A vulnerability in Check Point’s SmartConsole is being actively exploited in the wild, granting attackers administrator access to the security management platform.
Attackers exploit CVE-2026-50522 to steal machine keys from SharePoint servers, enabling them to generate valid authentication tokens and maintain persistent access even after patching.
An SSRF vulnerability in Cisco Unified CM is being actively exploited in practice and potentially enables root access, making rapid patching or disabling vulnerable services essential.
A critical vulnerability in SimpleHelp remote management software is currently under active attack and requires immediate patching on affected systems.
Three vulnerabilities in Fortinet FortiSandbox (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) are being actively exploited; two were patched since April 2026, the newest only a week old.