Channel created
Channel photo updated
🚨 CVE-2026-45659 — SharePoint Server RCE (CVSS 8.8)

Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.

Microsoft patched this quietly in May — the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.

Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.

Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation

#CVE #SharePoint #CISAKEV #VulnerabilityManagement
🔴 CVE-2026-56155 — AD FS Privilege Escalation, Actively Exploited
Local attacker with low privileges → admin, on Microsoft AD FS servers. CVSS 7.8. Microsoft confirmed exploitation in the wild; ZDI says it chains well with RCE for ransomware. No public PoC yet, but that hasn't stopped active use.
Affected: AD FS on Windows Server 2012–2025 and related Server Core builds.

Full writeup: https://exploitgrid.net/blogs/cve-2026-56155-ad-fs-privilege-escalation-bug-is-already-being-exploited

#ADFS #CISAKEV
🚨 CRITICAL: Metabase RCE — CVE-2026-59827
CVSS 9.9
⚠️ Unsafe deserialization in H2 query handling → authenticated users can get full RCE
🎯 Target: default Sample DB (ships in every Metabase install)
🔧 How: SELECT X'...'::OTHER smuggles a malicious payload into ObjectInputStream.readObject()
📌 Affected:

OSS 0.58.0 – 0.61.1.3
Enterprise 1.58.0 – 1.61.1.3

Fix: Upgrade to 0.61.1.4+ / 1.61.1.4+
🩹 Can't patch now? Revoke native query perms on H2 DBs
🔗 Also check CVE-2026-59826 (H2 connection string RCE), dropped same day
🧪 We reproduced this in an isolated lab to validate patch behavior — full writeup with gadget chains + lab setup:
👉 https://exploitgrid.net/blogs/cve-2026-59827-vuln-and-exploit-working
⚖️ Lab research, defensive purpose only — don't test this on systems you don't own/have permission for.
#Metabase #CVE #RCE #InfoSec
🔴 CVE-2026-9810 | CVSS 9.8

AI Copilot WordPress Plugin — OAuth token binding failure grants unauthenticated admin access.

▪️ Affected: < 1.5.4
▪️ Fixed: 1.5.4
▪️ Auth required: None

Public exploit details are available. Full technical breakdown, detection queries, and remediation steps on ExploitGrid.

🔗 exploitgrid.net/blogs/cve-2026-9810-unauthenticated-rce
🛡️ ExploitGrid Daily Threat Digest
Today: 1374 CVEs, 189 exploits, 570 critical, 189 with public PoCs

Top Highlights:
[CVE] CVE-2026-47056 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-47056

[CVE] CVE-2026-60217 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60217

[CVE] CVE-2026-60358 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60358

[CVE] CVE-2026-60360 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60360

[CVE] CVE-2026-60365 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60365

+1558 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 199 CVEs, 189 exploits, 49 critical, 189 with public PoCs

Top Highlights:
[CVE] CVE-2026-60366 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60366

[CVE] CVE-2026-60369 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60369

[CVE] CVE-2026-2395 [HIGH PRIORITY]
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform

[CVE] CVE-2026-60367 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60367

[CVE] CVE-2026-60372 [HIGH PRIORITY]
Vulnerability Record: CVE-2026-60372

+383 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 205 CVEs, 101 exploits, 47 critical, 104 with public PoCs

Top Highlights:
[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

[CVE] CVE-2026-62144 [CRITICAL/PoC]
Management Authentication Bypass and Privilege Escalation
⚠️ Recorded Exploit Available

[CVE] CVE-2026-60366 [HIGH PRIORITY]

[CVE] CVE-2026-60369 [HIGH PRIORITY]

[CVE] CVE-2026-2395 [HIGH PRIORITY]
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform

+301 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 205 CVEs, 101 exploits, 47 critical, 104 with public PoCs

Top Highlights:
[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

[CVE] CVE-2026-62144 [CRITICAL/PoC]
Management Authentication Bypass and Privilege Escalation
⚠️ Recorded Exploit Available

[CVE] CVE-2026-60366 [HIGH PRIORITY]

[CVE] CVE-2026-60369 [HIGH PRIORITY]

[CVE] CVE-2026-2395 [HIGH PRIORITY]
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform

+301 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 205 CVEs, 101 exploits, 47 critical, 104 with public PoCs

Top Highlights:
[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

[CVE] CVE-2026-62144 [CRITICAL/PoC]
Management Authentication Bypass and Privilege Escalation
⚠️ Recorded Exploit Available

[CVE] CVE-2026-60366 [HIGH PRIORITY]

[CVE] CVE-2026-60369 [HIGH PRIORITY]

[CVE] CVE-2026-2395 [HIGH PRIORITY]
SQLi in Xpoda Türkiye Informatics Technology's No Code Platform

+301 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 209 CVEs, 101 exploits, 44 critical, 104 with public PoCs

Top Highlights:
[EXPLOIT] EGE-GH-lPXYcAr [CRITICAL/PoC]
log4shell-vulnerable-app

[EXPLOIT] EGE-GH-Ixho1eK [CRITICAL/PoC]
keycloak__keycloak_CVE-2022-4361_21-1-1

[EXPLOIT] EGE-GH-kQ3GEHY [CRITICAL/PoC]
CVE-2022-4361

[EXPLOIT] EGE-GH-86ioQWk [CRITICAL/PoC]
Report-XZ-Utils-CVE-2024-3094

[EXPLOIT] EGE-GH-2h00wb7 [CRITICAL/PoC]
CVE-2024-9264

+305 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 216 CVEs, 101 exploits, 46 critical, 104 with public PoCs

Top Highlights:
[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

[CVE] CVE-2026-62144 [CRITICAL/PoC]
Management Authentication Bypass and Privilege Escalation
⚠️ Recorded Exploit Available

[CVE] CVE-2026-62145 [HIGH PRIORITY]
Local Privilege Escalation in Gaia Portal
⚠️ Recorded Exploit Available

[CVE] CVE-2026-60366 [HIGH PRIORITY]

[CVE] CVE-2026-60369 [HIGH PRIORITY]

+312 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 216 CVEs, 101 exploits, 46 critical, 104 with public PoCs

Top Highlights:
[EXPLOIT] EGE-GH-lPXYcAr [CRITICAL/PoC]
log4shell-vulnerable-app

[EXPLOIT] EGE-GH-Ixho1eK [CRITICAL/PoC]
keycloak__keycloak_CVE-2022-4361_21-1-1

[EXPLOIT] EGE-GH-kQ3GEHY [CRITICAL/PoC]
CVE-2022-4361

[EXPLOIT] EGE-GH-86ioQWk [CRITICAL/PoC]
Report-XZ-Utils-CVE-2024-3094

[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

+312 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 216 CVEs, 101 exploits, 46 critical, 104 with public PoCs

Top Highlights:
[EXPLOIT] EGE-GH-lPXYcAr [CRITICAL/PoC]
log4shell-vulnerable-app

[EXPLOIT] EGE-GH-Ixho1eK [CRITICAL/PoC]
keycloak__keycloak_CVE-2022-4361_21-1-1

[EXPLOIT] EGE-GH-kQ3GEHY [CRITICAL/PoC]
CVE-2022-4361

[EXPLOIT] EGE-GH-86ioQWk [CRITICAL/PoC]
Report-XZ-Utils-CVE-2024-3094

[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

+312 more threats tracked today →
🛡️ ExploitGrid Daily Threat Digest
Today: 216 CVEs, 101 exploits, 46 critical, 104 with public PoCs

Top Highlights:
[EXPLOIT] EGE-GH-lPXYcAr [CRITICAL/PoC]
log4shell-vulnerable-app

[EXPLOIT] EGE-GH-Ixho1eK [CRITICAL/PoC]
keycloak__keycloak_CVE-2022-4361_21-1-1

[EXPLOIT] EGE-GH-kQ3GEHY [CRITICAL/PoC]
CVE-2022-4361

[EXPLOIT] EGE-GH-86ioQWk [CRITICAL/PoC]
Report-XZ-Utils-CVE-2024-3094

[CVE] CVE-2026-16232 [CRITICAL/PoC]
Authentication Bypass in the SmartConsole Login Process Using an Application ...
⚠️ Recorded Exploit Available

+312 more threats tracked today →