SharePoint CVE-2026-50522 is the one to fix first
The top mover this week is CVE-2026-50522, a Microsoft SharePoint remote code execution vulnerability rated Critical at CVSS 9.8. It is listed on the CISA Known Exploited Vulnerabilities catalog, so this is not a patch-eventually item. It is a patch-now item. An EPSS score of 0.571 means the models already see meaningful odds of exploitation activity against unpatched servers.
If you run SharePoint on-premises, treat this as your first task of the day. While you are in the SharePoint patch queue, also look at CVE-2026-55040, a SharePoint Server security feature bypass at CVSS 9.8. It is not on KEV yet, but it carries the same EPSS reading and sits in the same product surface, so bundle it into the same maintenance window.
ColdFusion, Langflow, and two Exchange flaws round out the KEV movers
Outside the Microsoft stack, CVE-2026-48282 is an Adobe ColdFusion path traversal at the maximum CVSS score of 10.0 with an EPSS of 0.9899. That near-certain exploitation probability plus a KEV listing makes it the most urgent non-Microsoft item this week. CVE-2026-55255, a Langflow authorization bypass through a user-controlled key at CVSS 9.9, is also KEV-listed.
On the mail side, CVE-2026-42897 is a Microsoft Exchange Server spoofing vulnerability (High, CVSS 8.8) that is now on KEV. A related Exchange elevation of privilege flaw, CVE-2026-45504, shares the same CVSS 8.8 and EPSS reading but is not yet KEV-listed. Two older entries also resurfaced in the exploited set: CVE-2008-4250, a Windows buffer overflow, and CVE-2007-3010, an Alcatel OmniPCX remote code execution bug at CVSS 9.8. Old CVEs on KEV mean attackers still find unpatched instances, so confirm your inventory does not include them.
What the press is tracking: Zimbra and ServiceNow
Help Net Security and Dark Reading both report Russian state-supported actors exploiting unpatched Zimbra Collaboration Suite servers to steal email, tied to CVE-2025-66376. CISA published a matching advisory (AA26-204A) describing the phishing campaign against Zimbra users, and Australian agencies issued a parallel warning about an ongoing Russian phishing campaign. If you run Zimbra, patch it and review mailbox access.
Help Net Security's week-in-review also flags a ServiceNow pre-auth remote code execution being exploited in the wild and a Hugging Face breach. Rapid7 continues to track the Check Point SmartConsole authentication bypass CVE-2026-16232, which remains under active exploitation. On the operational technology side, CISA released a batch of ICS advisories covering Panduit IntraVUE, Johnson Controls C-CURE 9000 and XAAP Android, and MZ Automation lib60870 and libIEC61850. Route those to your OT owners.
Do this first
Work the KEV-listed items in order of blast radius and exploitation probability.
- Patch SharePoint for CVE-2026-50522, then address CVE-2026-55040 in the same window.
- Patch Adobe ColdFusion for CVE-2026-48282 (CVSS 10.0, EPSS 0.9899) as your top non-Microsoft priority.
- Apply the Langflow fix for CVE-2026-55255 and the Exchange fix for CVE-2026-42897.
- Patch Zimbra against CVE-2025-66376 and review mailbox access given the active Russian campaign.
- Confirm no legacy exposure to CVE-2008-4250 or CVE-2007-3010 remains in your estate.
Confirm your own patch state
The free Microsoft Patch Tracker from Siemserva by Senserva ranks open Microsoft patches by CISA KEV, EPSS, and ransomware linkage, which lines up directly with the SharePoint and Exchange items above. For the ColdFusion and Langflow entries, the Siemserva non-Microsoft exploited-CVE tracker follows CISA KEV additions daily. Every CVE and KB named here has a detail page with the current exploitation picture so you can verify status before you close a ticket.
Sources
- Help Net Security: Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached (2026-07-26)
- Help Net Security: Russian hackers exploit unpatched Zimbra servers to steal emails (2026-07-24)
- Dark Reading: Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets (2026-07-23)
- Rapid7: CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild (2026-07-23)
- CISA Cybersecurity Advisories: Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (2026-07-23)
- defenceconnect.com.au: ASD, National Cyber Security Coordinator warn of ongoing Russian phishing campaign - defenceconnect.com.au (2026-07-24)
- CISA Cybersecurity Advisories: Panduit IntraVUE (2026-07-23)
- CISA Cybersecurity Advisories: Johnson Controls C-CURE 9000 and Victor application server (2026-07-23)
Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-07-26.