Daily Security Intel

Archives
Log in
Subscribe
July 23, 2026

[SecurityIntel] 23 Jul | SharePoint and Langflow Flaws Face Active Exploitation

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, July 23, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

SharePoint and Langflow Flaws Face Active Exploitation

CRITICAL

5

C2 IPs

0

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities in Microsoft SharePoint (CVE-2026-50522) and the Langflow AI framework highlights an immediate threat to enterprise collaboration tools and AI development pipelines. Concurrently, a high-severity path traversal flaw in the Windmill developer platform (CVE-2026-29059) and a silent data exfiltration vulnerability in the Adobe Acrobat Chrome extension are actively putting sensitive server files and messaging data at risk. Organizations must also defend against credential-stuffing campaigns and sophisticated phishing kits like Kratos that bypass multi-factor authentication to compromise corporate accounts.

■ CRITICAL STORIES

CRITICAL#1

Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

Threat actors are actively exploiting CVE-2026-50522 in Microsoft SharePoint to steal machine keys, allowing them to bypass security controls and maintain persistent, long-term access to corporate networks.

HIGH#2

CISA orders urgent action on actively exploited Langflow RCE flaw

CISA has added an actively exploited remote code execution (RCE) vulnerability in the Langflow visual framework to its Known Exploited Vulnerabilities catalog, ordering federal agencies to secure their AI agent-building systems immediately.

HIGH#3

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

An unauthenticated path traversal vulnerability (CVE-2026-29059) in the Windmill developer platform is being actively exploited in the wild, enabling remote attackers to read sensitive configuration and server files.

HIGH#4

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

A newly disclosed vulnerability chain in the Adobe Acrobat Chrome extension allows malicious websites to silently hijack and exfiltrate private WhatsApp Web conversations and contact lists without requiring user authentication.

■ CVEs IDENTIFIED

CVE-2026-50522

Microsoft — SharePoint — Machine key theft and persistent unauthorized access

Critical

CVE-2026-29059

Windmill Labs — Windmill — Unauthenticated path traversal and arbitrary file read

High

[CVE-TBD]

Langflow — Langflow Visual Framework — Remote code execution via visual AI agent builder

Critical

[CVE-TBD]

Adobe — Acrobat Chrome Extension — Silent information disclosure and WhatsApp Web data hijacking

High

■ THREAT ACTORS

Kimsuky

APT

Targeted South Korean collaborative-work software vendors in a supply chain compromise campaign.

Everest

Cybercrime

Breached a shared data exchange platform and demanded a $12.3 million ransom from Swiss rail manufacturer Stadler Rail.

Iran-linked APT

APT

Conducted targeted attacks on operational technology (OT) systems, manipulating SCADA and HMI displays using malicious project files.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to exploit SharePoint (CVE-2026-50522), Windmill (CVE-2026-29059), and Langflow.
T1068
Exploitation for Privilege Escalation | Utilized via the snap-confine vulnerability to obtain root access on Ubuntu.
T1195
Supply Chain Compromise | Employed by Kimsuky to target South Korean collaborative software vendors.
T1110.004
Credential Stuffing | Used to hijack Chick-fil-A One loyalty accounts.
T1566
Phishing | Distributed via the Kratos phishing kit to harvest credentials.
T1111
Multi-Factor Authentication Bypass | Executed by the Kratos phishing kit to steal active Microsoft 365 sessions.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL — Microsoft — SharePoint (CVE-2026-50522) — Actively exploited to steal machine keys and establish persistent access — [SW] Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks

[P3 PATCH NOW]≤1 week

CRITICAL — Langflow — Langflow Visual Framework ([CVE-TBD]) — Actively exploited RCE vulnerability targeted in the wild and flagged by CISA — [BC] CISA orders urgent action on actively exploited Langflow RCE flaw

[P3 PATCH NOW]≤1 week

HIGH — Windmill Labs — Windmill (CVE-2026-29059) — High-severity path traversal under active exploitation to read arbitrary server files — [THN] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

[P3 PATCH NOW]≤1 week

HIGH — Canonical — snap-confine ([CVE-TBD]) — Local privilege escalation vulnerability giving root access on default Ubuntu desktops — [THN] Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Microsoft SharePoint immediately to remediate CVE-2026-50522 and prevent attackers from stealing machine keys.
2[P1] Update the Langflow visual framework to the latest secure version to mitigate the actively exploited RCE vulnerability.
3[P1] Apply security updates to Windmill developer platform instances to address the CVE-2026-29059 path traversal vulnerability.
4[P2] Force an immediate update of the Adobe Acrobat Chrome extension across all enterprise endpoints to block WhatsApp Web data hijacking.
5[P2] Update Canonical snap-confine on all Ubuntu desktop deployments to eliminate the risk of local privilege escalation to root.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 24 Jul | Russian State Hackers Exploit Zimbra Zero-Click Zero-Day Older → [SecurityIntel] 22 Jul | SharePoint and PAN-OS Flaws Actively Exploited
Powered by Buttondown, the easiest way to start and grow your newsletter.