WARLOCK

RANSOMWARE

Confirmed CVEs (5)

Exploited by this group as confirmed by threat intelligence sources.

CVE-2026-23760 CRITICAL SmarterTools SmarterMail 9.8 CVE-2025-40551 CRITICAL SolarWinds Web Help Desk 9.8 CVE-2025-14611 CRITICAL Gladinet CentreStack and TrioFox 9.8 CVE-2025-49704 HIGH Microsoft SharePoint Enterprise Server 2016 8.8 CVE-2025-49706 MEDIUM Microsoft SharePoint Enterprise Server 2016 6.5

Predicted CVEs (7) CORRELATION

How does prediction work?

Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.

CVE-2025-52691 CRITICAL SmarterTools SmarterMail predicted 10.0 CVE-2026-24423 CRITICAL SmarterTools SmarterMail predicted 9.8 CVE-2026-23760 CRITICAL SmarterTools SmarterMail predicted 9.8 CVE-2025-53770 CRITICAL Microsoft SharePoint Enterprise Server 2016 predicted 9.8 CVE-2025-49704 HIGH Microsoft SharePoint Enterprise Server 2016 predicted 8.8 CVE-2024-38094 HIGH Microsoft SharePoint Enterprise Server 2016 predicted 7.2 CVE-2025-49706 MEDIUM Microsoft SharePoint Enterprise Server 2016 predicted 6.5