ctipilot.ch
← Back to Weekly 2026-W29
NOTABLEexploitedNATOB2outlook

2026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running

discovered 2026-07-19 23:59 UTCrun 2026-07-19T2310Z-weekly5 sourcesmulti-source

Items already in motion at the close of the week — each sourced, none a prediction:

  • WordPress "WP2Shell" pre-auth RCE (CVE-2026-63030 + CVE-2026-60137) — Searchlight Cyber withheld exploit details but published a public checker, public proof-of-concept code is already on GitHub, and NCSC-NL assesses short-term exploitation is expected; no confirmed in-the-wild abuse as of 2026-07-18 (Searchlight Cyber, 2026-07-17). Any stock WordPress not on 7.0.2 / 6.9.5 / 6.8.6 is the exposure to close first.
  • SharePoint JWT auth-bypass CVE-2026-55040 (Pwn2Own chain) — Rapid7 is holding full technical detail and the PoC under a 30-day disclosure embargo, and the chained RCE half is not scheduled for patch until August, so applying the July fix now is the only current break in the chain (Rapid7, 2026-07-14). Watch for the embargo lift (~mid-August) and the August RCE patch.
  • Firefox 152.0.6 (CVE-2026-15718 WebAssembly, CVE-2026-15719 site-isolation) — public exploit code exists; Mozilla states no in-the-wild attacks, contrary to some aggregator "zero-day" framing (NCSC-NL, 2026-07-16). A browser code-execution chain with public code on managed/ESR fleets is the watch item.
  • Progress ShareFile Storage Zone Controller CVE — Progress named a path-traversal root cause and shipped 5.12.5 / 6.0.2 but reserved and withheld the CVE identifier, due to publish in roughly two weeks (BleepingComputer, 2026-07-14); patch and post-exposure review should not wait for the identifier.
  • Oracle E-Business Suite Payments (CVE-2026-46817) — confirmed exploited from late June before any public PoC (Help Net Security, 2026-06-30); any instance exposed after 2026-05-28 is inside a live post-exposure compromise-assessment window, not merely a patch task.
  • EU regulatory clocks running — the CRA Article 14 24-hour vulnerability-reporting obligation begins 11 September 2026, and Germany's KRITIS-Dachgesetz operator-registration window opened 17 July 2026 (three-month registration deadline); both are covered in this week's policy entry and are obligations the constituency's supplier and cross-border tail is already inside.
PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.