Skip to main content
developing↑ EscalatingCyber

Multiple Critical Vulnerabilities Actively Exploited Across Enterprise Software

Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint.

Impact
7.5
Confidence
High
Evidence
6 sig · 3 src
Trajectory
↑ Escalating
Geo
US CN MX
First seen Jul 21·Updated Jul 21·Synthesized Jul 21
Export brief

Assessment

High confidence3/6 signals corroborated across 3 independent sources

Threat actors are actively exploiting critical vulnerabilities in WordPress, ServiceNow, and Microsoft SharePoint. These exploits enable webshell deployment, arbitrary code execution, and persistent access, posing significant risks to server integrity and enterprise environments. The scope of compromise and specific threat actor attribution remain largely uncertain.

Why it matters — Widespread exploitation of these platforms could lead to significant data breaches, operational disruptions, and long-term compromise of critical infrastructure.

Established

  • ·Confirmed: Active exploitation of WordPress wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) to deploy persistent webshells and malicious plugins.
  • ·Confirmed: Active exploitation of a critical pre-authentication sandbox escape vulnerability (CVE-2026-6875) in ServiceNow AI platform, allowing unauthenticated arbitrary code execution.
  • ·Confirmed: Active exploitation of critical Microsoft SharePoint RCE vulnerability (CVE-2026-50522) to steal machine keys and maintain persistent access, even after patching.
  • ·Confirmed: A vulnerability in AWS Kiro AI allows prompt injection via hidden web content, enabling arbitrary code execution and configuration modification.
  • ·Unclear: The full scope of compromise for WordPress and ServiceNow vulnerabilities.
  • ·Unclear: Specific threat actor attribution for the WordPress and ServiceNow exploits.

Indicators to watch

  • Disclosure of specific threat actor attribution for WordPress and ServiceNow exploits.
  • Reports of widespread data exfiltration or significant operational disruptions linked to these vulnerabilities.
  • Further details on the effectiveness of patching efforts against SharePoint persistence mechanisms.
  • Additional vulnerabilities or exploitation campaigns targeting AI-integrated development tools.

Evidence

Confirmed · 3 independent sources · 6 signals · 3 independent sources

Central claimActive exploitation of critical WordPress wp2shell vulnerabilities detected33% on claim · mixed evidence

Corroborated1 · 1 src · best low 54%
Single-source1 · 1 src · best low 58%
Context4 · 2 src · best low 54%

Topics wordpress · vulnerability · webshell · cybersecurity · cve · servicenow · rce · exploit · wp2shell · vulnerabilities · exploited · sharepoint

Discussion

Sign in to add a note, contribute a source, or challenge the assessment.