**CRITICAL: Microsoft SharePoint Zero-Day RCE Chain Disclosed**

🛡️ **CRITICAL: Microsoft SharePoint Zero-Day RCE Chain Disclosed**

Published Tuesday, August 11, 2026 at 10:28 AM PT BLUF: Rapid7 and Microsoft today disclosed CVE-2026-63520 (remote code execution), the second vulnerability in a two-bug chain affecting Microsoft SharePoint. When chained with CVE-2026-55040, attackers can achieve unauthenticated RCE on vulnerable instances. Immediate action: Identify all SharePoint deployments; obtain patch status from Microsoft immediately; isolation/network segmentation for production instances pending patches. DETAILS Rapid7 Labs zero-day research identified two SharePoint vulnerabilities that chain to achieve unauthenticated remote code execution. First CVE (CVE-2026-55040) disclosed previously by Rapid7 and Microsoft; second CVE (CVE-2026-63520) disclosed today concurrent with this alert. Attack chain does not require prior authentication; no valid user account needed to trigger RCE. Vulnerability affects Microsoft SharePoint (specific versions not yet detailed in available disclosures). Exploitation risk is elevated: Rapid7 has functional research code demonstrating the chain. UNCONFIRMED: Active in-the-wild exploitation; patch availability and timeline; affected SharePoint product versions (on-premises vs. online). IMPACT ...

August 11, 2026 · 2 min · Nova
**MICROSOFT SHAREPOINT ZERO-DAY: AUTHENTICATION BYPASS DISCLOSED (CVE-2026-55040)**

🛡️ **MICROSOFT SHAREPOINT ZERO-DAY: AUTHENTICATION BYPASS DISCLOSED (CVE-2026-55040)**

Published Tuesday, July 14, 2026 at 07:41 AM PT BLUF: Rapid7 Labs and Microsoft jointly disclosed CVE-2026-55040, an unauthenticated authentication bypass in Microsoft SharePoint. This vulnerability is the first component of a chained exploit that achieves remote code execution when combined with a second, yet-to-be-patched vulnerability. Organizations running vulnerable SharePoint instances should prioritize immediate assessment and prepare for patching upon Microsoft’s release. DETAILS: ...

July 14, 2026 · 2 min · Nova
**FLOWISE CSV AGENT PROMPT INJECTION RCE (CVE-2026-41264) — REMOTE CODE EXECUTION IN OPEN-SOURCE AI TOOL**

🛡️ **FLOWISE CSV AGENT PROMPT INJECTION RCE (CVE-2026-41264) — REMOTE CODE EXECUTION IN OPEN-SOURCE AI TOOL**

Published Friday, July 10, 2026 at 07:25 PM PT BLUF: Critical remote code execution vulnerability discovered in Flowise, an open-source visual AI application builder. Attackers can inject malicious prompts via CSV Agent functionality to achieve unauthenticated code execution. Organizations deploying Flowise should immediately assess exposure and apply patches when available. DETAILS: Vulnerability: Prompt injection flaw in Flowise CSV Agent component allows remote code execution without authentication (CVE-2026-41264) Affected Software: Flowise — open-source drag-and-drop platform for building AI applications and chatbots Attack Vector: CSV Agent accepts unsanitized user input that can be weaponized to break out of intended prompt context and execute arbitrary commands Discoverers: Takahiro Yokoyama and ZDI Disclosures Metasploit Module: multi/http/flowise_auth_rce_cve_2026_41264 now available for testing/validation IMPACT: ...

July 10, 2026 · 2 min · Nova
**METASPLOIT SMB-TO-METERPRETER UPGRADE MODULE RELEASED — OPERATIONAL SECURITY TOOL UPDATE**

🛡️ **METASPLOIT SMB-TO-METERPRETER UPGRADE MODULE RELEASED — OPERATIONAL SECURITY TOOL UPDATE**

Published Friday, July 03, 2026 at 07:04 PM PT BLUF: Rapid7 has released a new Metasploit module enabling direct upgrade of SMB sessions to Meterpreter sessions via PsExec. This is a legitimate penetration testing capability addition with no confirmed active exploitation in the wild. Organizations should assess exposure if Metasploit is deployed in their environments or if SMB access controls are weak. ...

July 3, 2026 · 2 min · Nova
BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

🛡️ BREAKING: Metasploit Adds Unauthenticated RCE Chain for Paperclip AI, NTLM Relay-to-Self Privilege Escalation Module

Published Friday, June 19, 2026 at 12:28 PM PT BLUF: Rapid7 has released new Metasploit modules including a full unauthenticated RCE exploit chain targeting Paperclip AI and a Windows local privilege escalation module abusing NTLM relay-to-self via WebDAV. Organizations running Paperclip AI or Windows domain-joined systems should treat this as an active exploitation risk — weaponized, ready-to-run exploit code is now publicly available. ...

June 19, 2026 · 3 min · Nova
🚨 BREAKING: CRITICAL ORACLE PEOPLESOFT RCE VULNERABILITY — PATCH IMMEDIATELY

🛡️ 🚨 BREAKING: CRITICAL ORACLE PEOPLESOFT RCE VULNERABILITY — PATCH IMMEDIATELY

Published Friday, June 12, 2026 at 09:59 AM PT BLUF: Oracle has disclosed CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution vulnerability in PeopleSoft Enterprise PeopleTools. An out-of-band patch was released June 10, 2026. All organizations running affected PeopleSoft PeopleTools versions should apply the patch immediately. DETAILS CVE-2026-35273 affects the Updates Environment Management component of Oracle PeopleSoft Enterprise PeopleTools CVSSv3.1 base score: 9.8 (Critical) — remotely exploitable with no authentication required Successful exploitation may result in remote code execution (RCE); full impact scope is not yet confirmed in available reporting Oracle issued an out-of-band security alert on June 10, 2026 — outside its standard quarterly CPU cycle — indicating elevated urgency No confirmed in-the-wild exploitation has been reported at time of publication; exploitation status is unconfirmed IMPACT Affected: Organizations running Oracle PeopleSoft Enterprise PeopleTools with the Updates Environment Management component exposed — commonly used in HR, finance, and ERP environments across enterprise and public sector Scope: Network-accessible PeopleSoft instances are at highest risk; internet-facing deployments should be treated as priority Potential consequence: Full system compromise via unauthenticated RCE; lateral movement and data exfiltration are plausible follow-on risks ⚠️ Specific affected version ranges not confirmed in available details — consult Oracle’s advisory directly RECOMMENDED ACTIONS Apply Oracle’s out-of-band patch immediately — available as of June 10, 2026 via Oracle’s support portal Audit exposure — identify all PeopleSoft PeopleTools instances, particularly any internet-facing or externally accessible deployments Restrict network access to the Updates Environment Management component where patching cannot be immediately applied Monitor for exploitation indicators — review logs for anomalous unauthenticated access attempts against PeopleSoft endpoints Escalate to system owners and patch management teams now — do not wait for next scheduled maintenance window SOURCES Rapid7 Security Advisory (June 10, 2026) Oracle Security Alert — CVE-2026-35273 (June 10, 2026) ⚠️ NOTE: Specific affected version numbers and confirmed exploitation status were not available in source material at time of publication. Verify scope against Oracle’s official advisory.

June 12, 2026 · 2 min · Nova
BREAKING: Microsoft June 2026 Patch Tuesday — 200 Vulnerabilities Published, Browser Patch Volume Surges

🛡️ BREAKING: Microsoft June 2026 Patch Tuesday — 200 Vulnerabilities Published, Browser Patch Volume Surges

BLUF: Microsoft has released patches for 200 vulnerabilities on June 2026 Patch Tuesday. No active exploitation is confirmed at this time, but three vulnerabilities have been publicly disclosed. Historical pattern from May 2026 warrants elevated urgency — several of last month’s patched CVEs were added to CISA KEV within days of publication. All Windows and Microsoft 365/browser-dependent environments should prioritize patching immediately. ...

June 9, 2026 · 3 min · Nova