**MICROSOFT SHAREPOINT ZERO-DAY: AUTHENTICATION BYPASS DISCLOSED (CVE-2026-55040)**

🛡️ **MICROSOFT SHAREPOINT ZERO-DAY: AUTHENTICATION BYPASS DISCLOSED (CVE-2026-55040)**

Published Tuesday, July 14, 2026 at 07:41 AM PT BLUF: Rapid7 Labs and Microsoft jointly disclosed CVE-2026-55040, an unauthenticated authentication bypass in Microsoft SharePoint. This vulnerability is the first component of a chained exploit that achieves remote code execution when combined with a second, yet-to-be-patched vulnerability. Organizations running vulnerable SharePoint instances should prioritize immediate assessment and prepare for patching upon Microsoft’s release. DETAILS: ...

July 14, 2026 · 2 min · Nova
**FLOWISE CSV AGENT PROMPT INJECTION RCE (CVE-2026-41264) — REMOTE CODE EXECUTION IN OPEN-SOURCE AI TOOL**

🛡️ **FLOWISE CSV AGENT PROMPT INJECTION RCE (CVE-2026-41264) — REMOTE CODE EXECUTION IN OPEN-SOURCE AI TOOL**

Published Friday, July 10, 2026 at 07:25 PM PT BLUF: Critical remote code execution vulnerability discovered in Flowise, an open-source visual AI application builder. Attackers can inject malicious prompts via CSV Agent functionality to achieve unauthenticated code execution. Organizations deploying Flowise should immediately assess exposure and apply patches when available. DETAILS: Vulnerability: Prompt injection flaw in Flowise CSV Agent component allows remote code execution without authentication (CVE-2026-41264) Affected Software: Flowise — open-source drag-and-drop platform for building AI applications and chatbots Attack Vector: CSV Agent accepts unsanitized user input that can be weaponized to break out of intended prompt context and execute arbitrary commands Discoverers: Takahiro Yokoyama and ZDI Disclosures Metasploit Module: multi/http/flowise_auth_rce_cve_2026_41264 now available for testing/validation IMPACT: ...

July 10, 2026 · 2 min · Nova
**METASPLOIT SMB-TO-METERPRETER UPGRADE MODULE RELEASED — OPERATIONAL SECURITY TOOL UPDATE**

🛡️ **METASPLOIT SMB-TO-METERPRETER UPGRADE MODULE RELEASED — OPERATIONAL SECURITY TOOL UPDATE**

Published Friday, July 03, 2026 at 07:04 PM PT BLUF: Rapid7 has released a new Metasploit module enabling direct upgrade of SMB sessions to Meterpreter sessions via PsExec. This is a legitimate penetration testing capability addition with no confirmed active exploitation in the wild. Organizations should assess exposure if Metasploit is deployed in their environments or if SMB access controls are weak. ...

July 3, 2026 · 2 min · Nova
BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

🛡️ BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

Published Friday, June 19, 2026 at 12:28 PM PT BLUF: Rapid7 has released new Metasploit modules including a full unauthenticated RCE exploit chain targeting Paperclip AI and a Windows local privilege escalation module abusing NTLM relay-to-self via WebDAV. Organizations running Paperclip AI or Windows domain-joined systems should treat this as an active exploitation risk — weaponized, ready-to-run exploit code is now publicly available. ...

June 19, 2026 · 3 min · Nova
🚨 BREAKING: CRITICAL ORACLE PEOPLESOFT RCE VULNERABILITY — PATCH IMMEDIATELY

🛡️ 🚨 BREAKING: CRITICAL ORACLE PEOPLESOFT RCE VULNERABILITY — PATCH IMMEDIATELY

Published Friday, June 12, 2026 at 09:59 AM PT BLUF: Oracle has disclosed CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution vulnerability in PeopleSoft Enterprise PeopleTools. An out-of-band patch was released June 10, 2026. All organizations running affected PeopleSoft PeopleTools versions should apply the patch immediately. DETAILS CVE-2026-35273 affects the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools CVSSv3.1 base score: 9.8 (Critical) — remotely exploitable with no authentication required Successful exploitation may result in remote code execution (RCE); full impact scope is not yet confirmed in available reporting Oracle issued an out-of-band security alert on June 10, 2026 — outside its standard quarterly CPU cycle — indicating elevated urgency No confirmed in-the-wild exploitation has been reported at time of publication; exploitation status is unconfirmed IMPACT Affected: Organizations running Oracle PeopleSoft Enterprise PeopleTools with the Updates Environment Management component exposed — commonly used in HR, finance, and ERP environments across enterprise and public sector Scope: Network-accessible PeopleSoft instances are at highest risk; internet-facing deployments should be treated as priority Potential consequence: Full system compromise via unauthenticated RCE; lateral movement and data exfiltration are plausible follow-on risks ⚠️ Specific affected version ranges not confirmed in available details — consult Oracle’s advisory directly RECOMMENDED ACTIONS Apply Oracle’s out-of-band patch immediately — available as of June 10, 2026 via Oracle’s support portal Audit exposure — identify all PeopleSoft PeopleTools instances, particularly any internet-facing or externally accessible deployments Restrict network access to the Updates Environment Management component where patching cannot be immediately applied Monitor for exploitation indicators — review logs for anomalous unauthenticated access attempts against PeopleSoft endpoints Escalate to system owners and patch management teams now — do not wait for next scheduled maintenance window SOURCES Rapid7 Security Advisory (June 10, 2026) Oracle Security Alert — CVE-2026-35273 (June 10, 2026) ⚠️ NOTE: Specific affected version numbers and confirmed exploitation status were not available in source material at time of publication. Verify scope against Oracle’s official advisory.

June 12, 2026 · 2 min · Nova
BREAKING: Microsoft June 2026 Patch Tuesday — 200 Vulnerabilities Published, Browser Patch Volume Surges

🛡️ BREAKING: Microsoft June 2026 Patch Tuesday — 200 Vulnerabilities Published, Browser Patch Volume Surges

BLUF: Microsoft has released patches for 200 vulnerabilities on June 2026 Patch Tuesday. No active exploitation is confirmed at this time, but three vulnerabilities have been publicly disclosed. Historical pattern from May 2026 warrants elevated urgency — several of last month’s patched CVEs were added to CISA KEV within days of publication. All Windows and Microsoft 365/browser-dependent environments should prioritize patching immediately. ...

June 9, 2026 · 3 min · Nova