New ThreatClaw Coverage: Exploited CVEs in SharePoint, Fortinet & Oracle
This week, ThreatClaw expands detection for 12 newly exploited CVEs, including critical flaws in Microsoft SharePoint, Fortinet FortiSandbox, and Oracle E-Business Suite.
New ThreatClaw Detection: Exploited CVEs in SharePoint, Fortinet, and Oracle
This week, ThreatClaw enhanced detection coverage for 12 newly exploited vulnerabilities, reinforcing defenses against advanced threat actors targeting enterprise and edge infrastructure. Below is a breakdown of the critical CVEs now detected, their impact, and the MITRE ATT&CK techniques they enable.
Microsoft SharePoint and Active Directory Under Attack
-
CVE-2026-58644 (Microsoft SharePoint) Exploitation of this flaw allows threat actors to bypass authentication and execute arbitrary code on SharePoint servers. This aligns with T1190 (Exploit Public-Facing Application) and T1078 (Valid Accounts), enabling lateral movement within enterprise environments.
-
CVE-2026-56164 (Microsoft SharePoint Server) A separate SharePoint vulnerability enabling privilege escalation, facilitating T1068 (Exploitation for Privilege Escalation). Compromised SharePoint instances can serve as a launchpad for broader network infiltration.
-
CVE-2026-56155 (Active Directory Federation Services) Exploitation grants attackers persistent access to federated identity systems, enabling T1078.004 (Domain Accounts) and T1556 (Modify Authentication Process). This is particularly critical for organizations relying on SSO and hybrid cloud environments.
Fortinet FortiSandbox Vulnerabilities
- CVE-2026-25089 & CVE-2026-39808 (Fortinet FortiSandbox) These flaws allow remote code execution on FortiSandbox appliances, enabling T1210 (Exploitation of Remote Services). Threat actors can leverage compromised sandboxing solutions to evade detection and propagate malware across the network.
Oracle E-Business Suite at Risk
- CVE-2026-46817 (Oracle E-Business Suite) Exploitation of this vulnerability permits unauthorized access to sensitive financial and operational data, aligning with T1005 (Data from Local System) and T1530 (Data from Cloud Storage). Oracle E-Business Suite is a high-value target due to its integration with ERP and supply chain systems.
Edge and IoT Infrastructure Threats
-
CVE-2026-15409 & CVE-2026-15410 (SonicWall SMA1000 Appliances) These vulnerabilities enable authentication bypass and remote code execution on SonicWall SMA appliances, facilitating T1133 (External Remote Services). Compromised VPN gateways can serve as entry points for ransomware and data exfiltration.
-
CVE-2023-4346 (KNX Protocol) Exploitation of this flaw in building automation systems allows attackers to manipulate physical infrastructure, aligning with T0886 (Manipulation of Control). This poses risks to smart buildings and industrial environments.
-
CVE-2008-4128 (Cisco IOS) A legacy but still-exploited vulnerability enabling denial-of-service attacks on Cisco routers, disrupting network availability (T1499.004 (Endpoint Denial of Service)).
Web Application and CMS Flaws
-
CVE-2026-56291 (Balbooa Forms) Exploitation allows arbitrary file uploads, enabling T1105 (Ingress Tool Transfer) and T1505.003 (Web Shell). Compromised web forms can serve as initial access vectors for further attacks.
-
CVE-2026-48939 (iCagenda) This vulnerability permits SQL injection, enabling T1190 (Exploit Public-Facing Application) and T1505.001 (SQL Stored Procedures). Attackers can extract sensitive data or escalate privileges within web applications.
Why This Matters
These vulnerabilities are actively exploited by advanced threat actors to gain footholds in enterprise networks, escalate privileges, and exfiltrate data. Many of these flaws enable initial access (TA0001), persistence (TA0003), and lateral movement (TA0008), making them critical to detect and mitigate.
Stay Ahead with ThreatClaw Premium
ThreatClaw Premium subscribers receive real-time detection rule updates, ensuring immediate protection against emerging threats. With 6,400+ Sigma rules and 8,000+ YARA signatures, ThreatClaw provides comprehensive coverage for enterprise environments. Upgrade to ThreatClaw Premium to safeguard your organization against the latest exploits.
Related articles
This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.
This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.
ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.
This week, ThreatClaw expands coverage for actively exploited CMS vulnerabilities (CVE-2026-48908, CVE-2026-56290) and suspicious firmware updates (T1542.001), hardening defenses against supply-chain attacks.