CISO Security Intel

Appliance/firmware & dev supply chain exploitation wave

Appliance/firmware & dev supply chain exploitation wave

Active exploitation of multiple appliance zero-days: SimpleHelp, Ivanti Sentry, Citrix NetScaler, Cisco Unified CM, SharePoint, BlueHammer Defender, FortiBleed, Ubiquiti UniFi, Palo Alto. New: SonicWall SMA1000 zero-days exploited pre-disclosure (CouchDB, WebSocket tunnel, root escalation) by UTA0533. New: Cursor IDE zero-day allows malicious git.exe auto-run via repo opening — supply chain risk for dev teams. New: WordPress Core RCE (wp2shell) critical unauthenticated — public exploits available, exploited within 24h. New: Critical NGINX heap overflow (CVE-2026-42533, CVSS 9.2) with potential RCE; PoC expected. New: FortiSandbox RCEs (CVE-2026-39808, CVE-2026-25089) added to CISA KEV — CISA gives feds until today to patch; structural trust chain collapse risk. New: AnyDesk zero-day (CVE-2026-15682) low-priv DoS. Zoom patches critical account takeover hole. CISA urges immediate SharePoint hardening as three CVEs added to KEV (CVE-2026-56164 remote unauthenticated). New: SharePoint zero-day attack chain survives patching via stolen IIS keys — key rotation and forensic checks necessary. Record Patch Tuesday 722 fixes includes appliance patches. Three Microsoft Defender zero-days (two unpatched) actively exploited — Nightmare Eclipse feud continues. RoguePlanet patched. CISA adds KEVs (JoomShaper, Langflow, Joomlack). New: CVE-2026-47291 Windows HTTP.sys RCE. New: Django SQL injection (CVE-2026-1207) actively exploited. New: Apple emergency patches for two WebKit zero-days. New: Edge RCE CVE-2026-58281. New: Langflow RCE deep-dive. Joomla extension vulns disclosed (12 critical, 4 on KEV). CVE-2023-26360 ColdFusion still actively exploited (97% EPSS). New: Google Chrome two critical updates (three use-after-free CVEs). New: ServiceNow sandbox escape exploited in wild. New: Record 570-patch Tuesday includes appliance patches and live Windows zero-day. New: Additional SharePoint RCE CVE-2026-50522 (CVSS 9.8) under active exploitation with public PoC; attackers stealing IIS machine keys for persistence. Oracle EBS zero-day CVE-2024-46817 actively exploited, Estée Lauder confirms impact. ServiceNow AI Platform RCE exploited days after disclosure. WordPress wp2shell exploited within 24h. Fourth SharePoint zero-day in a month (machine key theft) reinforces sustained campaign. New: Splunk zero-day CVE-2026-20253 (CVSS 9.8, pre-auth RCE via PostgreSQL sidecar) added to CISA KEV with 3-day patch deadline. New: Check Point zero-day (SmartConsole auth bypass CVE-2026-16232) actively exploited, CISA KEV. New: Cisco SD-WAN vulnerability (CVE-2026-20182) actively exploited, requires netadmin privileges. New: Russian APT28 (Laundry Bear) exploiting Zimbra zero-day (CVE-2026-???) for 5 months targeting Western governments. New: Certighost AD CS exploit (public PoC) enables DC impersonation from low-priv user — must-patch for AD CS environments. New: Oracle EBS zero-day CVE-2026-60880 (CVSS 9.8, unauthenticated RCE) in Work in Process module, July CPU patch available. New: FastJson RCE CVE-2026-16723 with public PoC and active exploitation, wide Spring Boot blast radius.

Sources (18)
Updated Jul 26, 2026