All posts

SharePoint RCE Exploited and a ColdFusion CVSS 10 in KEV

The Senserva daily security read, July 19, 2026

SharePoint Server unauthenticated RCE is being exploited now

The most consequential item this week is CVE-2026-58644, an unauthenticated remote code execution vulnerability in Microsoft SharePoint Server. Rapid7 reports it is already exploited in the wild, and SecurityWeek notes exploitation followed soon after disclosure. If you run on-premises SharePoint, treat this as a patch now situation, not a patch eventually one.

This does not sit alone. Tenable's FAQ ties together a wider cluster of actively exploited SharePoint flaws including CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, alongside the 2025 ToolShell-era chain (CVE-2025-49706, CVE-2025-49704, CVE-2025-53770) that attackers have leaned on repeatedly. On-premises SharePoint remains a favorite entry point, so confirm your servers are on current builds and hunt for web shell activity.

KEV hot movers: ColdFusion, Exchange, UniFi

The exploitation charts are led by CVE-2026-48282, an Adobe ColdFusion path traversal flaw rated CVSS 10 and listed on the CISA KEV catalog. Ubiquiti UniFi OS CVE-2026-34910 also carries CVSS 10 with an EPSS score of roughly 0.79, and the older Alcatel OmniPCX CVE-2007-3010 shows an EPSS near 0.98, meaning active exploitation is very likely. All three are KEV-listed, which is the line between routine patching and immediate action.

For Microsoft shops, CVE-2026-42897 is an Exchange Server spoofing vulnerability on the KEV list. It maps to the Exchange update track in this cycle, and KB5094144 for Exchange Server 2019 Cumulative Update 14 is flagged as KEV-related and addresses 8 CVEs. Langflow CVE-2026-55255 and the Joomlack Page Builder CVE-2026-56290 round out the critical KEV entries worth checking if those products are in your estate. CISA added three more known exploited vulnerabilities to the catalog on July 16.

What the press adds this week

Beyond SharePoint, several stories point at edge and endpoint exposure. Dark Reading reports Inc ransomware exploiting SonicWall SMA zero-days. BleepingComputer covers CISA urging federal agencies to patch actively exploited Fortinet FortiSandbox flaws by Sunday, and separately a new Windows LegacyHive zero-day that grants attackers admin privileges.

On the WordPress side, Help Net Security and Rapid7 both flag CVE-2026-63030, dubbed wp2shell, a critical remote code execution vulnerability in WordPress core, plus CVE-2026-60137. If you host WordPress, patch core immediately. CISA also published a run of industrial advisories covering Rockwell Automation, Siemens SICAM 8, AutomationDirect, and SALTO ProAccess Space for teams with OT responsibilities.

Do this first

Prioritize by exploitation evidence, not just severity score. The items below are grounded in this week's KEV listings and active exploitation reports.

  • Patch on-premises SharePoint against CVE-2026-58644 and the related exploited cluster, then hunt for web shells.
  • Apply the Exchange Server 2019 update KB5094144 to close CVE-2026-42897.
  • Remediate the CVSS 10 KEV entries: Adobe ColdFusion CVE-2026-48282 and Ubiquiti UniFi OS CVE-2026-34910.
  • Update WordPress core for CVE-2026-63030 (wp2shell) and CVE-2026-60137.
  • Check Fortinet FortiSandbox and SonicWall SMA against the CISA and ransomware reports.
  • Use the free Microsoft Patch Tracker from Siemserva by Senserva to rank your open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow KEV additions daily. Siemserva also lets you run a full audit of your Microsoft 365, Intune, Defender, and Entra ID environment.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-19.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.