Active exploitation of vulnerabilities affecting the open-source automation platform Windmill and Microsoft SharePoint added to an already busy month for enterprise defenders. While the flaws differ technically, the attacks share a common objective. They seek credentials, secrets, and cryptographic material that enable deeper access into enterprise environments.
Windmill is being targeted through a path traversal vulnerability that allows attackers to retrieve sensitive server files, including secrets that can enable administrative code execution under certain configurations.
SharePoint tells a similar story from a different angle. Researchers observed attackers stealing machine keys to maintain trusted access even after systems are patched, illustrating how many intrusion campaigns are designed to preserve access long after the initial vulnerability is remediated.
Why It Matters: Patching is only one part of recovery. Once attackers obtain privileged material from a compromised application, software updates alone may not fully remove the risk. Determining what was exposed, rotating affected credentials or keys, and validating trusted access become equally important steps in restoring the environment.
- Windmill Raises the Stakes: Attackers are exploiting CVE-2026-29059, an unauthenticated path traversal vulnerability affecting the get log file endpoint, to retrieve sensitive files from vulnerable servers. While researchers observed attempts to access etc passwd, the more significant target is the SUPERADMIN SECRET environment variable. When configured, that secret can be used to authenticate as a super administrator and execute arbitrary code through Windmill’s job preview API. Windmill fixed the vulnerability in version 1.603.3, though exposed deployments should be assessed for potential credential exposure.
- Exposure Remains Widespread: VulnCheck identified approximately 170 vulnerable Windmill instances across 24 countries and observed exploitation targeting direct deployments as well as systems exposed through Nextcloud proxy paths. The activity reinforces the importance of identifying internet-facing enterprise applications before attackers do.
- SharePoint Targets Persistence: Microsoft patched CVE-2026-50522 in July after Defused observed exploitation and WatchTowr later confirmed active attacks following public proof-of-concept release. The vulnerability joins CVE-2026-58644, CVE-2026-56164, and CVE-2026-45659, making it the fourth SharePoint vulnerability disclosed under active exploitation within roughly a month. WatchTowr also reported attackers stealing SharePoint machine keys to maintain trusted access after systems are patched, making credential and key rotation an important part of recovery.
- Exploitation Continues to Expand: CISA added four more vulnerabilities to its Known Exploited Vulnerabilities catalog, including the WordPress wp2shell chain, a DD-WRT buffer overflow, and a Langflow remote code execution flaw. Wordfence characterized wp2shell as one of the most significant WordPress security events in recent years, while KEVIntel observed Langflow exploitation progressing from reconnaissance to attempts to obtain AWS credentials, environment variables, container metadata, and deploy follow-on malware.
- Trust Is the Prize: Attackers place a premium on trusted access. Once privileged authentication material is compromised, patching the underlying vulnerability may not fully remove the risk. Recovery often depends on validating what was exposed and restoring trust across affected systems.
Fourth SharePoint Vulnerability Exploited in Past Month’s Wave of Attacks – SecurityWeek
Trusted insights for technology leaders
Our readers are CIOs, CTOs, and senior IT executives who rely on The National CIO Review for smart, curated takes on the trends shaping the enterprise, from GenAI to cybersecurity and beyond.
Subscribe to our 4x a week newsletter to keep up with the insights that matter.


