๐จ CVE-2026-45659 โ SharePoint Server RCE (CVSS 8.8)
Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.
Microsoft patched this quietly in May โ the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.
Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.
Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation
#CVE #SharePoint #CISAKEV #VulnerabilityManagement
Confirmed actively exploited. Added to CISA's Known Exploited Vulnerabilities catalog on July 1.
Microsoft patched this quietly in May โ the security bulletin wasn't published until three weeks later. Root cause: unsafe deserialization. An attacker only needs Site Member access, not admin.
Affected: SharePoint Server Subscription Edition, 2019, and Enterprise 2016.
Full breakdown + patch guidance:
https://exploitgrid.net/blogs/cve-2026-45659-sharepoint-rce-active-exploitation
#CVE #SharePoint #CISAKEV #VulnerabilityManagement
๐ด CVE-2026-56155 โ AD FS Privilege Escalation, Actively Exploited
Local attacker with low privileges โ admin, on Microsoft AD FS servers. CVSS 7.8. Microsoft confirmed exploitation in the wild; ZDI says it chains well with RCE for ransomware. No public PoC yet, but that hasn't stopped active use.
Affected: AD FS on Windows Server 2012โ2025 and related Server Core builds.
Full writeup: https://exploitgrid.net/blogs/cve-2026-56155-ad-fs-privilege-escalation-bug-is-already-being-exploited
#ADFS #CISAKEV
Local attacker with low privileges โ admin, on Microsoft AD FS servers. CVSS 7.8. Microsoft confirmed exploitation in the wild; ZDI says it chains well with RCE for ransomware. No public PoC yet, but that hasn't stopped active use.
Affected: AD FS on Windows Server 2012โ2025 and related Server Core builds.
Full writeup: https://exploitgrid.net/blogs/cve-2026-56155-ad-fs-privilege-escalation-bug-is-already-being-exploited
#ADFS #CISAKEV
๐จ CRITICAL: Metabase RCE โ CVE-2026-59827
CVSS 9.9
โ ๏ธ Unsafe deserialization in H2 query handling โ authenticated users can get full RCE
๐ฏ Target: default Sample DB (ships in every Metabase install)
๐ง How: SELECT X'...'::OTHER smuggles a malicious payload into ObjectInputStream.readObject()
๐ Affected:
OSS 0.58.0 โ 0.61.1.3
Enterprise 1.58.0 โ 1.61.1.3
โ Fix: Upgrade to 0.61.1.4+ / 1.61.1.4+
๐ฉน Can't patch now? Revoke native query perms on H2 DBs
๐ Also check CVE-2026-59826 (H2 connection string RCE), dropped same day
๐งช We reproduced this in an isolated lab to validate patch behavior โ full writeup with gadget chains + lab setup:
๐ https://exploitgrid.net/blogs/cve-2026-59827-vuln-and-exploit-working
โ๏ธ Lab research, defensive purpose only โ don't test this on systems you don't own/have permission for.
#Metabase #CVE #RCE #InfoSec
CVSS 9.9
โ ๏ธ Unsafe deserialization in H2 query handling โ authenticated users can get full RCE
๐ฏ Target: default Sample DB (ships in every Metabase install)
๐ง How: SELECT X'...'::OTHER smuggles a malicious payload into ObjectInputStream.readObject()
๐ Affected:
OSS 0.58.0 โ 0.61.1.3
Enterprise 1.58.0 โ 1.61.1.3
โ Fix: Upgrade to 0.61.1.4+ / 1.61.1.4+
๐ฉน Can't patch now? Revoke native query perms on H2 DBs
๐ Also check CVE-2026-59826 (H2 connection string RCE), dropped same day
๐งช We reproduced this in an isolated lab to validate patch behavior โ full writeup with gadget chains + lab setup:
๐ https://exploitgrid.net/blogs/cve-2026-59827-vuln-and-exploit-working
โ๏ธ Lab research, defensive purpose only โ don't test this on systems you don't own/have permission for.
#Metabase #CVE #RCE #InfoSec
exploitgrid.net
CVE-2026-59827 โ Critical Metabase Deserialization Bug Turns a SQL Query Into Remote Code Execution
Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization in Metabase
๐ด CVE-2026-9810 | CVSS 9.8
AI Copilot WordPress Plugin โ OAuth token binding failure grants unauthenticated admin access.
โช๏ธ Affected: < 1.5.4
โช๏ธ Fixed: 1.5.4
โช๏ธ Auth required: None
Public exploit details are available. Full technical breakdown, detection queries, and remediation steps on ExploitGrid.
๐ exploitgrid.net/blogs/cve-2026-9810-unauthenticated-rce
AI Copilot WordPress Plugin โ OAuth token binding failure grants unauthenticated admin access.
โช๏ธ Affected: < 1.5.4
โช๏ธ Fixed: 1.5.4
โช๏ธ Auth required: None
Public exploit details are available. Full technical breakdown, detection queries, and remediation steps on ExploitGrid.
๐ exploitgrid.net/blogs/cve-2026-9810-unauthenticated-rce
exploitgrid.net
CVE-2026-9810 Unauthenticated RCE
CVE-2026-9810 Wordpress AI Copilot Plugin Unauthenticated RCE
