Posts Tagged ‘deserialization’
CVE-2026-50522 SharePoint RCE: Patching Isn’t Enough
CVE-2026-50522 SharePoint RCE is now the third actively exploited remote code execution flaw hitting Microsoft’s on-premises collaboration platform in three weeks — and this one lets attackers steal cryptographic machine keys that remain valid long after the server is patched. If you run SharePoint Server 2016, 2019, or Subscription Edition on-premises, patching is no longer…
Read MoreSharePoint RCE CVE-2026-45659: Active Exploits
SharePoint RCE CVE-2026-45659 is now under active exploitation, and the federal patch deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is July 4 — tomorrow. The CVSS 8.8 deserialization flaw lets any authenticated user with nothing more than baseline Site Member permissions run code remotely on the server. Shadowserver currently counts more…
Read MorePTC Windchill RCE CVE-2026-12569: Web Shells Actively Deployed
The PTC Windchill RCE CVE-2026-12569 (CVSS 9.3) is actively exploited — and this is the second attack wave targeting the same product in three months. Attackers are deploying persistent JSP web shells inside Windchill PDMLink and FlexPLM installations right now. CISA added the flaw to its Known Exploited Vulnerabilities catalog on June 25, 2026; the…
Read More
