Daily Cyber Threat Intel Brief — 2026-08-12
Generated: 2026-08-12 08:00:14 UTC
Executive summary
Priority technology watch items
- Overview Rapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint…
- Overview On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, an authentication bypass vulnerability affecting Microsoft SharePoint. Today we are publishing a technical analysis of the vulnerability along with an accompanying proof-of-concept…
- Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
- Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to…
- Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to execute code over a network.
- Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.
- Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
- Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
- Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
- Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
- This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS…
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-55040` | CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) | Rapid7 Blog |
| cve | `CVE-2026-63520` | CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED) | Rapid7 Blog |
| cve | `CVE-2026-63514` | CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-57105` | CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62829` | CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62827` | CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62837` | CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63512` | CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-63516` | CVE-2026-63516 Microsoft SharePoint Server Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-65768` | CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54113` | CVE-2026-54113 Remote Procedure Call Denial of Service Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-54984` | CVE-2026-54984 Windows Imaging Component Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-49179` | CVE-2026-49179 Windows Active Directory Domain Services Remote Code Execution Vulnerabilit | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59113` | CVE-2026-59113 Visual Studio Code Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59124` | CVE-2026-59124 Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulne | Microsoft Security Response Center RSS |
| cve | `CVE-2026-50472` | CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulner | Microsoft Security Response Center RSS |
| cve | `CVE-2026-56174` | CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-58650` | CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-40375` | CVE-2026-40375 Microsoft Dynamics Business Central Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-58612` | CVE-2026-58612 PowerShell Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-47299` | CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-47285` | CVE-2026-47285 Visual Studio Code Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-6727` | CVE-2026-6727 MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59127` | CVE-2026-59127 Windows Installer Elevation of Privilege Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59128` | CVE-2026-59128 Windows Encrypting File System (EFS) Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59133` | CVE-2026-59133 Microsoft High Performance Computing (HPC) Pack Elevation of Privilege Vuln | Microsoft Security Response Center RSS |
| cve | `CVE-2026-59130` | CVE-2026-59130 AMD Zen Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57888` | CVE-2024-57888 workqueue: Do not warn when cancelling WQ_MEM_RECLAIM work from !WQ_MEM_REC | Microsoft Security Response Center RSS |
| cve | `CVE-2024-57795` | CVE-2024-57795 RDMA/rxe: Remove the direct link to net_device | Microsoft Security Response Center RSS |
| cve | `CVE-2026-3087` | CVE-2026-3087 shutil.unpack_archive() doesn't check for Windows absolute paths in ZIPs | Microsoft Security Response Center RSS |