CyberHighConfirmedAccelerating
7.7
Active exploitation of SharePoint RCE vulnerability CVE-2026-50522 enables persistent access
The Hacker News·US·about 4 hours ago
A critical vulnerability (CVE-2026-6875) in the ServiceNow AI platform is currently being exploited in the wild, allowing unauthenticated attackers to execute arbitrary code via a sandbox escape. The extent of the compromise remains uncertain, but the flaw poses a significant risk to self-hosted enterprise environments.
Active exploitation of critical vulnerabilities in WordPress, ServiceNow AI, and Microsoft SharePoint is confirmed. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.