WordPress Core · ServiceNow AI Platform · SailPoint IdentityIQ
Daily Threat Intelligence Briefing
Date: 2026-07-21 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Active exploitation of the WordPress “wp2shell” RCE chain (CVE-2026-63030 / CVE-2026-60137) is now confirmed with public PoCs circulating — this remains the highest-priority patching action for European organizations. A critical ServiceNow AI Platform RCE (CVE-2026-6875) has moved to active exploitation. SailPoint IdentityIQ carries a new unauthenticated OAuth bypass (CVSS 8.8). Rapid7 has published detailed analysis of an AI-assisted WebDAV malware delivery operation with confirmed IOCs, and a new espionage implant (HollowGraph) is abusing Microsoft 365 calendar as a C2 channel.
Critical Vulnerabilities
CVE-2026-63030 / CVE-2026-60137 — WordPress Core (“wp2shell”, Unauthenticated RCE)
- Severity: Critical
- Technical detail: SQL injection in WordPress Core chained with a second flaw enables unauthenticated remote code execution. No authentication or privileges required. Affects all major WordPress deployments; the combination has been dubbed “wp2shell” by researchers.
- Exploitation status: Actively exploited in the wild. Public PoCs published over the weekend of July 19–20. BSI emergency advisory updated (version 1.1, 2026-07-20) confirming first exploitation reports. SANS ISC confirmed exploitation underway as of July 20.
- Remediation: Patch to WordPress 6.9.5 / 7.0.2 immediately. Verify manually — do not rely on auto-update confirmation. Consider WAF rules blocking SQLi patterns as a temporary compensating control.
CVE-2026-6875 — ServiceNow AI Platform (Unauthenticated RCE)
- Severity: Critical
- Technical detail: A critical code execution vulnerability in the ServiceNow AI Platform is now being actively exploited according to threat intelligence firm Defused. ServiceNow is widely deployed in enterprise IT service management environments, making the attack surface significant. Full technical details are limited in available data.
- Exploitation status: Actively exploited in the wild as of July 20, 2026.
- Remediation: Apply ServiceNow patches immediately. Restrict external access to ServiceNow instances where possible; review access logs for anomalous activity.
CVE-2026-12341 — SailPoint IdentityIQ (Unauthenticated OAuth Bypass)
- Severity: CVSS 8.8
- EPSS: 0 (newly published; score expected to rise)
- Technical detail: Improper validation of OAuth bearer tokens allows an unauthenticated remote attacker to access protected APIs and data. Affects IdentityIQ 8.3 (≤8.3p5), 8.4 (≤8.4p4), and 8.5 (≤8.5p1). IdentityIQ is a privileged identity governance platform; unauthorized API access could expose sensitive identity and access management data across the enterprise.
- Exploitation status: No confirmed in-the-wild exploitation reported.
- Remediation: Apply vendor patches to 8.3p6, 8.4p5, or 8.5p2 as applicable. Audit OAuth token validation configurations and review API access logs for anomalous unauthenticated requests.
CVE-2026-64620 — FreeRDP (Heap Buffer Overflow, Pre-Auth)
- Severity: CVSS 9.3
- Technical detail: A heap-based buffer overflow in
crypto_rsa_common()(libfreerdp/crypto/crypto.c) writes the modular-exponentiation result into an undersized buffer. Exploitable prior to authentication, affecting all FreeRDP versions ≤3.27.1. FreeRDP is widely used in Linux desktop environments and enterprise remote access tooling. - Exploitation status: No confirmed exploitation; EPSS not yet scored.
- Remediation: Upgrade to FreeRDP 3.28.0. Prioritize deployments exposed to untrusted RDP sources.
CVE-2026-50528 — Microsoft .NET (Security Feature Bypass)
- Severity: CVSS 8.2
- EPSS: 0.44 — moderate-to-high exploitation probability
- Technical detail: Security feature bypass affecting .NET 8.0 (< 8.0.29), .NET 9.0 (< 9.0.18), .NET 10.0 (< 10.0.6), and Visual Studio 2022 versions 17.12 and 17.14. Broad enterprise impact given .NET’s ubiquity in Windows application stacks.
- Exploitation status: No confirmed exploitation; EPSS of 0.44 warrants prompt patching.
- Remediation: Apply July 2026 .NET and Visual Studio updates. See also
CVE-2026-47304(.NET Framework security feature bypass, CVSS 8.1) patched in the same cycle.
ONGOING:
CVE-2026-42533(NGINX heap buffer overflow): patch to 1.30.4/1.31.3/Plus R37.0.3.1 — no confirmed exploitation yet.CVE-2026-15409(SonicWall SMA 1000): treat unpatched deployments as compromised; IR review from June 22 onward.CVE-2026-47865/CVE-2026-47871(VMware Avi Load Balancer): unauthenticated RCE chain; patch all branches.CVE-2026-58644(SharePoint Server): CISA KEV deadline passed — escalate any outstanding remediation.CVE-2026-44747(SAP NetWeaver ABAP, CVSS 9.9): patch immediately if not done.CVE-2026-53412(Zoom for Windows, CVSS 9.8): patch to 7.0.0+.
European Advisories
[WID-SEC-2026-2409] WordPress — Critical RCE (BSI, NEW): BSI has published a critical advisory covering CVE-2026-63030 and CVE-2026-60137. Version 1.1 (2026-07-20) confirms public PoCs and first exploitation reports. See Critical Vulnerabilities for full detail. BSI Advisory
[WID-SEC-2026-2418] GitHub Enterprise Server — Multiple Vulnerabilities (BSI, NEW): BSI rates this high. An authenticated remote attacker can cause denial of service, manipulate data, execute code, and disclose information. Apply available GitHub Enterprise Server security updates promptly.
[WID-SEC-2026-2416] Extreme Networks ExtremeXOS — Multiple Vulnerabilities (BSI, NEW): BSI rates this high, covering CVE-2026-8169 (weak random in debug-mode challenge-response, CVSS 8.7) and CVE-2026-8170 (symlink-following privilege escalation via shell utilities, CVSS 8.7). Affects EXOS branches 31.x, 32.x, and 33.x. Patch to 31.7.4, 32.7.4.15, 33.1.100, or 33.7.1 as applicable. BSI Advisory
[WID-SEC-2026-2414] Grafana — File Manipulation (BSI, NEW): An authenticated remote attacker can manipulate files. Apply available Grafana security updates. BSI Advisory
BSI UPDATE advisories (multiple, 2026-07-20): BSI updated advisories for Golang Go (multiple), Apache HTTP Server (multiple), HTTP/2 implementations (DoS), Red Hat OpenShift/RHEL/Ansible/Satellite (multiple), Atlassian suite (Bamboo, Bitbucket, Confluence, Jira), and Kiali for OpenShift Service Mesh. Apply vendor patches per existing remediation guidance; no new CVEs introduced in these updates.
Active Threats and Campaigns
NEW — AI-Assisted WebDAV Malware Delivery (PureRAT / .NET Infostealer): Rapid7 has published detailed analysis of an exposed malware delivery server containing 1,048 artifacts, revealing an operator using LLM-assisted tooling to build and test delivery pipelines at scale. Two active campaigns were identified: a CURP-themed phishing campaign targeting Mexican government ID lookup users (primary impact), and a DlrtyGames DLL-sideloading chain deploying a modular .NET RAT (PureRAT). The operator tested CVE-2025-33053 (Windows working-directory hijack), CVE-2026-21513 (MSHTML bypass), and CVE-2025-24054 (NTLM leak). German IPs generated 2,751 requests to the delivery infrastructure (scanning/research profile, 1 launch event). IOCs: C2 77[.]110[.]127[.]205 (ports 56001–56003, 57666, 57777, 57888), domain google.services[.]ug, phishing domain gobf[.]mx, WebDAV server onedrive[.]cv, SHA256 04A8018191F2E9E76072D072A933371D9D669A42DE2B2A087541CD3A653B0BA7 (RTLO-spoofed .scr), e8be17a7fbef48b45f1e958b3ae5ebdfcad58808969982c431a905eefcae5268 (DlrtyGames.exe). Rapid7 Report
NEW — HollowGraph Espionage Implant (Microsoft 365 Calendar C2): Group-IB has identified HollowGraph, a malware implant that uses hijacked Microsoft 365 mailboxes as a C2 channel — planting operator commands and exfiltrating stolen data as attachments on calendar events dated to year 2050. Traffic blends with legitimate Microsoft Graph API activity, making network-layer detection difficult. Hunt for anomalous Graph API calls, calendar events with future dates (2050), and unexpected large attachments on calendar items.
NEW — FakeGit Campaign (SmartLoader via GitHub): Approximately 7,600 malicious GitHub repositories — over 800 posing as AI tools or MCP servers — are distributing SmartLoader malware. Targets developers and AI practitioners. Enforce repository vetting policies; block execution of code from unverified GitHub sources. The Hacker News
ONGOING — UAC-0145 (Sandworm) ClickFix campaign: Targeting Ukrainian entities; ClickFix delivery technique actively replicated by other actors. Block clipboard-injection lures; alert on mshta.exe/PowerShell spawned from browser processes.
ONGOING — ACR Stealer / NadMesh Botnet / ViteVenom: No material new developments; maintain existing detection and remediation posture.
Security News and Context
Romania land registry wiped: A cybercriminal deleted Romania’s entire national land registry database after a failed extortion attempt, halting the country’s real estate market. Heise Security
Phishing service “Kratos” dismantled: German and US investigators have taken down the infrastructure of the Kratos phishing-as-a-service platform, which enabled thousands of attacks per month against hundreds of thousands of victims. Heise Security
Estée Lauder data breach via Oracle E-Business Suite: Attackers exploited a flaw in Oracle E-Business Suite used for HR operations; customer notifications are underway. Bleeping Computer
Hugging Face breached by autonomous AI agent: The AI model repository confirmed unauthorized access to internal datasets and credentials via an autonomous AI agent attack. Bleeping Computer
AI coding tool sandbox escapes: Cursor, Codex, Gemini CLI, and Antigravity were found vulnerable to sandbox escapes via file-write techniques; multiple CVEs and patches issued. Bleeping Computer
Recommended Actions
- Verify WordPress wp2shell patches applied (6.9.5 / 7.0.2) — active exploitation confirmed; manual verification required on every internet-facing installation (
CVE-2026-63030/CVE-2026-60137). - Patch ServiceNow AI Platform immediately —
CVE-2026-6875is actively exploited; restrict external access and review logs for anomalous activity. - Patch SailPoint IdentityIQ to 8.3p6 / 8.4p5 / 8.5p2 — unauthenticated OAuth bypass (
CVE-2026-12341); audit API access logs. - Upgrade FreeRDP to 3.28.0 — pre-auth heap overflow (
CVE-2026-64620, CVSS 9.3); prioritize internet-facing deployments. - Apply July 2026 .NET / Visual Studio updates —
CVE-2026-50528(EPSS 0.44) andCVE-2026-47304security feature bypasses. - Block HollowGraph IOCs — hunt for anomalous Microsoft Graph API calls and calendar events dated 2050 in M365 environments.
- Ingest WebDAV campaign IOCs — block
77[.]110[.]127[.]205,google.services[.]ug,gobf[.]mx,onedrive[.]cv; alert on scheduled tasks namedbrokerhostornet_queue_32. - Apply GitHub Enterprise Server and Grafana patches — new BSI advisories (WID-SEC-2026-2418, WID-SEC-2026-2414).
- Patch Extreme Networks ExtremeXOS to fixed branch versions — privilege escalation and weak randomness (
CVE-2026-8169/CVE-2026-8170). - Continue remediation of previously reported items: NGINX (
CVE-2026-42533), SonicWall SMA 1000 (CVE-2026-15409— IR if unpatched pre-disclosure), VMware Avi Load Balancer, SharePoint (CVE-2026-58644), SAP NetWeaver ABAP (CVE-2026-44747), Zoom (CVE-2026-53412).