Last Updated On

CCTTII--22002266--00772244
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

Your Edge VPN Just Became the Attackers Front Door

Edge remote access, CMS cores, firewall management planes, and on prem collaboration stacks are all under active exploitation in the same window. SonicWall SMA1000 chained SSRF and AMC code injection is in CISA KEV, WordPress WP2Shell turns stock installs into unauthenticated RCE, Check Point SmartConsole token bypass hands attackers the policy brain, and SharePoint deserialization pairs code execution with machine key theft that survives lazy patching.

Origin Energy confirmed unauthorised access to customer data in Australia, raising fraud and phishing risk without evidenced OT or generation impact. The operator lesson is identical across the tech stack: patch clocks and compromise assessment clocks both run at once.

If you only close scanner tickets, you will miss implants on appliances, rogue CMS admins, silent firewall policy edits, forged SharePoint access after key theft, and Origin themed social engineering against your own users.

10

CVSS Score

12

IOC Count

6

Source Count

82

Confidence Score

CVEs

CVE-2026-15409 (SSRF, SMA1000 Work Place), CVE-2026-15410 (code injection, SMA1000 AMC), CVE-2026-63030, CVE-2026-60137, CVE-2026-50522, CVE-2026-58644, CVE-2026-16232, CVE-2026-62144, CVE-2026-62145, CVE-2026-56164, CVE-2026-45659; Origin Energy incident has insufficient data with no CVEs linked publicly yet.

Actors

Under Attribution, Inc / INC Ransomware / Lynx (secondary bulletin aliases)

Sectors

Government, E commerce, Education, Financial Services, Healthcare, Hospitality, Information Technology, Multimedia, Nonprofit, Real Estate, Retail, Technology Hardware, Critical Infrastructure, Energy, Enterprise, Service Providers

Regions

Global, United States, Italy, North America, Europe, Australia

Chapter 01 - Executive Overview

Today’s brief is dominated by actively exploited edge and content platform flaws with federal remediation clocks landing on or immediately after 24 July 2026, plus a confirmed customer data breach at a major Australian energy retailer. WordPress Core (WP2Shell), Check Point security management, on prem Microsoft SharePoint, and SonicWall SMA1000 form the technical decision stack; Origin Energy forms the concurrent privacy, fraud, and critical infrastructure trust stack. Primary technical depth is strong from vendor adjacent and security press; where full CISA advisory body text for every KEV line was not retrieved in a given collection pass, treat KEV and deadline claims as corroborated via consulted secondary reporting, not as a substitute for reading the live CISA catalog.

SonicWall SMA1000 zero day chain Critical edge VPN remote access
SMA1000 appliances (6210, 7210, 8200v) are under active attack through chained exploitation of a critical SSRF flaw (CVE-2026-15409, CVSS 10.0) and a high severity code injection flaw (CVE-2026-15410, CVSS 7.2), delivering full remote command execution on edge VPN gateways.
CISA has placed both vulnerabilities in KEV and set short remediation deadlines; SonicWall and multiple vendors stress that patching must be combined with deep forensic review and, if IOCs are found, re imaging and credential resets including TOTP.
Strategic risk: unauthenticated edge in path on internet facing Work Place, internal service and metadata reachability via SSRF, then AMC level RCE and custom implants.
Business impact: full appliance compromise, credential theft, lateral movement into downstream networks, potential multi tenant impact for service providers hosting SMA1000 for customers.
Intelligence confidence: High (~82) on exploitation and remediation facts; actors remain under attribution.
Leader decision NOW: enumerate every SMA1000, attest firmware against fixed hotfixes 12.4.3-03453+ and 12.5.0-02835+, hunt extraweb_access.log and ctrl-service.log now, re image on IOC hit, rotate all admin and user secrets.

WP2Shell Critical Web / CMS / public sites
Two WordPress Core flaws chain to unauthenticated remote code execution on stock installs (no plugins required). In the wild exploitation and public PoCs are reported; CISA KEV remediation for CVE-2026-63030 is cited as due 24 July 2026; CVE-2026-60137 carries a later cited due date of 4 Aug 2026 in secondary explainers.
Strategic risk: high traffic and agency adjacent publishing estates; auto update is not proof of remediation because hosts may block writes or stage updates.
Business impact: full site takeover, defacement, malware staging, credential theft from web roots, secondary supply chain risk to customers and partners.
Intelligence confidence: Medium High on exploitation fact pattern; Medium on exact federal deadline wording pending direct KEV pull.
Leader decision NOW: mandate version attestation (7.0.2 / 6.9.5 / 6.8.6) for every internet facing WordPress property before end of day, with offline until patched for any holdouts.

Check Point SmartConsole auth bypass Critical network security management
Unauthenticated attackers can obtain application login tokens and operate as full admins on Security Management / Multi Domain Management when management is reachable and Trusted Clients is open. Active exploitation reported; CISA KEV deadline cited as 25 July 2026. CVSS 9.3 as reported for CVE-2026-16232; related CVE-2026-62144 and CVE-2026-62145 in the same Jul 22 Jumbo hotfix bundle.
Strategic risk: compromise of the policy control plane where rule changes and logging disablement look like legitimate admin work.
Business impact: perimeter policy rewrite, silent allow rules, loss of detection integrity, potential multi gateway blast radius.
Intelligence confidence: Medium (detailed secondary plus vendor advisory references; small number of targeted customers per vendor messaging).
Leader decision NOW: apply Jul 22 Jumbo HFA bundle per sk185169 class guidance, lock Trusted Clients, remove Any management exposure, audit recent policy and admin token activity, treat exposed management as incident response priority.

SharePoint CVE-2026-50522 Critical on prem collaboration
Unauthenticated is not the model here: exploitation requires authentication as at least Site Owner, then CWE-502 deserialization yields RCE. Observed behaviour includes machine key theft for persistence, webshells, and suspicious w3wp.exe child processes. Fixed in 14 Jul 2026 Patch Tuesday for SharePoint Server Subscription Edition, 2019, and 2016 Enterprise. Related wave includes CVE-2026-58644 (KEV, CVSS 9.8 class reporting) plus CVE-2026-56164 and CVE-2026-45659. As of this report CVE-2026-50522 itself was not listed on KEV per consulted SecurityWeek class reporting.
Strategic risk: persistence after patch if ValidationKey and DecryptionKey are not rotated; prior ToolShell era lessons apply.
Business impact: persistent access to collaboration content, pivoting inside Windows estates, integrity loss on intranet and extranet portals.
Intelligence confidence: Medium High on technical pattern and active exploitation; Medium on exact KEV membership of 50522.
Leader decision NOW: confirm July Patch Tuesday deployment, rotate SharePoint machine keys immediately after patch, hunt unauthorized .aspx and anomalous app pool children, review Site Owner assignments.

Origin Energy customer data breach High critical infrastructure retailer
Origin Energy has confirmed unauthorised access and disclosure of some customer data, with exposed fields including personal and account information and, in some reports, partial card or bank numbers, while stressing that full credit card or bank details are not believed to be included. The incident currently appears limited to customer information systems, with no evidence of impact on energy production or OT operations.
Strategic risk: high credibility phishing and identity fraud against Australian energy customers; reputational and regulatory pressure on sector trust.
Business impact for non Origin organisations: downstream social engineering that abuses accurate billing and identity data; pressure to stop using static PII as primary authenticator.
Intelligence confidence: Medium (~60 to 65); breach fact strong, root cause and full scope incomplete.
Leader decision NOW: prime fraud and helpdesk playbooks for Origin themed lures, tighten step up verification on account changes, do not treat partial PAN or account fragments as proof of identity.

Cross incident executive bottom line
Patch clocks and compromise assessment clocks are both running. Edge VPN (SonicWall), CMS core (WordPress), security management (Check Point), and collaboration (SharePoint) are simultaneous Initial Access magnets; Origin shows that even without a public CVE chain, customer trust damage and fraud externalities arrive within days of disclosure. Prefer re image plus credential rotation over “hotfix and hope” on SMA1000 IOC hits; prefer key rotation plus webshell hunt on SharePoint; prefer management plane lockdown plus policy audit on Check Point; prefer version attestation not auto update assumptions on WordPress; prefer fraud monitoring over infrastructure IOC hunting for Origin themed abuse.

Chapter 02 - Threat & Exposure Analysis

SonicWall SMA1000 Work Place SSRF and AMC code injection chain

CVE-2026-15409 is a server side request forgery vulnerability in the SMA1000 Work Place interface. An unauthenticated attacker can coerce the appliance into sending HTTP requests to arbitrary internal or external destinations, including RFC1918 services and cloud metadata endpoints such as 169.254.169.254. Affected appliance families in consulted sources include SMA1000 models 6210, 7210, and 8200v. Affected builds span firmware 12.4.3-03245 through 12.5.0-02800 before fixed hotfixes.

CVE-2026-15410 is a code injection flaw in the AMC where attacker controlled input becomes part of OS command execution under administrator context, yielding remote code execution on the appliance. Consulted vendor and partner analysis supports a chain where CVE-2026-15409 first provides reachability to internal AMC adjacent services or supports credential theft paths, then CVE-2026-15410 executes arbitrary OS commands and stages custom implants. Rapid7, Tenable, SonicWall, and peer briefings all describe active exploitation and treat internet facing SMA1000 nodes as high priority incident response targets, not routine patch tickets.

Observed and inferred technical behaviour on compromised SMA1000 estates:
Work Place requests that abuse /wsproxy with atypical host parameters to tunnel toward internal management planes or metadata services.
Spikes or anomalous success patterns on /api/login and /api/logout in extraweb_access.log.
ctrl-service.log entries describing hotfix removal paired with path traversal style names, consistent with tampering or implant maintenance.
Anomalous outbound HTTP or HTTPS from SMA1000 interfaces to internal RFC1918 ranges, cloud metadata IPs, or non approved external services.
Custom malware and Python oriented webshell or implant patterns called out in mid to late July follow on analysis, which is why re imaging is preferred over hotfix only recovery when IOCs hit.

WP2Shell WordPress Core REST batch desync to SQLi to RCE

Attack vector: network, unauthenticated HTTP to the WordPress REST batch endpoint. Consulted technical paths include ?rest_route=/batch/v1 and wp-json/batch/v1 style batch abuse.

Exploitation mechanism (from consulted F5 and SecurityWeek class technical summaries): WP REST server serve batch request v1 index desynchronization after invalid sub request validation is unbound from handler execution. A malicious query var reaches WP_Query where string author__not_in bypasses is_array, skips absint, enables SQL injection, and chains to remote code execution. No malicious plugin is required on the initial foothold; stock core is enough on vulnerable trains.

Observed behaviour:
Site takeover and rogue administrator creation.
Malicious plugin or PHP drop under wp-content/plugins, including wp2shell styled plugin path patterns in bulletin material.
Defacement, malware staging, and credential theft from web roots.
Honeypot and in the wild exploitation reported across 17 to 19 Jul 2026 windows, with public PoC circulation.

Affected versions (consulted):
7.0.0 to 7.0.1 and 6.9.0 to 6.9.4 for both CVEs in the primary chain narrative.
6.8.0 to 6.8.5 for CVE-2026-60137 per secondary KEV explainer class material.
Patched: 7.0.2, 6.9.5, 6.8.6.
Patch status: upstream patched; residual risk remains on hosts that block writes, stage updates, or disable forced auto update. Auto update success must be attested, never assumed.

CVE identifiers in this chain: CVE-2026-63030 and CVE-2026-60137. Federal remediation for CVE-2026-63030 is cited as due 24 July 2026; CVE-2026-60137 carries a later cited due date of 4 Aug 2026 in secondary explainers. Treat deadline wording as corroborated via consulted reporting and verify on the live KEV catalog before attestation.

Check Point SmartConsole token auth bypass and related management plane flaws

CVE-2026-16232: improper authentication in SmartConsole login so an attacker can obtain an application login token without credentials and operate as full admin on Security Management or Multi Domain Management when the management GUI path is reachable and Trusted Clients is open (including the dangerous Trusted Clients Any anti pattern).

Related window CVEs in the same Jul 22 Jumbo hotfix bundle narrative:
CVE-2026-62144 unauthenticated admin commands class issue.
CVE-2026-62145 Gaia Portal privilege issue.

CVSS 9.3 as reported for CVE-2026-16232. Affected version span reported as R77.30 through R82.10 broad; end of support trains need migration, not only patch.

Observed behaviour:
Security policy and configuration changes performed through the legitimate management channel.
Control plane abuse where malicious allow rules or logging changes blend into normal admin telemetry.
Vendor messaging indicates a small number of customers targeted pre disclosure, with active exploitation reported and secondary technical briefings circulating IOCs around 23 Jul 2026.
Cited federal KEV due date 25 July 2026 in consulted secondary material.

Strategic technical meaning: this is not classic endpoint malware first. It is takeover of the policy brain that pushes rules to gateways. Blast radius is multi gateway when one management server governs many enforcement points.

SharePoint CVE-2026-50522 untrusted deserialization RCE and related wave

Attack vector: network to on prem SharePoint; consulted technical summary states exploitation requires authentication as at least Site Owner (not anonymous unauthenticated in the primary 50522 writeups).

Exploitation mechanism: CWE-502 deserialization of untrusted data to inject and execute code on SharePoint Server.

Observed behaviour:
Machine key theft (ValidationKey and DecryptionKey) for persistence and ticket or token forgery style follow on access.
Unauthorized .aspx webshells.
Anomalous w3wp.exe (IIS app pool) child processes.
Honeypot path: ~17 Jul possible 0 day assessment, ~20 Jul update toward likely CVE-2026-50522, ~21 Jul public PoC and confirmation of active exploitation plus machine key theft pattern (WatchTowr class reporting via SecurityWeek).

Affected products: SharePoint Server Subscription Edition, SharePoint Server 2019, SharePoint Server 2016 Enterprise.
Patch status: fixed 14 Jul 2026 Patch Tuesday. Critical post patch step is rotation of ValidationKey and DecryptionKey; patch without key rotation leaves persistence intact.

Related SharePoint wave in the same period:
CVE-2026-58644 (KEV add narrative ~16 Jul with due ~19 Jul per bulletin class reporting, CVSS 9.8 class).
CVE-2026-56164 and CVE-2026-45659 in the broader on prem SharePoint exploitation wave context.
As of this report, CVE-2026-50522 itself was not listed on KEV per consulted SecurityWeek class reporting. Do not equate “actively exploited” with “already on KEV” for 50522 without live catalog confirmation.

Origin Energy customer data breach threat dynamics

Confirmed unauthorised access and disclosure of some customer data. Exposed field classes in consulted reporting include personal and account information and, in some reports, partial card or bank numbers. Origin has stressed that full credit card or full bank details are not believed to be included. No public evidence of impact to energy production or OT operations; impact narrative remains on customer information systems.

Threat consequence (not exploit chain, because root cause is undisclosed):
High credibility phishing and social engineering that references real energy accounts, billing history, refunds, disconnections, or payment changes.
Identity theft and account takeover pressure on customers and on any third party that still accepts static PII (name, address, DOB, phone, partial account numbers) as primary authenticator.
Reputational and regulatory pressure on critical infrastructure retail energy trust, even without OT downtime.

Technical exploit vector: insufficient data. No CVEs publicly linked. No general purpose infrastructure IOC set released. Downstream abuse detection matters more than classic C2 hunting for non Origin defenders in this window.

CISA Zimbra listing note (context only)
On 23 Jul 2026 the CISA cybersecurity advisories index listed a phishing campaign targeting Zimbra Collaboration users. Full advisory body was not retrieved in the wide search pass; deep technical claims are insufficient source data and are not fabricated here. Track as a watch item, not a fully specified incident chapter.

Cross incident threat synthesis
The common adversary preference in this window is internet reachable control or content planes that yield admin equivalent power quickly: edge VPN appliances (SonicWall), CMS core (WordPress), security policy management (Check Point), collaboration servers (SharePoint). Chaining pattern repeats: initial access flaw, credential or key material theft, persistence that survives naive patching, then either lateral movement or fraud externalization (Origin). Custom implants on SMA1000 and machine key theft on SharePoint are the two clearest “patch is not remediation” lessons in the set.

Chapter 03 - Operational Response

SonicWall SMA1000 immediate operations

Enumerate all SMA1000 appliances (physical and virtual) and record firmware version. Treat builds from 12.4.3-03245 through 12.5.0-02800 as in scope until proven fixed.
Apply SonicWall hotfixes 12.4.3-03453+ and 12.5.0-02835+ to all affected appliances. Prioritise internet facing Work Place nodes first.
Restrict Work Place and AMC access to trusted admin networks or bastion hosts. Remove direct internet exposure wherever feasible.
Implement strict egress controls from SMA1000 segments. Block outbound connections to cloud metadata services and to non approved internal management planes.
Hunt before you declare victory:
extraweb_access.log for /api/login and /api/logout with HTTP 200 and for /wsproxy requests with suspicious host parameters.
ctrl-service.log for hotfix removal entries containing path traversal patterns.
NetFlow or firewall telemetry for unusual SMA1000 originated egress to RFC1918, 169.254.169.254, or odd external destinations.
If IOCs are present:
Re image hardware or redeploy virtual appliances.
Restore configuration only from backups that predate the vulnerable hotfix lines.
Audit restored configuration for tampering.
Rotate all user and admin passwords and reset TOTP tokens.
Review downstream systems for lateral movement and exfiltration linked to SMA1000 origin.
Do not equate “hotfix applied” with “compromise cleared” when log IOCs or implant signs exist.

WP2Shell WordPress immediate operations

Inventory every internet facing WordPress property including forgotten marketing microsites, campaign landing hosts, and agency managed properties.
Attest running version is 7.0.2 or 6.9.5 or 6.8.6 as applicable. Do not trust auto update flags alone; confirm on disk and in the admin UI or CLI.
Any host that cannot patch same day: take offline or place behind maintenance control until patched.
After patch:
Review users for rogue administrators.
Review installed plugins for unexpected wp2shell styled or unknown PHP drops under wp-content/plugins.
Review web roots for recently modified PHP, scheduled tasks, and unexpected outbound connections from the web tier.
Reset application secrets, salts, and highly privileged CMS credentials if compromise is suspected.
For agencies and multi site hosts: require customer version attestation in writing before end of day on deadline date.

Check Point Security Management immediate operations

Confirm whether Security Management or Multi Domain Management GUI is reachable beyond a tightly controlled admin network.
Apply the 22 Jul 2026 Jumbo HFA bundle covering CVE-2026-16232, CVE-2026-62144, and CVE-2026-62145 per vendor sk185169 class guidance.
Lock Trusted Clients. Eliminate Trusted Clients Any.
Require admin access only from named jump hosts with MFA and session recording where available.
Audit recent policy packages, admin logins, token issuances, and rule changes for unexplained allow paths or logging disablement.
If management exposure or suspicious admin actions exist: treat as incident response, not as a quiet patch window. Validate gateway policy integrity after cleanup.
End of support trains in the R77.30 through R82.10 span need migration planning, not perpetual hotfix reliance.

SharePoint CVE-2026-50522 and related wave immediate operations

Confirm 14 Jul 2026 Patch Tuesday fixes are deployed on SharePoint Server Subscription Edition, 2019, and 2016 Enterprise.
Rotate ValidationKey and DecryptionKey immediately after patching. Document key rotation completion.
Hunt unauthorized .aspx files, anomalous w3wp.exe child processes, and signs of machine key theft or reuse.
Review Site Owner and higher role assignments; remove standing privilege that is not required.
Apply related KEV driven SharePoint fixes in the same change window where CVE-2026-58644 and peer CVEs apply.
Assume persistence may predate the patch if the farm was exploitable; pair patching with compromise assessment.

Origin Energy concurrent response for non Origin organisations

Prepare detection and response for phishing and social engineering that references Origin’s breach, energy accounts, refunds, disconnections, or payment changes.
Reduce reliance on static personal data (names, addresses, DOB, phone, partial account numbers) as primary identity proof in your own processes.
Guide staff and customers to treat urgent energy account change requests as high risk and to verify only via official channels you already trust, not via links in inbound messages.
Tune fraud and helpdesk playbooks for higher volume identity assertion attempts using accurate leaked field classes.
Origin internal OT production impact is not evidenced; do not spread OT outage claims. Focus external defenders on fraud and privacy externalities.

Governance oriented response shared across incidents

Track KEV listed vulnerabilities with explicit asset owners, patch SLAs, and compromise assessment checklists for edge access gateways, CMS estates, security management planes, and on prem collaboration farms.
Treat edge VPN and security management servers as critical assets equal to identity providers in priority, not as “network plumbing.”
For critical infrastructure customer data incidents, coordinate privacy, cyber, communications, and fraud teams on a single timeline rather than separate threads.

SonicWall SMA1000 timeline

13 Jul 2026: SonicWall publishes product notice and confirms multiple vulnerabilities in SMA1000, including CVE-2026-15409 and CVE-2026-15410.
14 Jul 2026: eSentire, Tenable, Rapid7 and others release blogs confirming active exploitation and recommending urgent patching and log review.
14 to 15 Jul 2026: CISA adds both CVEs to KEV with a 17 Jul remediation deadline for federal agencies.
Mid to late Jul 2026: Further analysis highlights custom malware on SMA1000 appliances and emphasises re imaging plus credential rotation for compromised deployments.
Early Jul 2026 (pre advisory): SonicWall and partners report exploitation preceding the 14 July public advisory.
24 Jul 2026: This CTI window incorporates KEV status and multi vendor analysis into the active record.

WP2Shell WordPress timeline

17 Jul 2026: WordPress 7.0.2 and backports released; forced auto update path enabled for affected versions in consulted reporting.
17 to 19 Jul 2026: In the wild exploitation and honeypot hits reported (Patchstack, Hexastrike, WatchTowr class signals via SecurityWeek).
21 Jul 2026: CISA KEV add date cited for both CVEs in secondary reporting.
24 Jul 2026: Cited federal remediation due date for CVE-2026-63030 (deadline day in this window).
4 Aug 2026: Cited due date for CVE-2026-60137 in secondary explainer class material.

Check Point SmartConsole timeline

DATE UNCONFIRMED pre disclosure: Vendor indicates a small number of customers targeted.
22 Jul 2026: Hotfix bundle Jumbo takes published covering CVE-2026-16232, CVE-2026-62144, CVE-2026-62145.
23 Jul 2026: Secondary technical briefings circulate with IOCs and KEV 25 July deadline claim.
25 Jul 2026: Cited federal KEV due date.

SharePoint CVE-2026-50522 and related wave timeline

14 Jul 2026: Microsoft Patch Tuesday fix for CVE-2026-50522.
16 Jul 2026: CISA adds related SharePoint CVE-2026-58644 and FortiSandbox CVEs to KEV with due 19 Jul per bulletin class reporting.
17 Jul 2026: Defused honeypots observe exploitation attempts initially assessed as possible 0 day.
20 Jul 2026: Defused update toward likely CVE-2026-50522.
21 Jul 2026: PoC public; WatchTowr class reporting confirms active exploitation and machine key theft pattern.
As of this report: CVE-2026-50522 not listed on KEV per SecurityWeek class reporting.

Origin Energy timeline

21 Jul 2026: Potential security incident disclosed; authorities notified.
22 Jul 2026: Broad media coverage and hacker claims emerge.
23 Jul 2026: Origin confirms unauthorised access and disclosure of some customer data via ASX and media release.
24 Jul 2026: Customer update page continues; scope and field inventory still under investigation.

CISA Zimbra index timeline

23 Jul 2026: CISA cybersecurity advisories index lists phishing campaign targeting Zimbra Collaboration users. Full advisory body not retrieved in the wide search pass; technical depth remains insufficient source data.

Window bracket for this daily record

23 Jul 2026 15:00 IST through 24 Jul 2026 approximately 16:04 IST collection window, published 2026-07-24T10:30:00Z, last updated 2026-07-24T10:30:00Z for the combined brief.


Chapter 04 - Detection Intelligence

SMA1000 SSRF to AMC Command Execution

  • Attack vector: unauthenticated network access to the SMA1000 Work Place interface

  • CVE-2026-15409: server side request forgery that forces the appliance to send HTTP requests to attacker chosen internal or external targets, including RFC1918 hosts and cloud metadata at 169.254.169.254

  • CVE-2026-15410: code injection in AMC where attacker controlled input becomes part of OS command execution under administrator context

  • Exploitation chain supported by consulted sources: SSRF establishes reachability or supports credential exposure, then AMC injection yields remote code execution and implant staging

  • Affected products: SMA1000 models 6210, 7210, 8200v

  • Affected builds: 12.4.3-03245 through 12.5.0-02800

  • Fixed builds: hotfixes 12.4.3-03453+ and 12.5.0-02835+

  • Post exploit signals called out by vendors: custom malware on the appliance, abusive /wsproxy use, anomalous API login or logout activity, hotfix removal tampering in control logs

  • Practical meaning: a fully compromised edge VPN gateway with admin level command execution and a path into internal networks

WordPress Core REST Batch Desync to SQLi to RCE

  • Attack vector: unauthenticated HTTP to WordPress REST batch endpoints

  • Primary paths in consulted material: ?rest_route=/batch/v1 and /wp-json/batch/v1

  • Mechanism: batch request index desynchronization after invalid sub request validation; malicious query data reaches WP_Query; string author__not_in bypasses is_array, skips absint, enables SQL injection, then chains to remote code execution

  • No malicious plugin required for initial foothold on vulnerable core

  • CVEs: CVE-2026-63030, CVE-2026-60137

  • Affected trains: 7.0.0 to 7.0.1, 6.9.0 to 6.9.4; 6.8.0 to 6.8.5 for CVE-2026-60137 per secondary KEV explainers

  • Patched versions: 7.0.2, 6.9.5, 6.8.6

  • Observed outcomes: site takeover, rogue administrator creation, malicious plugin or PHP drop under wp-content/plugins, including wp2shell styled paths

  • Residual risk: hosts that block writes, stage updates, or never complete forced auto update remain exposed even when “auto update” is believed enabled

SmartConsole Token Auth Bypass on Security Management

  • Attack vector: network reachability to Security Management or Multi Domain Management GUI

  • CVE-2026-16232: improper authentication on SmartConsole login; attacker obtains an application login token without credentials and operates as full admin

  • Enabling condition: management plane exposed and Trusted Clients too open, including Trusted Clients Any

  • Related CVEs in the same Jul 22 Jumbo hotfix bundle: CVE-2026-62144 (unauthenticated admin commands class), CVE-2026-62145 (Gaia Portal privilege class)

  • CVSS for CVE-2026-16232: 9.3 as reported

  • Affected span reported: R77.30 through R82.10; end of support trains need migration, not only patching

  • Observed behaviour: policy and configuration changes through the legitimate management channel

  • Practical meaning: compromise of the policy control plane, not a normal endpoint malware first intrusion; one management server can affect many gateways

SharePoint Untrusted Deserialization RCE

  • Attack vector: network access to on prem SharePoint with authentication as at least Site Owner

  • CVE-2026-50522: CWE-502 deserialization of untrusted data leading to code execution on SharePoint Server

  • Affected products: SharePoint Server Subscription Edition, 2019, 2016 Enterprise

  • Patch: 14 Jul 2026 Patch Tuesday

  • Mandatory post patch step: rotate ValidationKey and DecryptionKey; patch without key rotation leaves persistence intact

  • Observed behaviour: machine key theft, unauthorized .aspx webshells, anomalous w3wp.exe child processes

  • Related wave CVEs: CVE-2026-58644, CVE-2026-56164, CVE-2026-45659

  • KEV note from consulted reporting: CVE-2026-58644 added to KEV in mid July; CVE-2026-50522 itself was not listed on KEV as of this report window

  • Practical meaning: authenticated RCE plus key material theft creates patch surviving persistence on collaboration farms

Origin Energy Customer Data Exposure

  • Confirmed outcome: unauthorised access and disclosure of some customer data

  • Exposed field classes in consulted reporting: personal and account information; some reports mention partial card or bank numbers

  • Origin position: full credit card or full bank details not believed included

  • Scope limit in current evidence: customer information systems; no evidenced impact on energy production or OT

  • Technical root cause: INSUFFICIENT SOURCE DATA

  • Linked CVEs: none published

  • Practical meaning for external defenders: fraud and high credibility phishing risk, not a public exploit chain to reverse engineer

Cross Incident Technical Pattern

Surface

Initial flaw class

What attacker gains

What survives naive patching

SMA1000

SSRF + AMC injection

Appliance RCE, internal pivot

Implants, stolen admin or TOTP material

WordPress core

REST batch desync to SQLi to RCE

Full site admin equivalent

Rogue admins, malicious plugins

Check Point Mgmt

Auth bypass to admin token

Policy control plane

Silent allow rules, disabled logging

SharePoint

Deserialization RCE

Code exec on farm

Stolen machine keys, webshells

Origin Energy

Undisclosed

Customer PII or account data

Downstream identity fraud

SMA1000 appliance focused indicators

Log based IOCs

  • extraweb_access.log: requests to /_api_/login or /_api_/logout returning HTTP 200

  • extraweb_access.log: /wsproxy requests with atypical host parameters

  • ctrl-service.log: hotfix removal entries that contain path traversal patterns

Network indicators

  • Unusual outbound HTTP or HTTPS from SMA1000 interfaces to internal RFC1918 ranges

  • Connections from the appliance toward cloud metadata 169.254.169.254

  • Appliance originated egress to non approved external services

Atomic IOC note

  • No credible general purpose attacker IP, domain, or file hash set was published in consulted authoritative research for this exploitation family

  • Environment specific MSSP indicators must stay local context only

Infrastructure pattern

  • Internet exposed Work Place plus weak egress from the appliance segment are the enabling conditions

Check Point management plane indicators

Type

Value

Context

Verdict

IP Address

151.241.99.207

Attacker IP from observed intrusions in consulted briefings

Pending

IP Address

151.241.99.233

Attacker IP

Pending

IP Address

158.62.198.182

Attacker IP

Pending

IP Address

192.142.10.99

Attacker IP

Pending

IP Address

139.28.37.250

Attacker IP

Pending

CVE ID

CVE-2026-16232

SmartConsole auth bypass

N/A

CVE ID

CVE-2026-62144

Unauth admin commands class

N/A

CVE ID

CVE-2026-62145

Gaia Portal privilege class

N/A

Infrastructure pattern

  • Exposed Security Management or Multi Domain Management GUI

  • Trusted Clients set too broadly, including Trusted Clients Any

  • Blast radius follows management hierarchy: one control plane can rewrite many gateways

WP2Shell WordPress indicators

Type

Value

Context

Verdict

URL

?rest_route=/batch/v1

Batch abuse path

Pending

URL

/wp-json/batch/v1

REST batch endpoint

Pending

URL

wp-content/plugins/wp2shell and wp2shell styled PHP plugin paths

Post exploit plugin pattern

Pending

Domain

wp2shell.com

Listed in consulted attacker domain table material

Pending

URL

Public PoC repository references in bulletin material

PoC reference only, not automatic C2

Pending

CVE ID

CVE-2026-63030, CVE-2026-60137

Core chain

N/A

Infrastructure pattern

  • Stock WordPress on vulnerable core with reachable REST batch endpoints

  • Shared hosting and multi site estates raise mass scan value

Broad malware domain lists that appear in generic bulletin tables are not promoted here as confirmed WP2Shell C2 without stronger corroboration in consulted sources.

SharePoint CVE-2026-50522 indicators

Type

Value

Context

Verdict

CVE ID

CVE-2026-50522

Primary deserialization RCE

N/A

CVE ID

CVE-2026-58644, CVE-2026-56164, CVE-2026-45659

Related SharePoint wave

N/A

Behavioral

Stolen machine keys (ValidationKey, DecryptionKey)

Persistence after binary patch

Hunt ready

Behavioral

Unauthorized .aspx webshells

File system and content path artifacts

Hunt ready

Behavioral

Anomalous w3wp.exe child processes

IIS app pool process tree abuse

Hunt ready

Actor

Under Attribution

No authoritative naming in consulted sources

Unattributed

Infrastructure pattern

  • On prem SharePoint Server Subscription Edition, 2019, or 2016 Enterprise

  • Site Owner or higher accounts reachable by attackers

  • Machine keys not rotated after 14 Jul 2026 Patch Tuesday

Origin Energy indicators

  • General purpose IOC count: 0

  • IP, domain, URL, hash: INSUFFICIENT SOURCE DATA

  • Enrichment focus: fraud and phishing abuse of leaked customer fields, not classic C2 infrastructure

  • OT or generation network IOCs: not evidenced

IOC hygiene for this window

  • Pending verdict items need local allowlist and true positive tuning before production blocks

  • Prefer behavioural clusters (logs + egress + privilege change) over single IP blocks for management plane and CMS cases

  • Preserve raw appliance and IIS logs before reimage or key rotation

  • Structured atomic style entries from the wide search set: 12 class items across IPs, URLs, domains, and CVE IDs

  • Plus SMA1000 log and behavioural artefacts from deep research

  • Plus zero public Origin infrastructure IOCs

SMA1000 hunting priorities

  • Parse extraweb_access.log for /wsproxy with internal or metadata hosts

  • Parse same log for /_api_/login and /_api_/logout success spikes

  • Parse ctrl-service.log for hotfix removal plus path traversal style names

  • Correlate those events with appliance sourced egress in NetFlow or firewall telemetry

  • On matched cluster: preserve logs, restrict egress, open IR, decide reimage before trusting the device again

WP2Shell hunting priorities

  • Web access logs for POST to batch REST paths

  • Query strings containing author__not_in

  • Sudden creation of administrators

  • New or unknown plugins under wp-content/plugins

  • Recently modified PHP outside release windows

Check Point management hunting priorities

  • Successful SmartConsole or management token issuance from outside jumphost allowlists

  • Policy package publish without change ticket

  • Logging disable or tracker mute from unexpected admin sessions

  • Large unexplained rule diffs, especially new broad allows

SharePoint hunting priorities

  • w3wp.exe spawning cmd.exe, powershell.exe, or cscript.exe outside baseline

  • New .aspx under SiteAssets, layouts, or odd site paths outside deployment windows

  • Machine key configuration changes outside the Patch Tuesday change record

  • Site Owner role growth and dormant high privilege accounts coming alive

Origin themed abuse hunting priorities

  • Mail or SMS lures using Origin branding, refunds, disconnection threats, or direct debit updates

  • Links that are not on official allowlisted domains

  • Helpdesk calls that assert identity using only static PII classes likely exposed in the breach

Sigma style: SMA1000

title: SMA1000 Work Place SSRF and API Anomalies
logsource: sonicwall_sma1000
detection:
  wsproxy_ssrf:
    uri|contains: '/wsproxy'
    host_param|contains_any:
      - '169.254.169.254'
      - '10.'
      - '192.168.'
      - '172.16.'
  api_auth_spikes:
    uri|contains_any:
      - '/_api_/login'
      - '/_api_/logout'
    status: 200
  hotfix_tamper:
    log_field|contains: 'hotfix removal'
    log_field|re: '\.\./|\.\.\\'
  condition: wsproxy_ssrf or api_auth_spikes or hotfix_tamper
level: high

YARA style: SMA1000 implant heuristic

Tune against known good firmware before production use.

rule SMA1000_Suspicious_Python_Implant_Heuristic
{
  meta:
    description = "Heuristic Python webshell or reverse shell constructs on appliance"
  strings:
    $a = "subprocess" ascii
    $b = "os.system" ascii
    $c = "reverse" ascii nocase
    $d = "socket.socket" ascii
    $e = "/wsproxy" ascii
  condition:
    filesize < 500KB and (2 of ($a,$b,$c,$d) or ($e and 1 of ($a,$b,$d)))
}

SIEM correlation: SMA1000

correlate within 30m
  eventA: Work Place request with suspicious /wsproxy host param
  eventB: ctrl-service hotfix removal or path traversal name
  eventC: SMA1000 interface egress to metadata IP or non approved external
output: possible SMA1000 exploitation path
action: page IR, preserve logs, block egress, begin reimage decision tree

Sigma style: WP2Shell batch abuse

title: WordPress REST Batch Endpoint Abuse
logsource: webserver
detection:
  selection:
    cs_uri_stem|contains_any:
      - '/wp-json/batch/v1'
      - 'rest_route=/batch/v1'
      - '?rest_route=/batch'
    cs_method: 'POST'
  suspicious_query:
    cs_uri_query|contains: 'author__not_in'
  condition: selection and suspicious_query
level: critical

SIEM logic: Check Point management plane

alert if
  SmartConsole or management login token success from IP outside Trusted Clients allowlist
  OR policy package publish without change ticket
  OR logging disable / tracker mute from unexpected admin session
enrich with: source IP vs jumphost inventory, time of day, geo, volume of rule diffs

SIEM logic: SharePoint key theft and webshell

alert if
  w3wp.exe spawns cmd.exe OR powershell.exe OR cscript.exe unexpectedly
  OR new .aspx written under SiteAssets / layouts / random site paths outside deployment window
  OR machineKey configuration change outside Patch Tuesday change record
action: isolate site collection admin sessions, preserve IIS logs, rotate keys if not done post patch

Detection logic: Origin themed phishing

mail|body or sms|body contains_any
  'Origin Energy', 'energy refund', 'disconnection notice', 'update direct debit'
AND link domain not in official allowlist
AND urgency language on payment or identity reverify

Contextual technical headings only. Confirmed items are evidence mapped from consulted sources. Inferred items are labelled inferred.

T1190 edge appliance SSRF on SMA1000 Work Place

Item

Detail

Technique

T1190 Exploit Public Facing Application

Status

Confirmed by evidence

Tactic

Initial Access

Evidence basis

Unauthenticated SSRF on internet facing Work Place (CVE-2026-15409)

What to detect

/wsproxy abuse, appliance outbound to internal or metadata targets

T1105 / T1104 AMC code execution and tool staging on SMA1000

Item

Detail

Technique

T1105 Ingress Tool Transfer; T1104 multi stage or remote service style staging

Status

Confirmed by evidence in consulted chain analysis

Tactic

Execution

Evidence basis

CVE-2026-15410 AMC code injection under administrator context; arbitrary commands and tooling

What to detect

Implant drop, unexpected command execution on appliance, hotfix tamper logs

T1046 internal discovery via SMA1000 SSRF tunnels

Item

Detail

Technique

T1046 Network Service Discovery

Status

Confirmed by evidence

Tactic

Discovery

Evidence basis

/wsproxy probing of internal services and metadata endpoints

What to detect

Appliance to RFC1918 HTTP patterns, metadata IP hits

T1078 valid accounts risk on SMA1000

Item

Detail

Technique

T1078 Valid Accounts

Status

Confirmed as risk by vendor remediation guidance

Tactic

Credential Access

Evidence basis

Guidance to rotate admin credentials and reset TOTP after compromise

What to detect

Reuse of old admin secrets, failed then successful admin logins post incident

SMA1000 inferred techniques

Technique

Tactic

Why inferred

T1059 Command and Scripting Interpreter

Execution

AMC driven OS command execution

T1505.003 Server Software Component Web Shell

Persistence

Python webshell or implant hunt guidance

T1041 Exfiltration Over C2 Channel

Exfiltration

Plausible if odd appliance egress is observed post exploit

T1021 Remote Services

Lateral Movement

Compromised edge VPN as pivot into downstream systems

T1552 Unsecured Credentials

Credential Access

SSRF to metadata or internal planes may expose tokens

WP2Shell inferred techniques

Technique

Tactic

Why inferred

T1190 Exploit Public Facing Application

Initial Access

Unauthenticated REST batch chain to RCE

T1059 Command and Scripting Interpreter

Execution

SQLi chained to code execution and PHP drop

T1505.003 Web Shell / malicious plugin

Persistence

Rogue plugin paths and PHP drops

T1068 Exploitation for Privilege Escalation

Privilege Escalation

Full CMS admin equivalent on stock core

No explicit ATT&CK IDs for WP2Shell were published in the processed primary source set; mappings above are inferred from technical behaviour.

Check Point SmartConsole inferred techniques

Technique

Tactic

Why inferred

T1190 Exploit Public Facing Application

Initial Access

Reachable management GUI auth bypass

T1078 Valid Accounts

Credential Access

Application login token without credentials

T1484 style policy modification impact

Defense impact / integrity

Policy changes via legitimate management channel

T1562 Impair Defenses

Defense Evasion

Logging disablement risk under admin equivalent control

Related CVE-2026-62144 and CVE-2026-62145 support additional Initial Access and Privilege Escalation inferences on the same management family.

SharePoint CVE-2026-50522 inferred techniques

Technique

Tactic

Why inferred

T1190 Exploit Public Facing Application

Initial Access

On prem SharePoint code execution path

T1059 Command and Scripting Interpreter

Execution

CWE-502 deserialization RCE

T1552 credential material theft

Credential Access

ValidationKey and DecryptionKey theft

T1505.003 Web Shell

Persistence

Unauthorized .aspx, odd w3wp.exe children

Note: consulted technical summary states exploitation requires authentication as at least Site Owner for CVE-2026-50522.

Origin Energy MITRE status

Item

Detail

Confirmed techniques

NOT CONFIRMED beyond generic unauthorised access and data disclosure outcomes

Confirmed tactics

NOT CONFIRMED

Inferred only at narrative level

Collection and exfiltration of customer data are outcome classes; Initial Access vector unknown

Rule

Do not assert specific technique IDs without root cause detail

Combined tactical picture

  • Dominant tactics in this window: Initial Access, Execution, Credential Access, Persistence, Discovery

  • Control plane abuse (Check Point) and patch surviving persistence (SharePoint keys, SMA1000 implants, WordPress rogue admins) are the operator relevant themes

  • D3FEND oriented defensive themes implied by consulted remediation: harden public access points, rotate credentials and keys, restrict management plane trust, validate logging integrity, reimage when appliance integrity is doubtful

Chapter 05 - Governance, Risk & Compliance

KEV driven patch governance for edge and management planes

  • Track CISA KEV listed items with named asset owners, not shared inbox ownership

  • Give edge VPN gateways and security management servers the same patch SLA class as identity providers

  • Required evidence package per asset: version attestation, change ticket, compromise assessment checklist, credential or key rotation proof where applicable

  • SonicWall CVE-2026-15409 and CVE-2026-15410: already KEV with short federal deadline earlier in July; late estates are overdue, not merely at risk

  • WordPress CVE-2026-63030: cited federal due date 24 Jul 2026 in consulted reporting; verify on live KEV before executive attestation

  • Check Point CVE-2026-16232 family: cited federal due date 25 Jul 2026 in consulted reporting; verify on live KEV before attestation

  • SharePoint CVE-2026-58644: KEV narrative in mid July; CVE-2026-50522 actively exploited in consulted reporting but not listed on KEV as of this window per SecurityWeek class material

SMA1000 governance controls

  • Board or risk committee language: unauthenticated edge RCE on remote access appliances is a material control failure if internet facing and unpatched

  • Mandate forensic review plus reimage decision tree when IOCs hit; hotfix alone is not acceptance criteria

  • Require TOTP and admin password rotation evidence after any suspected compromise

  • Service providers hosting SMA1000 for customers need multi tenant notification playbooks

WordPress estate governance

  • Auto update is not an audit control; require version attestation (7.0.2 / 6.9.5 / 6.8.6)

  • Agencies and marketing vendors must contractually attest internet facing CMS versions

  • Offline until patched is an accepted business decision for holdouts on deadline day

Check Point management governance

  • Management plane exposure is a policy integrity risk, not only a CVE ticket

  • Ban Trusted Clients Any in secure configuration baselines

  • Require dual control or ticket linkage for policy publishes on internet facing estates

  • End of support trains in the reported R77.30 through R82.10 span need formal migration risk acceptance if still online

SharePoint governance

  • Patch Tuesday completion metrics must include machine key rotation completion, not only CU install percentage

  • Site Owner privilege reviews are a recurring control, not a one time cleanup

  • Treat stolen machine keys as credential compromise equivalent for collaboration farms

Origin Energy privacy and sector trust

  • Confirmed customer data incident at a critical infrastructure energy retailer creates privacy regulator and customer notification duties for Origin

  • External organisations should treat leaked static PII as burned for authentication

  • Fraud monitoring, step up verification, and staff guidance are proportionate third party responses

  • Do not claim OT or generation outage; consulted evidence does not support it

  • Reputational and regulatory exposure extends beyond individual customers to sector trust and resilience narratives

Cross cutting GRC actions this week

Control gap

Business risk

Evidence to collect

Internet facing SMA1000 unpatched or unhunted

Edge takeover, downstream breach

Firmware inventory, log hunt results, reimage records

WordPress version unknown

Mass site takeover, supply chain defacement

Attested versions per property

Check Point Mgmt reachable

Silent perimeter policy rewrite

Trusted Clients config, admin session audit

SharePoint patched without key rotation

Persistent forged access

Key rotation tickets, webshell hunt results

Static PII still used as authenticator

Fraud after Origin style leaks

Auth policy exceptions list

Assurance statement for leadership

Governance processes that only measure “CVE closed in scanner” will miss this window. The auditable bar is patched plus hunted plus rotated plus, where integrity is doubtful, rebuilt.

Chapter 06 - Adversary Emulation

Lab only. No production appliances, no real customer credentials, no internet attacking of third parties.

SMA1000 validation scenarios

Objective: prove detection and response for SSRF style Work Place abuse and post exploit appliance integrity checks without firing real zero days against live VPN users.

  • Build an isolated lab SMA1000 or vendor documented equivalent logging stack with extraweb_access.log and ctrl-service.log forwarding to SIEM

  • Validate parsers alert on synthetic /wsproxy events with internal host parameters

  • Validate alerts on synthetic /_api_/login and /_api_/logout success bursts

  • Validate alerts on synthetic hotfix removal lines with path traversal names

  • Validate egress detections when lab appliance traffic heads to a lab metadata sink

  • Tabletop the reimage decision: IOC present, config backup integrity, credential and TOTP rotation, downstream lateral review

  • Success criteria: detection within agreed MTTD, IR runbook names reimage not “hotfix only”, evidence bag preserved

Purple team notes

  • Do not replay public exploit code against production

  • Prefer log injection or vendor safe test events if available

  • Map exercises to T1190, T1046, T1105, T1078

WP2Shell validation scenarios

Objective: prove web tier detections for batch endpoint abuse and post exploitation CMS integrity checks.

  • Staging WordPress only on vulnerable trains inside an isolated VLAN, or use request replay against a deliberately vulnerable lab clone

  • Send POST traffic to batch REST paths including author__not_in style query patterns

  • Confirm WAF or SIEM critical alerts fire

  • After simulated compromise: verify hunts for rogue admins and unexpected plugins

  • Success criteria: version attestation process catches lab host still on 7.0.1 class builds; SOC playbook isolates web root and rotates salts or secrets

Purple team notes

  • Keep PoC use inside lab; do not target third party sites

  • Map to T1190, T1059, T1505.003

Check Point management validation scenarios

Objective: prove that management plane abuse is visible when tokens or admin sessions originate off allowlist.

  • In lab management, confirm Trusted Clients is enforced and Any is rejected by config compliance checks

  • Simulate or replay admin session from non jumphost IP in a controlled window

  • Push a benign labelled test policy change and confirm ticket linkage monitoring

  • Simulate logging disable attempt and confirm high severity alert

  • Success criteria: SOC treats off allowlist management success as IR, not as noise; gateway policy integrity check is in the runbook

Purple team notes

  • Never test auth bypass on production management

  • Map to T1190, T1078, T1562, policy integrity checks

SharePoint validation scenarios

Objective: prove patch plus key rotation plus webshell behavioural detections.

  • Lab farm on supported SharePoint builds

  • Confirm July CU presence via inventory

  • Execute controlled machine key rotation and confirm monitoring sees the change under change control

  • Drop a benign marked test .aspx in a non prod library path and confirm FIM or SIEM alert

  • Simulate odd w3wp.exe child process with a safe coded test harness if available in purple tooling

  • Success criteria: “patched but keys not rotated” fails compliance; webshell behavioural rules page on call

Purple team notes

  • No production deserialization exploit replay

  • Map to T1190, T1059, T1552, T1505.003

Origin Energy third party breach tabletop

Objective: rehearse fraud and customer trust response when a major energy retailer confirms customer data exposure.

  • Inject synthetic phishing samples referencing energy refunds, disconnections, and payment updates

  • Run helpdesk social engineering drills that try to pass static PII as proof of identity

  • Exercise step up verification and official channel only callbacks

  • Coordinate comms, fraud, privacy, and SOC on one timeline

  • Success criteria: static PII alone never unlocks high risk account changes; detection rules catch lure themes within the drill window

Purple team notes

  • No use of real Origin customer data

  • No claims of OT impact in exercise injects unless separately evidenced

Emulation schedule suggestion for the next 72 hours

Order

Scenario

Owner

Exit gate

1

WordPress version attestation drill

Web or CMS ops

All internet facing properties attested or offline

2

SMA1000 log hunt plus egress review

Network IR

Hunt complete; reimage decisions documented

3

Check Point Trusted Clients and admin session audit

Firewall engineering

Any removed; off allowlist sessions reviewed

4

SharePoint key rotation proof plus .aspx hunt

Collaboration platform team

Keys rotated; hunt closed or IR opened

5

Origin themed phishing tabletop

Fraud + SOC + comms

Playbooks updated the same day

Safety and scope boundaries

  • Lab networks only for exploit class tests

  • No scanning of customer or partner assets without written authorisation

  • No production credential use in purple scripts

  • Record every test IOC so defenders can expire them after the exercise

Intelligence Confidence82%

Item

Score

Rationale

SonicWall SMA1000

82 High

KEV + vendor + multi firm corroboration; actors unclear

WP2Shell

70 Medium High

In the wild + PoCs strong; some KEV deadline wording secondary

Check Point Mgmt

60 Medium

Vendor advisory + exploitation reported; smaller victim set

SharePoint 50522

68 Medium High

Patch, PoC, key theft pattern solid; 50522 not on KEV in window

Origin Energy

62 Medium

Breach confirmed; root cause and full scope incomplete

Overall

72 Medium High

Evidence led merge; stronger sources win on conflicts