Generated · Archived snapshot 7 findings · 2 CVEs
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are under active exploitation across diverse platforms, with threat actors rapidly weaponizing recently disclosed flaws. A global campaign targeting CVE-2026-59310 in VMware vCenter began earlier this month, while attackers are exploiting CVE-2026-55040 in Microsoft SharePoint following public proof-of-concept release. The North Korean Lazarus Group leveraged a Windows zero-day to deploy a novel backdoor against defense and aerospace targets in four countries as part of Operation Dream Job. Simultaneously, a maximum-severity SAP Commerce Cloud RCE is being attacked within days of patch availability, and macOS Screen Sharing authentication bypass exploitation has prompted a national cyber security center warning.

Financially motivated actors continue to exploit service provider vulnerabilities for large-scale fraud, evidenced by a €30 million bank heist leveraging a flaw at a third-party provider affecting Commerzbank customers. The Akira ransomware group demonstrated advanced defense evasion by abusing Safe Mode to disable EDR solutions. Espionage-focused operations persist, with the Jewelbug APT conducting parallel government targeting and cryptocurrency theft from a shared web panel. Belgium's eID authentication framework was fully compromised through severe browser extension vulnerabilities, exposing citizen accounts to remote code execution.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-59310#

  • Description: A critical vulnerability in VMware vCenter Server that allows remote code execution. Exploitation against this flaw began earlier this month as part of a global threat campaign.
  • Impact: Attackers can achieve remote code execution on vulnerable vCenter servers, potentially leading to full compromise of virtualized infrastructure.
  • Status: Actively exploited in a global campaign; patching may not be sufficient to fully mitigate the threat.

CriticalActive exploitationPatchCVE-2026-55040#

  • Description: A critical security feature bypass vulnerability (CVSS 9.1) stemming from weak authentication in Microsoft SharePoint. The flaw was patched in July 2026 Patch Tuesday updates, but threat actors began exploitation following public proof-of-concept code release.
  • Impact: Attackers can bypass authentication mechanisms to gain unauthorized access to SharePoint environments, potentially accessing sensitive documents and data.
  • Status: Actively exploited in the wild after PoC publication; patch available since July 2026.

CriticalActive exploitationPatch#

  • Description: A maximum-severity remote code execution vulnerability in SAP Commerce Cloud that was patched three days before active targeting was observed by threat intelligence firm Defused.
  • Impact: Successful exploitation allows remote code execution on SAP Commerce Cloud instances, potentially leading to full application and data compromise.
  • Status: Actively targeted in attacks within days of patch release.

HighActive exploitationPatch#

  • Description: An authentication bypass vulnerability in macOS Screen Sharing functionality. Public exploit code has emerged, and the Netherlands' National Cyber Security Centre (NCSC) has issued a warning about active exploitation.
  • Impact: Attackers can bypass authentication to gain unauthorized remote access to macOS systems, currently being used to deploy Monero cryptocurrency miners.
  • Status: Actively exploited in the wild with public exploit code available; NCSC warning issued.

CriticalActive exploitationPatch#

  • Description: A newly patched security flaw in Microsoft Windows exploited as a zero-day by the North Korean Lazarus Group. The vulnerability allows elevation to SYSTEM privileges and was used to deploy a never-before-seen backdoor.
  • Impact: Attackers gain SYSTEM-level access on compromised Windows hosts and deploy persistent backdoors for espionage targeting defense and aerospace sectors.
  • Status: Zero-day exploitation confirmed; patch now available; attributed to Operation Dream Job campaign.

CriticalObservedInvestigate#

  • Description: Severe vulnerabilities in a key browser extension underlying Belgium's electronic ID trust framework, fully compromising the authentication system and enabling remote code execution on citizen accounts.
  • Impact: Complete compromise of the eID trust framework, allowing remote code execution on citizen accounts and exposing broader systemic issues with browser extension security.
  • Status: Vulnerabilities identified and framework fully compromised; highlights systemic extension security problems.

HighActive exploitationInvestigate#

  • Description: A vulnerability at a service provider exploited by cybercriminals to withdraw funds from Commerzbank customer accounts, resulting in €30 million in fraud across Brazil and Europe.
  • Impact: Unauthorized financial transactions and fund withdrawal from victim bank accounts via compromised service provider infrastructure.
  • Status: Actively exploited for financial fraud; four arrests in Brazil, three charged in Europe.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities