TL;DR
Microsoft SharePoint CVE-2026-55040 (CVSS 9.1 auth bypass) is being actively exploited following public PoC release. 737 malicious Chrome VPN extensions are intercepting traffic from Russian speakers. Microsoft released patches for 398 vulnerabilities including one Windows zero-day in active use.
Executive Summary
- Attackers have begun exploiting CVE-2026-55040, a critical SharePoint authentication bypass (CVSS 9.1), in the days following public proof-of-concept code release.
- A massive malware campaign distributes 737 free VPN and proxy extensions through Chrome Web Store to intercept browser traffic and route it through malicious proxy infrastructure, primarily targeting Russian-speaking users.
- Microsoft released 398 security patches covering Windows and supported software, including at least one vulnerability actively being exploited in the wild and two others publicly disclosed before the patch date.
- Lazarus Group has deployed a previously unknown backdoor via Windows zero-day exploitation against defense and aerospace companies in France, Germany, Brazil, and India.
- Adobe Commerce vulnerability CVE-2026-71362 began receiving exploitation attempts immediately after Adobe released patches.
Top Threats Today
1. SharePoint Authentication Bypass Under Active Exploitation
Severity: HIGH Affected: Technology, Government
Threat actors have begun exploiting CVE-2026-55040, a critical authentication security feature bypass in Microsoft SharePoint, following the public release of proof-of-concept code [1]. The vulnerability carries a CVSS score of 9.1, indicating severe impact [1]. Active exploitation has been confirmed in the immediate aftermath of the PoC publication.
Sources:[1] The Hacker News
Recommended Action
- Prioritize patching or updating SharePoint systems to the latest available version immediately
- Review SharePoint access logs for authentication anomalies or unexpected user sessions
- Enable additional authentication controls such as multi-factor authentication on SharePoint applications
- Monitor network traffic for suspicious activity originating from or targeting SharePoint infrastructure
2. Malicious VPN Extension Campaign Targeting Russian-Speaking Users
Severity: HIGH Affected: Technology
A coordinated campaign distributes 737 free VPN and proxy extensions primarily targeting Russian-speaking users seeking to access blocked services [1]. These extensions intercept browser traffic and route it through attacker-controlled proxy infrastructure [1]. The malicious extensions have been published across at least 40 Chrome Web Store developer accounts, indicating an organized distribution network.
Sources:[1] The Hacker News
Recommended Action
- Audit all installed browser extensions, particularly free VPN and proxy tools, and remove any unknown or suspicious ones
- Review Chrome Web Store permissions and remove extensions with excessive network access rights
- Deploy browser extension control policies via MDM/endpoint management to whitelist approved extensions only
- Educate users on risks of free VPN extensions and direct them to vetted corporate VPN solutions
3. Microsoft Patch Tuesday: 398 Vulnerabilities Including Active Zero-Day Exploitation
Severity: HIGH Affected: Technology, Government
Microsoft released security updates addressing at least 398 vulnerabilities in Windows operating systems and supported software [1]. The update set includes at least one vulnerability already being actively exploited in the wild and two others that were publicly detailed prior to the patch release [1]. This represents a significant patch burden requiring rapid deployment across enterprise environments.
Sources:[1] Krebs on Security
Recommended Action
- Test and deploy Microsoft patches to all Windows systems within 24-48 hours, prioritizing systems running public-facing services
- Prioritize patching the actively exploited vulnerability ahead of others in the batch
- Verify patch deployment using endpoint management tools and security scanning
- Monitor systems for post-patch stability and revert if critical issues emerge, then coordinate with Microsoft for fixes
4. Lazarus Deploys New Backdoor via Windows Zero-Day Against Defense/Aerospace Sector
Severity: HIGH Affected: Defense, Technology
Lazarus Group has been attributed to exploitation of a newly patched Windows zero-day vulnerability to deliver a previously undocumented backdoor targeting defense and aerospace companies [1]. The campaign has confirmed victims in France, Germany, Brazil, and India [1]. The backdoor grants SYSTEM-level access to compromised systems, enabling attackers to install secondary malware and maintain persistent access. ⚠
Sources:[1] The Hacker News
Recommended Action
- Immediately patch Windows systems to the latest version to close the zero-day exploitation vector
- Hunt for indicators of compromise (IOCs) and lateral movement consistent with Lazarus tactics
- Review Windows Event Logs for suspicious SYSTEM-level process creation and privilege escalation activity
- Isolate any suspected compromised systems and initiate forensic investigation
5. Adobe Commerce RCE Exploitation Begins Immediately After Patch Release
Severity: HIGH Affected: Technology, Retail
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches for the vulnerability [1]. The rapid onset of exploitation activity indicates attackers are actively scanning for and targeting unpatched Adobe Commerce instances.
Sources:[1] SecurityWeek
Recommended Action
- Patch Adobe Commerce systems to the latest patched version without delay
- Scan web server logs and WAF logs for exploitation attempts matching CVE-2026-71362 signatures
- If breach is suspected, review order history, customer data access, and payment card information for unauthorized access
- Notify payment processors and customers if data compromise is confirmed
Today’s Action Checklist
- ☐ URGENT: Patch Microsoft SharePoint systems to address CVE-2026-55040 (CVSS 9.1) under active attack
- ☐ URGENT: Audit and remove malicious VPN extensions from user browsers and enforce extension policy controls
- ☐ HIGH: Deploy Microsoft patch batch (398 flaws) to Windows and Office systems, prioritizing the actively exploited vulnerability
- ☐ HIGH: Patch or verify patching of Adobe Commerce installations vulnerable to CVE-2026-71362
- ☐ HIGH: Hunt for Lazarus indicators of compromise (SYSTEM-level process creation, backdoor signatures) on Windows endpoints, particularly in defense/aerospace sectors
- ☐ ROUTINE: Apply Cisco Firewall (CVE-2026-20349) and Windows driver (CVE-2026-68820) patches added to CISA KEV catalog