Multiple Critical Vulnerabilities Actively Exploited Across Enterprise Software
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint.
Assessment
Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.
Why it matters — Widespread exploitation of these platforms could lead to significant data breaches, operational disruptions, and long-term compromise of critical infrastructure.
Established
- ·Confirmed: Active exploitation of WordPress wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) to deploy persistent webshells and malicious plugins.
- ·Confirmed: Active exploitation of a critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow AI platform, allowing unauthenticated arbitrary code execution.
- ·Confirmed: Active exploitation of critical Microsoft SharePoint RCE vulnerability (CVE-2026-50522) to steal machine keys and maintain persistent access, even after patching.
- ·Confirmed: A vulnerability in AWS Kiro AI allows prompt injection via hidden web content, enabling arbitrary code execution and configuration modification.
- ·Unclear: The full scope of compromise for WordPress and ServiceNow vulnerabilities.
- ·Unclear: Specific threat actor attribution for the WordPress and ServiceNow exploits.
Indicators to watch
- →Disclosure of specific threat actor attribution for WordPress and ServiceNow exploits.
- →Reports of widespread data exfiltration or significant operational disruptions linked to these vulnerabilities.
- →Further details on the effectiveness of patching efforts against SharePoint persistence mechanisms.
- →Additional vulnerabilities or exploitation campaigns targeting AI-integrated development tools.
Evidence
Central claim — Active exploitation of critical WordPress wp2shell vulnerabilities detected33% on claim · mixed evidence
- Jul 21Critical SharePoint RCE flaw exploited to steal machine keys
- Jul 21AWS Kiro AI coding tool vulnerable to prompt injection via hidden web content
- Jul 21Active exploitation of SharePoint RCE vulnerability CVE-2026-50522 enables persistent access
- Jul 21Critical pre-authentication sandbox escape vulnerability identified in ServiceNow AI platform
Topics wordpress · vulnerability · webshell · cybersecurity · cve · servicenow · rce · exploit · wp2shell · vulnerabilities · exploited · sharepoint
Discussion
…Sign in to add a note, contribute a source, or challenge the assessment.