This week saw the disclosure of several critical vulnerabilities affecting widely deployed enterprise technologies, with Microsoft SharePoint and SonicWall SMA1000 topping the list due to confirmed active exploitation. Other notable advisories impacted Dell PowerProtect Data Domain, Splunk Enterprise, Zoom Workplace, JetBrains development platforms, and AnyDesk, highlighting continued attacker interest in remote access infrastructure, collaboration platforms, backup systems, and software development environments.
Key Vulnerabilities
Microsoft SharePoint Server - Actively Exploited
Multiple critical vulnerabilities affecting on-premises SharePoint Server are being actively exploited to achieve remote code execution, privilege escalation, authentication bypass, and persistent access. Attackers have been observed stealing IIS machine keys and deploying malware, prompting CISA to add the vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog with expedited remediation timelines.
SonicWall SMA1000 – Critical Zero-Day
SonicWall disclosed two actively exploited zero-day vulnerabilities affecting SMA1000 appliances. The flaws can be chained to achieve unauthenticated remote code execution and full root access, with public proof-of-concept exploit code already available and additional exploitation tooling expected.
Dell PowerProtect Data Domain
Dell addressed a large collection of critical vulnerabilities affecting PowerProtect Data Domain appliances, including authentication bypass, path traversal, command injection, and privilege escalation flaws. Several vulnerabilities require no authentication, placing enterprise backup infrastructure at significant risk.
Splunk Enterprise & Zoom Workplace
Splunk released patches for multiple vulnerabilities, including command safeguards bypass and path traversal issues, while Zoom fixed a critical vulnerability that could allow unauthenticated account takeover on Windows clients. Although no active exploitation has been reported, both products remain attractive enterprise targets.
JetBrains Products
JetBrains resolved six vulnerabilities affecting IntelliJ IDEA, TeamCity, and YouTrack. The most severe issue could allow code execution through path traversal, while additional flaws impact CI/CD pipeline integrity and web application security.
AnyDesk
A newly disclosed zero-day vulnerability allows local attackers to trigger a denial-of-service condition by abusing the application's support information feature. Although exploitation requires prior local access, organizations should monitor vendor advisories for a forthcoming security update.
Trends Observed
This week's vulnerabilities reveal several recurring attack patterns:
- Active exploitation remains focused on internet-facing enterprise infrastructure, particularly remote access gateways and collaboration platforms.
- Remote Code Execution (RCE) continues to be the dominant attack objective, often achieved by chaining multiple vulnerabilities together.
- Authentication bypass and privilege escalation continue to feature prominently, allowing attackers to move from initial access to full system compromise.
- Backup and disaster recovery infrastructure is increasingly being targeted, reinforcing ransomware operators' focus on disrupting recovery capabilities.
- Development and CI/CD platforms continue to attract attention, reflecting ongoing interest in software supply chain compromise.
- Multiple vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, highlighting the speed at which newly disclosed flaws are being weaponized.
Overall Business Impact
If left unpatched, these vulnerabilities could enable attackers to gain unauthorized access to enterprise environments, execute arbitrary code, compromise privileged accounts, deploy malware or ransomware, steal sensitive data, disrupt backup and recovery operations, and establish long-term persistence within corporate networks. Organizations with internet-facing services remain at the highest risk.
Recommended Actions
Organizations should prioritize remediation using a risk-based approach:
- Immediately patch Microsoft SharePoint and SonicWall SMA1000 systems, as both are under active exploitation.
- Prioritize internet-facing systems, including remote access appliances, collaboration platforms, backup infrastructure, and development environments.
- Review affected systems for indicators of compromise (IOCs) before and after applying security updates.
- Validate that backup systems remain secure and recoverable following remediation.



.jpeg)

.jpeg)

.png)

.png)
.png)