Back to Archive
THREAT INTELLIGENCE BRIEFยทWednesday, July 22, 2026ยทAI-Powered

The immediate focus is on two sets of actively exploited vulnerabilities added to the CISA KEV list.

The immediate focus is on two sets of actively exploited vulnerabilities added to the CISA KEV list. A critical authentication bypass in Palo Alto Networks PAN-OS (CVE-2026-0257) shows a high exploitation probability (EPSS 0.8668) and is being used by the Qilin ransomware group for initial access. Additionally, two vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being exploited at scale to compromise websites. We are also tracking credible reports of active exploitation targeting critical flaws in Microsoft SharePoint and ServiceNow, indicating a high-risk environment for unpatched systems.

62 articles analysed5 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities4
๐Ÿ”’Ransomware1

Article Analyses (5)

Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access

critical
CVE-2026-0257
KEVEPSS 86.7%

Details

A critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect feature is being actively exploited by the Qilin ransomware group. The flaw allows an unauthenticated attacker to bypass all authentication checks, providing initial access to the network. This is a direct precursor to ransomware deployment.

Affected Systems

Palo Alto Networks PAN-OS with GlobalProtect portal or gateway enabled.

Potential Impact

Full network compromise, data exfiltration, and deployment of Qilin ransomware, leading to significant business disruption and financial loss.

Mitigations

Apply all relevant patches from Palo Alto Networks immediately. Per CISA's directive, federal agencies must patch this vulnerability by the due date of 2026-06-01. Hunt for signs of compromise, focusing on anomalous access patterns related to the GlobalProtect portal.

The Hacker NewsDraft Post

Critical wp2shell WordPress flaws exploited to install webshells

critical
CVE-2026-63030CVE-2026-60137
KEVEPSS 8.9%PoC

Details

Two critical vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137 and collectively codenamed 'wp2shell', are being chained by attackers. The combination allows for unauthenticated remote code execution (RCE) on vulnerable WordPress sites. Attackers are conducting mass scanning and exploiting these flaws to install webshells and malicious plugins, enabling persistent access and complete server compromise.

Affected Systems

WordPress Core versions vulnerable to CVE-2026-63030 and CVE-2026-60137.

Potential Impact

Complete compromise of company websites, leading to reputational damage, SEO poisoning, and use of the server for further malicious activities. Customer data may be at risk.

Mitigations

Update to the latest version of WordPress Core immediately. As these vulnerabilities are on the CISA KEV list, they require prompt remediation. Scan web servers for indicators of compromise, such as unexpected files or plugins.

BleepingComputerDraft Post

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

critical
CVE-2026-50522
EPSS 20.3%

Details

Despite not yet appearing on the CISA KEV list, multiple security news outlets report that this critical deserialization vulnerability in SharePoint is under active exploitation. The flaw allows an unauthenticated attacker to achieve remote code execution with a CVSS score of 9.8. Attackers are reportedly using it to steal machine keys, which could allow persistent access even after patching.

Affected Systems

Microsoft Office SharePoint versions affected by CVE-2026-50522.

Potential Impact

Complete compromise of SharePoint servers, leading to exfiltration of sensitive corporate data, intranet compromise, and a persistent foothold in the network.

Mitigations

Apply the July 2026 Patch Tuesday update from Microsoft immediately. Due to reports of active exploitation, this should be treated as an emergency patching priority. Investigate for signs of compromise, particularly focusing on access logs and the integrity of machine keys.

The Hacker NewsDraft Post

Exploitation of ServiceNow Vulnerability Seen Days After Disclosure

high
CVE-2026-6875
EPSS 0.5%PoC

Details

A critical pre-authentication vulnerability in the ServiceNow AI Platform is reportedly being exploited just days after its public disclosure. Public exploit code is available. The flaw can be leveraged by an unauthenticated attacker to achieve remote code execution on the platform.

Affected Systems

ServiceNow AI Platform versions vulnerable to CVE-2026-6875.

Potential Impact

Compromise of the ServiceNow instance, which often contains sensitive IT, employee, and business process data. An attacker could disrupt operations, steal data, or pivot to other connected systems.

Mitigations

Apply the patch from ServiceNow immediately. Review ServiceNow access logs for any anomalous activity originating from unknown IP addresses, especially around the time of the vulnerability's disclosure.

SecurityWeekDraft Post

SonicWall SMA Flaws Lead to KNUCKLEBALL Malware

critical

Details

A zero-day campaign is targeting SonicWall SMA 1000 series appliances. The campaign involves custom malware dubbed KNUCKLEBALL, which provides root-level access to the compromised device. Attackers are using this access to gather credentials and attempt to move laterally into the victim's network.

Affected Systems

SonicWall SMA 1000 series appliances.

Potential Impact

A breach of the network perimeter, providing a foothold for attackers to move laterally, steal credentials, and access internal resources. This can lead to a widespread network compromise.

Mitigations

Monitor SonicWall security advisories for patches. In the interim, organizations should review access logs on SMA appliances for any signs of unauthorized access or unusual activity. Restrict access to the management interface to trusted IP addresses only.

SOC RadarDraft Post
Generated by gemini-2.5-pro