Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026)
Weekly briefing: SharePoint deserialization RCE, Oracle PeopleSoft zero-day chain (100+ breaches), EY breach, and Capital One VulnHunter.
This week brought another actively exploited SharePoint deserialization flaw, Oracle's largest Critical Patch Update on record (with the PeopleSoft zero-day behind the ShinyHunters higher-ed breaches finally patched), a confirmed EY breach exposing client tax data, a critical SAP NetWeaver flaw, and Capital One open-sourcing an agentic AI vulnerability hunter. Details, CVEs, and remediation below.
Another SharePoint RCE Under Active Exploitation
A new Microsoft SharePoint Server vulnerability, CVE-2026-50522 (CVSS 9.8), is under active exploitation just days after a public proof-of-concept exploit went live. The flaw is a deserialization of untrusted data bug that lets an unauthenticated attacker achieve remote code execution over the network, and researchers have observed attackers using it to steal IIS machine keys for persistence, a pattern familiar from prior SharePoint attack waves. CISA added the CVE to its Known Exploited Vulnerabilities catalog on July 22, giving federal agencies until July 25 to remediate.
Remediation: patch all on-premises SharePoint Server instances (Subscription Edition, 2019, and 2016) immediately, and rotate ASP.NET machine keys regardless of whether compromise is confirmed, since a stolen key survives a patch.
Oracle's Largest-Ever Critical Patch Update
Oracle shipped its biggest Critical Patch Update ever this week: 1,434 CVEs across 334 products, including ten CVSS 10.0 flaws in Fusion Middleware. Buried in the PeopleSoft portion of the update (84 patches) is the fix for the zero-day chain, CVE-2026-35273 and CVE-2026-35278, both pre-authentication RCE in PeopleTools, that the ShinyHunters extortion group used to compromise roughly 300 PeopleSoft installations at more than 100 organizations, mostly universities and hospitals, between May 27 and June 9.
Remediation: apply Oracle's July CPU across all affected product lines as soon as possible, and treat PeopleSoft PeopleTools as a priority given confirmed pre-disclosure exploitation. If you run PeopleSoft, review logs from late May through early June for signs of prior compromise even after patching.
EY Confirms Breach of Third-Party IT Support Platform
Ernst & Young confirmed a breach after an unauthorized party accessed a third-party IT service management platform used by EY support staff between late March and mid-April, exfiltrating documents containing client tax data, including names, addresses, Social Security numbers, and payment card information. EY detected the anomalous activity in late April and filed breach notifications with regulators in mid-July.
Remediation: EY clients should watch for phishing or tax-fraud attempts referencing exposed personal data, and consider credit monitoring or an identity-theft protection service given the presence of Social Security numbers in the exposed documents.
SAP Patches CVSS 9.9 NetWeaver Flaw
SAP's July Patch Day included a fix for CVE-2026-44747 (CVSS 9.9), an out-of-bounds write in the NetWeaver AS ABAP kernel that allows a low-privileged, authenticated attacker to corrupt memory over the network with no user interaction, risking both data integrity and system availability.
Remediation: apply SAP Security Note 3747367 and update to the patched ABAP kernel version across affected NetWeaver deployments.
Capital One Open-Sources VulnHunter, an Agentic AI Vulnerability Hunter
Capital One released VulnHunter, an open-source, Apache 2.0-licensed tool that uses an agentic AI workflow to analyze source code from an attacker's perspective, trace exploitable paths, and propose fixes rather than just flagging patterns like a traditional static scanner. The initial release is built as a Claude Code skill optimized for Claude Opus 4.8.
Remediation: not applicable, this is a defensive tooling release. Security and AppSec teams evaluating AI-assisted code review may want to test it against existing SAST tooling.
Deep Dives
Deeper technical breakdowns of this week's top stories:
CVE-2026-50522: Microsoft SharePoint's Next Deserialization RCE, Exploited Days After a Public PoC, at colibrisec.org/cve-2026-50522-microsoft-sharepoints-next-deserialization-rce-exploited-days-after-a-public-poc/
CVE-2026-35273 & CVE-2026-35278: The Oracle PeopleSoft Zero-Day Chain Behind 100+ Breaches, at colibrisec.org/cve-2026-35273-cve-2026-35278-the-oracle-peoplesoft-zero-day-chain-behind-100-breaches/
EY Breach: What Was Taken, Who's Affected, and What Clients Should Do, at colibrisec.org/ey-breach-what-was-taken-whos-affected-and-what-clients-should-do/
VulnHunter: How Capital One Is Using Agentic AI to Hunt Vulnerabilities Before Attackers Do, at colibrisec.org/vulnhunter-how-capital-one-is-using-agentic-ai-to-hunt-vulnerabilities-before-attackers-do/
Sources
The Hacker News, Help Net Security, Security Affairs: CVE-2026-50522 SharePoint RCE.
CISA: KEV catalog addition, July 22, 2026.
Qualys, CSO Online, TechTimes, Rapid7, Picus Security: Oracle July 2026 CPU and CVE-2026-35273 / CVE-2026-35278.
SecurityWeek, UpGuard, CyberSecurityNews: EY breach.
The Hacker News, SecurityWeek: SAP NetWeaver CVE-2026-44747.
VentureBeat, Capital One Tech: VulnHunter release.