Apply glibc and Samba patches — BSI critical-rated updates; prioritize Linux-based servers and Samba file-sharing infrastructure.
  8. Enforce GitHub repository vetting — FakeGit campaign has distributed SmartLoader/StealC via 7,600 malicious repos; block execution of unverified code.
  9. Verify WordPress wp2shell patches and scan for webshells — CISA KEV deadline for CVE-2026-63030 is 2026-07-24; check for unauthorized plugins and webshells on all installations.
  10. Continue remediation of previously reported items: SailPoint IdentityIQ (CVE-2026-12341), FreeRDP (CVE-2026-64620), .NET (CVE-2026-50528), NGINX (CVE-2026-42533), SonicWall SMA 1000 (CVE-2026-15409), SAP NetWeaver ABAP (CVE-2026-44747).