- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,294
Positive Technologies has included four vulnerabilities in the May trendy threats digest.

Positive Technologies has included four vulnerabilities in the May digest that are already being used in attacks or can quickly turn into a massive problem for administrators. The list includes the shortcomings in Microsoft SharePoint Server, the Linux cryptographic subsystem, Apache ActiveMQ Classic and Adobe Acrobat Reader.
The vulnerability PT-2026-32853, also known as CVE-2026-32201, affects Microsoft SharePoint Server and received 6.5 points on the CVSS scale. Microsoft has warned that the problem has already been used in real attacks. Defused researchers linked the possible operation to the campaign against SharePoint servers, which took place from 1 to 11 April 2026.
Organizations using Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 are at risk. Particularly risky is the configuration in which SharePoint servers are available from the external network.
The lack of information allows an unauthenticated attacker to remotely replace the data transmitted over the network. Microsoft does not disclose the details of the operation, but experts suggest that the attacker can implement
Microsoft has closed the vulnerability as part of the April set of fixes. Administrators are advised to install security updates, and as a temporary measure, limit remote access to vulnerable systems with firewall screening tools.
The second problem, PT-2026-34274 or CVE-2026-31431CVE-2026-31431, is associated with the Linux kernel cryptographic API and received 7.8 points on the CVSS scale. The Copy Fail vulnerability affects the AF_ALG component and allows a local unprivileged user to increase rights to root.
After successful operation, the attacker can get full control over the system: read and change any files, including passwords and keys, replace system components, turn off the protective mechanisms, install backdoors and hide activity traces. The operation was confirmed on current versions of popular Linux distributions, including Ubuntu, Amazon Linux, RHEL and SUSE.
Administrators are advised to upgrade the Linux kernel to the corrected versions 6.18.22, 6.19.12 or 7.07.0. As an additional measure, the researchers advise to disable the algorithm algif_aead if the component is not needed in the work infrastructure.
The third vulnerability, PT-2026-30805 or CVE-2026-34197CVE-2026-34197, affects the Apache ActiveMQ Classic and received 8.8 points on the CVSS scale. According to the Shadowserver Foundation, more than 7000 Apache ActiveMQ servers remain vulnerable. Fortinet FortiGuard Labs recorded the beginning of operation in real attacks on April 13.
The problem is associated with insufficient verification of input data and uncontrolled data generation. Collectively, errors allow an attacker to implement and execute arbitrary commands on a vulnerable ActiveMQ Classic server.
After a successful attack, the attacker can gain full control over the server, steal messages, credentials or configuration files, set up malware and use the compromised system as an entry point to the internal infrastructure.
ActiveMQ Classic users are advised to switch to Apache ActiveMQ 5.5.4 or 6.2.3. Additionally, it is worth disabling Jolokia if the component is not used, close the port 8161 from external access, replace the standard admin attendant accounts, restrict access to the internal network management web interface and check logs for suspicious calls to addConnector.
The fourth vulnerability, PT-2026-32093 or CVE-2026-34621, affects Adobe Acrobat Reader, Acrobat DC and Acrobat 2024 for Windows and macOS. The disadvantage received 8.6 points on the CVSS scale and allows you to remotely execute arbitrary code after opening a specially prepared PDF document.
Adobe has confirmed that the CVE-2026-34621 has already been used in real attacks. According to the researchers, the operation could have been carried out at least since November 2025. It was also reported about malicious PDF documents with bait in Russian related to events in the oil and gas industry of Russia. Such a set of signs may indicate targeted attacks against Russian organizations.
Malicious PDF could secretly read files on a vulnerable system, transfer sensitive data to the attackers’ server, and download additional malicious scripts to develop the attack. To start the chain, it was enough for the user to open the prepared document in a vulnerable version of the program.
Adobe has released emergency security updates. Users of Acrobat Reader and Acrobat are recommended to install the latest versions through the built-in Help > Check for Updates, auto-update or official Adobe installer. Before installing corrections, PDF files from external sources are better to open only after an additional check.

Positive Technologies has included four vulnerabilities in the May digest that are already being used in attacks or can quickly turn into a massive problem for administrators. The list includes the shortcomings in Microsoft SharePoint Server, the Linux cryptographic subsystem, Apache ActiveMQ Classic and Adobe Acrobat Reader.
The vulnerability PT-2026-32853, also known as CVE-2026-32201, affects Microsoft SharePoint Server and received 6.5 points on the CVSS scale. Microsoft has warned that the problem has already been used in real attacks. Defused researchers linked the possible operation to the campaign against SharePoint servers, which took place from 1 to 11 April 2026.
Organizations using Microsoft SharePoint Server Subscription Edition, Microsoft SharePoint Server 2019 and Microsoft SharePoint Enterprise Server 2016 are at risk. Particularly risky is the configuration in which SharePoint servers are available from the external network.
The lack of information allows an unauthenticated attacker to remotely replace the data transmitted over the network. Microsoft does not disclose the details of the operation, but experts suggest that the attacker can implement
Microsoft has closed the vulnerability as part of the April set of fixes. Administrators are advised to install security updates, and as a temporary measure, limit remote access to vulnerable systems with firewall screening tools.
The second problem, PT-2026-34274 or CVE-2026-31431CVE-2026-31431, is associated with the Linux kernel cryptographic API and received 7.8 points on the CVSS scale. The Copy Fail vulnerability affects the AF_ALG component and allows a local unprivileged user to increase rights to root.
After successful operation, the attacker can get full control over the system: read and change any files, including passwords and keys, replace system components, turn off the protective mechanisms, install backdoors and hide activity traces. The operation was confirmed on current versions of popular Linux distributions, including Ubuntu, Amazon Linux, RHEL and SUSE.
Administrators are advised to upgrade the Linux kernel to the corrected versions 6.18.22, 6.19.12 or 7.07.0. As an additional measure, the researchers advise to disable the algorithm algif_aead if the component is not needed in the work infrastructure.
The third vulnerability, PT-2026-30805 or CVE-2026-34197CVE-2026-34197, affects the Apache ActiveMQ Classic and received 8.8 points on the CVSS scale. According to the Shadowserver Foundation, more than 7000 Apache ActiveMQ servers remain vulnerable. Fortinet FortiGuard Labs recorded the beginning of operation in real attacks on April 13.
The problem is associated with insufficient verification of input data and uncontrolled data generation. Collectively, errors allow an attacker to implement and execute arbitrary commands on a vulnerable ActiveMQ Classic server.
After a successful attack, the attacker can gain full control over the server, steal messages, credentials or configuration files, set up malware and use the compromised system as an entry point to the internal infrastructure.
ActiveMQ Classic users are advised to switch to Apache ActiveMQ 5.5.4 or 6.2.3. Additionally, it is worth disabling Jolokia if the component is not used, close the port 8161 from external access, replace the standard admin attendant accounts, restrict access to the internal network management web interface and check logs for suspicious calls to addConnector.
The fourth vulnerability, PT-2026-32093 or CVE-2026-34621, affects Adobe Acrobat Reader, Acrobat DC and Acrobat 2024 for Windows and macOS. The disadvantage received 8.6 points on the CVSS scale and allows you to remotely execute arbitrary code after opening a specially prepared PDF document.
Adobe has confirmed that the CVE-2026-34621 has already been used in real attacks. According to the researchers, the operation could have been carried out at least since November 2025. It was also reported about malicious PDF documents with bait in Russian related to events in the oil and gas industry of Russia. Such a set of signs may indicate targeted attacks against Russian organizations.
Malicious PDF could secretly read files on a vulnerable system, transfer sensitive data to the attackers’ server, and download additional malicious scripts to develop the attack. To start the chain, it was enough for the user to open the prepared document in a vulnerable version of the program.
Adobe has released emergency security updates. Users of Acrobat Reader and Acrobat are recommended to install the latest versions through the built-in Help > Check for Updates, auto-update or official Adobe installer. Before installing corrections, PDF files from external sources are better to open only after an additional check.