A fourth SharePoint vulnerability, CVE-2026-50522, is under active attack to steal machine keys. CISA also added four flaws to the KEV catalog on July 21.
Adobe ColdFusion path traversal CVE-2026-48282 scores CVSS 10 and is on the CISA KEV list, joining ServiceNow and Exchange flaws under active exploitation.
Adobe ColdFusion path traversal CVE-2026-48282 (CVSS 10) is now CISA KEV listed, alongside a UniFi OS flaw and an actively exploited SharePoint RCE.
Microsoft SharePoint RCE CVE-2026-58644 is exploited in the wild while Adobe ColdFusion CVE-2026-48282 sits at CVSS 10 on the CISA KEV list. Patch now.
Run 650+ Microsoft 365, Intune, Defender, Entra ID, and Purview security checks against a free demo tenant, no cost, no agents.
Get startedPatching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.
Deep security commentary and research notes on Microsoft 365, Intune, Defender, Entra ID (logs included), patch state, CVEs, and Purview, plus behind-the-scenes posts on Senserva Trustworthy AI. Longer articles live on Substack: Senserva on Substack and Mark Shavlik's Substack.
We use Google Analytics cookies to understand site traffic. No findings, scan data, or tenant data are sent. Privacy policy.