New ThreatClaw Detections: Exploited CVEs in VMware, SharePoint & MLflow
This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.
New ThreatClaw Detections: Exploited CVEs in VMware, SharePoint & MLflow
This week, ThreatClaw enhanced detection coverage for 8 newly exploited vulnerabilities in enterprise and cloud environments. These additions address high-risk CVEs actively leveraged by advanced threat actors to compromise systems, escalate privileges, or exfiltrate data. Below is a breakdown of the threats and their operational impact.
Coverage Highlights
- 8 newly exploited CVEs added to detection rules, spanning VMware, Microsoft, Apple, and open-source platforms.
- No new Sigma or Yara rules this period; focus remains on refining existing detection logic for these CVEs.
- Total coverage now stands at 6,400+ Sigma rules and 8,000+ Yara files.
Why These Threats Matter
VMware vCenter (CVE-2026-59310)
VMware vCenter is a cornerstone of virtualized infrastructure, making it a prime target for attackers. This vulnerability enables remote code execution (RCE) (ATT&CK T1210), allowing threat actors to gain control over virtualized environments. Compromised vCenter instances can lead to lateral movement across entire data centers, making this a critical detection priority for enterprises.
Microsoft SharePoint (CVE-2026-55040)
SharePoint is widely used for document management and collaboration, often storing sensitive corporate data. This flaw permits privilege escalation (ATT&CK T1068), enabling attackers to access restricted documents, modify permissions, or deploy malicious payloads. Given SharePoint’s integration with Microsoft 365, exploitation could facilitate broader credential theft or data exfiltration.
MLflow (CVE-2026-64849)
MLflow, a popular open-source platform for machine learning lifecycle management, is increasingly targeted due to its role in AI/ML pipelines. This vulnerability allows arbitrary code execution (ATT&CK T1059), which could be used to poison training datasets, steal proprietary models, or pivot into broader cloud environments. As AI adoption grows, securing ML workflows is critical to preventing intellectual property theft or sabotage.
Microsoft IKE Extensions (CVE-2026-33824)
The Internet Key Exchange (IKE) protocol is essential for secure VPN communications. This flaw enables denial-of-service (DoS) attacks (ATT&CK T1499) or potential man-in-the-middle (MITM) exploitation (ATT&CK T1557), disrupting remote access or intercepting encrypted traffic. For organizations relying on VPNs for secure connectivity, this poses a significant risk to operational continuity.
Apple macOS (CVE-2026-65400)
This vulnerability affects macOS systems, allowing local privilege escalation (ATT&CK T1068). While macOS is often perceived as less targeted, its growing adoption in enterprise environments makes it a valuable foothold for attackers. Exploitation could lead to unauthorized access to sensitive data or the deployment of persistent malware.
TrueConf Server (CVE-2026-72530, CVE-2026-72529)
TrueConf Server is a video conferencing and collaboration platform. These vulnerabilities enable RCE (ATT&CK T1210), which could be used to intercept communications, deploy spyware, or move laterally within networks. As remote collaboration tools remain critical, securing them is essential to preventing espionage or data leaks.
Ray (CVE-2025-62593)
Ray, a distributed computing framework, is used in large-scale data processing and AI workloads. This flaw allows unauthenticated RCE (ATT&CK T1210), posing risks to cloud-native environments. Attackers could exploit it to hijack compute resources, steal data, or disrupt AI-driven operations.
Call to Action
These updates reflect ThreatClaw’s commitment to staying ahead of emerging threats. For comprehensive detection coverage, including real-time alerts and advanced threat intelligence, explore ThreatClaw Premium at https://threatclaw.io/en/feeds.
Related articles
This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.
ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.
This week, ThreatClaw expands detection for 12 newly exploited CVEs, including critical flaws in Microsoft SharePoint, Fortinet FortiSandbox, and Oracle E-Business Suite.
This week, ThreatClaw expands coverage for actively exploited CMS vulnerabilities (CVE-2026-48908, CVE-2026-56290) and suspicious firmware updates (T1542.001), hardening defenses against supply-chain attacks.