Generated · Archived snapshot 7 findings · 2 CVEs
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are being actively exploited in the wild across diverse technology stacks, including VMware vCenter, Microsoft SharePoint, Windows, SAP Commerce Cloud, and macOS. The VMware vCenter Syslog Server RCE (CVE-2026-59310) has triggered a global threat campaign with attackers deploying reverse SSH tunnels for persistence, while Microsoft SharePoint's authentication bypass (CVE-2026-55040) is being exploited following public PoC release.

A Windows zero-day known as LegacyHive was patched in July 2026 Patch Tuesday and immediately exploited by North Korea's Lazarus Group in Operation Dream Job targeting defense and aerospace organizations across four countries.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-59310#

  • Description: A critical remote code execution vulnerability in VMware vCenter Syslog Server that allows unauthenticated attackers to execute arbitrary code on affected systems.
  • Impact: Attackers gain full control of the vCenter server, enabling deployment of reverse SSH tools for persistent remote access and lateral movement within virtualized infrastructure.
  • Status: Actively exploited in a global threat campaign; patches available but may not fully mitigate threat if compromise already occurred.

CriticalActive exploitationPatchCVE-2026-55040#

  • Description: A critical security feature bypass vulnerability (CVSS 9.1) stemming from weak authentication in Microsoft SharePoint, patched as part of July 2026 Patch Tuesday.
  • Impact: Attackers can bypass authentication mechanisms to gain unauthorized access to SharePoint environments, potentially accessing sensitive documents, sites, and connected systems.
  • Status: Actively exploited following public proof-of-concept code release; patch available since July 2026 Patch Tuesday.

CriticalActive exploitationPatch#

  • Description: A Windows zero-day vulnerability dubbed "LegacyHive" that was actively exploited before being patched in Microsoft's July 2026 Patch Tuesday release.
  • Impact: Provides attackers with SYSTEM-level access on compromised Windows systems, enabling deployment of backdoors and full system compromise.
  • Status: Patched in July 2026 Patch Tuesday; confirmed exploited by Lazarus Group in Operation Dream Job campaign.

CriticalActive exploitationPatch#

  • Description: A maximum-severity remote code execution vulnerability in SAP Commerce Cloud that was patched only three days before active exploitation was observed.
  • Impact: Unauthenticated remote code execution allowing full compromise of SAP Commerce Cloud instances and potential access to connected business systems and customer data.
  • Status: Patch available; active targeting confirmed by threat intelligence within days of patch release.

HighActive exploitationPatch#

  • Description: An authentication bypass vulnerability in macOS Screen Sharing that allows unauthorized remote access; public exploit code has emerged.
  • Impact: Attackers can bypass authentication to gain remote desktop access, currently being used to deploy Monero cryptocurrency miners on compromised systems.
  • Status: Actively exploited in the wild per NCSC-NL warning; public exploit code available.

CriticalObservedMitigate#

  • Description: Severe vulnerabilities in a key browser extension underlying Belgium's electronic ID (eID) authentication system that fully compromise the trust framework.
  • Impact: Remote code execution enabling takeover of citizen accounts authenticated through the eID system, exposing identity theft and unauthorized access to government services.
  • Status: Vulnerabilities disclosed; trust framework fully compromised.

HighObservedInvestigate#

  • Description: A vulnerability at a third-party service provider exploited to withdraw funds from Commerzbank customer accounts, resulting in €30M fraud.
  • Impact: Unauthorized financial transactions and account takeover at scale across bank customers; four arrests in Brazil and charges in Europe.
  • Status: Law enforcement action taken; vulnerability exploited for financial fraud.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities