CVE-2021-27137, CVE-2026-0770, CVE-2026-12080, CVE-2026-14586, CVE-2026-16232, CVE-2026-26080, CVE-2026-29059, CVE-2026-32665, CVE-2026-40691, CVE-2026-41637, CVE-2026-45659, CVE-2026-50522, CVE-2026-53910, CVE-2026-55973, CVE-2026-55990, CVE-2026-55991, CVE-2026-56145, CVE-2026-56164, CVE-2026-58644, CVE-2026-60137, CVE-2026-62144, CVE-2026-62145, CVE-2026-62994, CVE-2026-63030, CVE-2026-8933
Domains:
99[.]207, 99[.]233, 198[.]182, 10[.]99, 37[.]250, 18[.]137., 126[.]18
Get tomorrow's brief in your inbox
Today: Check Point patches critical zero-day CVE-2026-16232 exploited for full admin access via SmartConsole. Microsoft SharePoint sees fourth exploited vulnerability in a month with CVE-2026-50522 enabling RCE and credential theft. Chaos ransomware deploys new Rust-based msaRAT that tunnels C2 through Chrome DevTools Protocol and WebRTC to evade network detection.
New Check Point Zero-Day Vulnerability Exploited in the Wild (CVE-2026-16232)
Check Point disclosed CVE-2026-16232, a critical authentication bypass in Security Management and Multi-Domain Management products that allows unauthenticated attackers to obtain application login tokens and authenticate with full administrator privileges via SmartConsole. The vulnerability affects environments where Management is exposed directly to the internet without IP restrictions. Check Point confirmed limited exploitation in the wild and has privately notified affected customers. The Qilin ransomware group was recently observed targeting Check Point appliances.
Fourth SharePoint Vulnerability Exploited: CVE-2026-50522
Microsoft SharePoint vulnerability CVE-2026-50522 (CVSS 9.3, EPSS 0.203/97th percentile) is under active exploitation. The critical RCE flaw stems from deserialization of untrusted data, allowing attackers authenticated as Site Owner to execute arbitrary code remotely. Threat actors are stealing SharePoint machine keys via single requests to retain long-term access. This is the fourth SharePoint vulnerability exploited in the past month, following CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659.
Windmill Path Traversal Exploited (CVE-2026-29059)
CVE-2026-29059 (CVSS 7.5, EPSS 0.026/84th percentile) in Windmill developer platform allows unauthenticated path traversal via the get_log_file endpoint. Attackers exploit unsanitized filename parameters using ../ sequences to read arbitrary files including /etc/passwd and environment variables. When SUPERADMIN_SECRET is set, attackers can extract it from /proc/1/environ and use it as a Bearer token for superadmin authentication and arbitrary code execution. VulnCheck observed active exploitation targeting about 170 vulnerable systems across 24 countries.
WordPress WP2Shell Exploitation (CVE-2026-60137, CVE-2026-63030)
Two WordPress Core vulnerabilities collectively known as wp2shell are under active exploitation (both on CISA KEV, due August 4 and July 24). The chain combines unauthenticated REST API batch request route-confusion with SQL injection to achieve administrator access and code execution. No plugins or themes required, making this exploitable on default WordPress installations. Wordfence called this "one of the most significant WordPress Core security events in recent years" due to unauthenticated reachability and large attack surface. VulnCheck verified over two dozen unique PoC exploits as of July 19.
Langflow RCE Exploited (CVE-2026-0770)
CVE-2026-0770 (CVSS score unavailable, EPSS 0.545/99th percentile, CISA KEV due July 24) enables unauthenticated remote code execution in Langflow. KEVIntel detected first exploitation attempts on June 27, 2026, with 137 attempts from 46 unique IPs across 17 countries. Over half the activity (75 attempts from 20 IPs) occurred in the last seven days. Observed payloads include command execution checks, /etc/passwd extraction, AWS credential access, environment variable collection, wget/curl malware downloads, and shell script execution for second-stage payloads.
DD-WRT Buffer Overflow Exploited (CVE-2021-27137)
CVE-2021-27137 (EPSS 0.108/95th percentile, CISA KEV due July 24), a stack-based buffer overflow in DD-WRT, has been added to CISA's KEV catalog. The 2021-vintage vulnerability is now seeing active exploitation in the wild.
Chaos Ransomware Deploys msaRAT with Browser-Based C2
Cisco Talos discovered msaRAT, a new Rust-based remote access trojan used by Chaos ransomware group. The malware establishes C2 exclusively through Chrome DevTools Protocol (CDP), never touching the network directly. msaRAT manipulates the browser via CDP, performs WebRTC signaling through Cloudflare Workers, and establishes a DataChannel using Twilio TURN as relay. The binary contains a Cloudflare Workers endpoint but offloads all HTTP connections to the browser, creating a covert tunnel. Infection chain starts with curl downloads of update_ms.msi from attacker-controlled servers over plain HTTP on port 443, bypassing port-based firewall rules without protocol inspection.
Ransomware Crews Re-Extort Over a Third of Paying Victims
Over a third of ransomware victims who pay initial extortion demands face re-extortion attempts from the same or different groups. Attackers return for second payments after victims demonstrate willingness to pay, effectively treating payment as a signal of future compliance rather than resolution.
Nichirei Ransomware Attack Disrupts Japan Food Supply
RansomHouse ransomware group claimed credit for an attack on Nichirei, a Japan-based frozen-food supplier and logistics firm managing 7,000 refrigerated vehicles from 141 locations. The attack disrupted shipments to approximately 5,000 customers including Kentucky Fried Chicken franchises in Japan, leading to hour cutbacks and warnings of shortages. Nichirei severed internal networks to contain active encryption and lateral movement. The company has largely recovered after implementing security measures with external security firms, transitioning all locations to normal operations by this week.
Kootenai County Ransomware Data Breach
Kootenai County detected ransomware on its computer network on March 30, 2026, and has begun notifying residents whose personal information may have been compromised. The county immediately secured its network and began restoration operations.
SIM Swap and Account Takeover Attack Chain
A coordinated attack combining social engineering, SIM swapping, session hijacking, and credential theft nearly achieved full account takeover of a wireless services account. The attacker established trust through a fake customer satisfaction call with personalized account information, exploited SMS-based one-time passcodes despite carrier warnings never to share codes, obtained the account passcode, and hijacked an active session by forcing the legitimate user's logout during concurrent authentication. The attack failed due to rapid detection and email-based password reset before the attacker could complete takeover. The incident demonstrates that point-in-time authentication is insufficient against identity-focused adversaries and that concurrent sessions from different environments should trigger immediate risk escalation.
Ubuntu snap-confine Local Privilege Escalation (CVE-2026-8933)
CVE-2026-8933 (CVSS 7.8, EPSS 0.001/4th percentile) allows unprivileged users on default Ubuntu Desktop 24.04, 25.10, and 26.04 installations to obtain root access. The vulnerability stems from a race condition in snap-confine during sandbox initialization. The set-capabilities hardening model allows snap-confine to execute with the effective UID of the calling user while retaining near-root capabilities. During sandbox setup, temporary directories and files under /tmp are initially owned by the unprivileged user before ownership transfers to root, creating a window where the caller retains full control. Attackers can mount malicious FUSE filesystems over the temporary scratch directory and create symbolic links pointing to arbitrary system files. By manipulating file permissions before ownership transfer, attackers inject malicious udev rules into /run/udev/rules.d/ and force systemd-udevd to execute arbitrary commands as root.
Check Point Security Management Flaws
Three vulnerabilities patched in Check Point Security Management and Multi-Domain Management products. CVE-2026-16232 (CVSS 9.3, CISA KEV) enables unauthenticated authentication bypass to obtain admin tokens. CVE-2026-62144 (CVSS 9.3) allows unauthenticated remote command execution including run-script and exec-command on Security Gateways. CVE-2026-62145 (CVSS 7.5) enables authenticated read-only Gaia Portal users to execute commands with root privileges. All three affect R77.30 through R82.10.
DNS Server Vulnerabilities in Unbound and Related Software
Multiple DNS server vulnerabilities disclosed affecting Unbound, CoreDNS, HAProxy, and related software. Notable issues include CVE-2026-55973 (stack buffer overflow from dns-error-reporting), CVE-2026-40691 (DNSCrypt over TCP packet of death), CVE-2026-32665 (DNS-over-QUIC DoS via quic-size budget bypass), CVE-2026-55990 (DNSCrypt misconfiguration packet of death), CVE-2026-55991 (DNS-over-QUIC flow-control assertion failure), CVE-2026-62994 (CoreDNS k8s_external AXFR panic), CVE-2026-14586 (libngtcp2 assertion under high concurrency), and CVE-2026-41637 (DNS-over-QUIC query accounting degradation).
Elasticsearch Denial of Service (CVE-2026-56145)
CVE-2026-56145 (EPSS 0.003/21st percentile) is an uncontrolled resource consumption vulnerability in Elasticsearch leading to denial of service.
QEMU Guest Agent Privilege Escalation (CVE-2026-12080)
CVE-2026-12080 (EPSS 0.002/8th percentile) is a local privilege escalation vulnerability in qemu-guest-agent via symlink attack in guest-ssh-add-authorized-keys.
HAProxy Community Edition Loop/Crash (CVE-2026-26080)
CVE-2026-26080 (EPSS 0.004/34th percentile) affects HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3, allowing the service to enter a loop or crash due to varint mishandling. HAProxy Enterprise and ALOHA are also affected.
GNU diffutils Heap Buffer Overflow (CVE-2026-53910)
Heap-based buffer overflow vulnerability disclosed in GNU diffutils.
This week demonstrates the convergence of advanced evasion techniques (Chaos msaRAT's browser-based C2), supply chain impact (Nichirei disrupting 5,000 customers), and the persistence of authentication vulnerabilities as critical infrastructure weaknesses (Check Point, SharePoint, WordPress all exploited via authentication bypasses). The four SharePoint vulnerabilities exploited in one month signals coordinated research or shared intelligence among threat actors. Re-extortion of paying victims validates the security consensus that payment creates persistent risk rather than resolution.