Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
41 clusters · 142 sources · 129 days · First seen · Last updated
Software vulnerability exploits & patch response, 2026
Overview
The wave of exploitation observed in July 2026 continued into August, with significant impacts on government infrastructure and core operating systems. In Switzerland, the breach of federal SharePoint servers was further detailed. Unknown actors exploited CVE-2026-56164 and CVE-2026-50522 to access the Federal Office for Information Technology and Telecommunication (BIT) servers. The breach, detected on 28 July 2026, resulted in the compromise of approximately 200 user and technical accounts. In response, the Swiss government isolated the servers, disconnected them from the internet, and initiated a full environment rebuild. While BIT is working with Microsoft and the Federal Office for Cybersecurity (BACS) on forensics, officials stated that no confidential or sensitive personal data is believed to have been stored on the platform, and no evidence of dark web exfiltration has been found. Simultaneously, Microsoft’s August security updates addressed 398 vulnerabilities, including 62 critical flaws. A notable active exploit, CVE-2026-68820, targets a use-after-free error in the Windows Ancillary Function Driver for WinSock (afd.sys). New disclosures in mid-August highlighted further critical risks. Oasis Security identified CVE-2026-41679, a CVSS 10.0 vulnerability in the Paperclip orchestration platform. Researchers also identified an unauthenticated RCE chain in Microsoft SharePoint, combining a JWT authentication-bypass (CVE-2026-55040) with a flaw in Business Connectivity Services (CVE-2026-63520). Further research uncovered complex chains targeting the Windows kernel and hypervisor, dubbed ‘Download More RAM,’ which can bypass Virtualization-Based Security (VBS). Additionally, a vulnerability in Microsoft System Center Configuration Manager (SCCM) allows remote code execution via an authorization issue and a path traversal flaw known as ‘CabSlip.’ In late August, Microsoft addressed CVE-2026-50522 in SharePoint, involving untrusted data deserialization. Concurrently, Microsoft disclosed a critical remote code execution (RCE) vulnerability in Entra ID, tracked as CVE-2026-69836. In early September 2026, new critical vulnerabilities emerged.
Entities
Microsoft · Microsoft Entra ID · SharePoint · Robert Fitzpatrick · CISA
Claims
What the coverage asserts, and how many sources carry each claim.
Coverage disagrees
Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.
-
"Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April."
vs
"Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April."
The claims provide different specific counts (90 vs 141) for the number of vulnerabilities identified by Claude Mythos Preview in SharePoint in April.
- [DISPUTED] Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April.
- [DISPUTED] Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April.
- [● 4 SOURCES] Around 300 medium‑severity SharePoint findings were deprioritized for later remediation.
- [● 3 SOURCES] Hundreds of serious vulnerabilities were also discovered in Microsoft 365, Teams and Copilot by May.
- [● 3 SOURCES] Four low‑severity flaws can be chained together to create a high‑severity vulnerability.
- [● 3 SOURCES] Microsoft has fully mitigated the CVE-2026-69836 vulnerability on its servers. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 3 SOURCES] The CVE-2026-69836 vulnerability was actively exploited by threat actors before being patched. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 3 SOURCES] Microsoft principal security engineer Robert Fitzpatrick discovered and reported the vulnerability. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 3 SOURCES] The CVE-2026-69836 vulnerability has a CVSS score of 10.0. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 3 SOURCES] The vulnerability is caused by the unsafe deserialization of untrusted data. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 3 SOURCES] Because Entra ID is a managed cloud service, users do not need to install any patches or updates. borncity.com · www.it-connect.fr · thecyberexpress.com
- [● 2 SOURCES] Microsoft engineers held an internal meeting in mid‑May to accelerate patching, setting May 31 as a deadline before the wider security community could catch up.
Timeline
-
9 days ago
[TECHNOLOGY] 4 sourcesMicrosoft discloses nine vulnerabilities including two critical CVSS 10.0 flawsMicrosoft disclosed nine vulnerabilities, including two with a CVSS 10.0 rating, affecting Azure AD B2C, Entra ID, and Copilot Studio due to authentication and authorization bypasses.
-
12 days ago
[TECHNOLOGY] 3 sourcesMozilla and Microsoft patch critical software vulnerabilitiesMozilla patched a critical Thunderbird vulnerability involving malicious calendar invites, while Microsoft resolved a high-severity RCE flaw in Entra ID that was not actively exploited.
-
21 days ago
[TECHNOLOGY] 3 sourcesMicrosoft Entra ID vulnerability receives maximum CVSS 10.0 ratingMicrosoft patched a critical CVE-2026-69836 vulnerability in Entra ID with a maximum CVSS score of 10.0. The flaw allowed unauthenticated remote code execution via untrusted data deserialization.
-
23 days ago
[TECHNOLOGY] 7 sourcesMicrosoft patches critical Entra ID remote code execution vulnerabilityMicrosoft has patched a critical 10.0 CVSS-rated remote code execution vulnerability in Entra ID. The flaw was discovered internally and fixed on the server side, requiring no action from customers.
-
25 days ago
[TECHNOLOGY] 13 sourcesMicrosoft Entra ID critical RCE vulnerability exploitedMicrosoft confirmed that a critical CVSS 10.0 remote code execution vulnerability in Entra ID (CVE-2026-69836) was exploited in the wild. The issue has been mitigated server-side by Microsoft.
-
29 days ago
[TECHNOLOGY] 3 sourcesMicrosoft software faces critical vulnerability chainsResearchers have uncovered critical vulnerability chains in Microsoft Windows and SCCM that allow for kernel-mode code execution and remote system compromise.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesCybersecurity researchers disclose critical RCE vulnerabilities in Paperclip and SharePointResearchers have identified critical RCE vulnerabilities in the Paperclip orchestration platform and Microsoft SharePoint, involving unauthenticated access and full server compromise.
-
about 1 month ago
[TECHNOLOGY] 5 sourcesMicrosoft SharePoint vulnerability exploited in active attacksAttackers are actively exploiting a critical SharePoint vulnerability (CVE-2026-55040) that allows unauthenticated identity impersonation and potential remote code execution.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesSwiss Government SharePoint Servers Breached, Hundreds of AccountsUnknown attackers exploited recent SharePoint flaws to breach Swiss BIT servers, accessing about 200 accounts. No sensitive data leaked; servers are being rebuilt with Microsoft and BACS support.
-
about 2 months ago
[TECHNOLOGY] 8 sourcesMicrosoft grapples with backlog fixing AI‑found SharePoint vulnerabilitiesAnthropic’s Claude Mythos AI revealed 90 critical and 141 important SharePoint bugs in April; Microsoft is scrambling to patch them, leaving around 300 medium‑severity issues unaddressed and warning that un‑rem
-
about 2 months ago
[TECHNOLOGY] 9 sourcesUS CISA adds critical software flaws to its Known Exploited Vulnerabilities catalogUS CISA added critical DD‑WRT, Langflow, WordPress and Check Point SmartConsole vulnerabilities—including CVE‑2026‑16232—to its Known Exploited Vulnerabilities catalog, urging immediate patching.
-
about 2 months ago
[TECHNOLOGY] 4 sourcesMicrosoft SharePoint and Windows Vulnerabilities Prompt Urgent PatchesMicrosoft SharePoint (CVE‑2026‑50522) and Windows LegacyHive flaws are being actively exploited; patches and a free 0patch micro‑fix are urged.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesMicrosoft SharePoint on‑premises flaws exploited; patches and key rotation urgedCISA lists critical on‑premise SharePoint flaws (CVE‑2026‑58644, CVE‑2026‑50522) as actively exploited; attackers steal machine keys, so immediate patching, key rotation and network segmentation are urged.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesEU and US regulators tighten cybersecurity measures as new vulnerabilities and sanctions emergeCERT‑FR flags critical SharePoint, Windows and Firefox flaws; EU sanctions Russian intel and Turla, proposes junior social‑media rules; NY bans large AI datacenters for a year.
-
2 months ago
[TECHNOLOGY] 6 sourcesUS CISA urges urgent hardening of Microsoft SharePoint after active exploitsCISA warns that three SharePoint flaws are actively exploited and urges immediate patching, segmentation and other defenses, giving federal agencies three days to remediate the newest vulnerability.
-
2 months ago
[TECHNOLOGY] 5 sourcesSAP releases patches for critical NetWeaver ABAP and other security flawsSAP issued July 2026 patches fixing three critical CVEs, including a 9.9‑rated NetWeaver ABAP flaw, and urges immediate customer updates.
-
2 months ago
[TECHNOLOGY] 5 sourcesUS CISA and German BSI order urgent patches for critical software flawsBSI warns of high‑severity Linux kernel flaws; Oracle releases patches. CISA mandates US agencies patch critical ColdFusion, AI, and Linux kernel bugs by July 10.
-
2 months ago
[TECHNOLOGY] 2 sourcesUbiquiti patches 25 critical UniFi vulnerabilitiesUbiquiti released patches for 25 UniFi software flaws, seven rated critical with CVSS up to 10.0, fixing remote takeover risks across its networking and surveillance products.
-
3 months ago
[TECHNOLOGY] 6 sourcesCritical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelpJTL‑Shop, Chrome, Langflow and SimpleHelp each face critical, actively exploited vulnerabilities; patches are available and users must update immediately.
-
3 months ago
[TECHNOLOGY] 4 sourcesCISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28CISA orders US federal agencies to patch critical Cisco Unified CM SSRF flaw (CVE‑2026‑20230) and PTC PLM vulnerability by June 28, citing active exploitation.
-
3 months ago
[TECHNOLOGY] 4 sourcesCritical Ubiquiti Device Vulnerabilities Exploited by AttackersUbiquiti disclosed three CVSS 10/10 flaws that let unauthenticated attackers alter systems, access accounts and run commands; a May patch was issued but exploitation is already reported.
-
3 months ago
[TECHNOLOGY] 3 sourcesMicrosoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threatsMicrosoft uncovered a dual‑actor breach while Mandiant identified a Cisco SD‑WAN zero‑day that gave attackers root access, showing evolving multi‑actor cyber threats.
-
3 months ago
[TECHNOLOGY] 2 sourcesCybersecurity firms stress exploitability over vulnerability scansCybersecurity experts say vulnerability scans identify gaps but attackers focus on exploitability; firms should prioritize exposing actionable risk over completing security activities.
-
3 months ago
[TECHNOLOGY] 9 sourcesCritical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and UbiquitiMultiple critical flaws affect FFmpeg (PixelSmash), Lantronix EDS5000, Cisco Unified CM and Ubiquiti UniFi OS, with active exploitation and CISA KEV listings; NinjaOne adds KEV data to its management tool.
-
3 months ago
[TECHNOLOGY] 4 sourcesCritical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OSCritical flaws in JTL Shop (CVE‑2026‑54390), Cisco ISE (CVE‑2026‑20181/20190) and Ubiquiti UniFi OS (CVE‑2026‑34908‑34910) enable unauthenticated remote code execution or root access; vendors urge immediate up‑
-
3 months ago
[TECHNOLOGY] 2 sourcesIT asset patch gaps and fragmented endpoint management expose security risksStudies show IT teams spend over half their time on routine endpoint work, while 18‑19 % of assets lack proper patching and 65 % of non‑BEC incidents exploit remote‑access gaps.
-
3 months ago
[TECHNOLOGY] 4 sourcesCisco patches actively exploited SD‑WAN Manager zero‑day vulnerabilityCisco patched CVE‑2026‑20262, a zero‑day SD‑WAN Manager bug exploited to gain root, after CISA flagged it as actively used and set a two‑week federal patch deadline.
-
3 months ago
[TECHNOLOGY] 2 sourcesCisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root ExploitsCisco reports active exploitation of CVE‑2026‑20245 in its SD‑WAN Manager, while a newly found Linux kernel CIFSwitch flaw lets unprivileged users gain root, affecting major distributions.
-
4 months ago
[TECHNOLOGY] 3 sourcesEnterprise Vulnerability Management Shifts Toward Real‑World Exploit PrioritizationVulnerability exploitation rose sharply in 2025; security firms cite gaps in patch validation, correlation, and prioritization. Solutions like HCL BigFix and risk‑based patching use threat intel and asset data,
-
4 months ago
[TECHNOLOGY] 3 sourcesCritical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent PatchesA critical LiteSpeed cPanel plug‑in flaw (CVE‑2026‑48172) enabling root‑level attacks is being exploited; CISA ordered urgent patches and cPanel auto‑removes the plug‑in.
-
4 months ago
[TECHNOLOGY] 5 sourcesArch Linux users urged to patch PinTheft kernel flawPatch Arch Linux now for PinTheft kernel bug that lets local attackers gain root.
-
4 months ago
[TECHNOLOGY] 2 sourcesLinux kernel and Windows Telephony Service patched for critical vulnerabilitiesLinux kernel TIPC and Windows Telephony Service flaws patched to stop code execution attacks.
-
4 months ago
[TECHNOLOGY] 2 sourcesLinux kernel hardening tool ModuleJail released as new privilege‑escalation flaws emergeLinux kernel faces new LPE flaws; ModuleJail tool blacklists unused modules to cut attack surface.
-
4 months ago
[TECHNOLOGY] 2 sourcesLinux kernel introduces Rust Untrusted Data API amid AI bug‑report backlashLinux adds a Rust API for safer untrusted data handling, while Torvalds denounces rising AI‑generated bug reports.
-
4 months ago
[TECHNOLOGY] 2 sourcesLinux kernel hit by third critical local privilege flaw in weeksLinux kernel suffers two new local privilege flaws—Fragnesia (root access) and a ptrace race (secret leakage)—prompting urgent patches.
-
4 months ago
[TECHNOLOGY] 2 sourcesCybersecurity Alerts: Ubuntu Twitter Scam and 'Dirty Frag' Root‑Access BugUbuntu's Twitter was hacked for a scam, and a new 'Dirty Frag' bug grants root access.
-
4 months ago
[TECHNOLOGY] 5 sourcesCopyFail Linux kernel flaw enables local root escalation across major distributionsCopyFail (CVE‑2026‑31431) is a Linux kernel bug that lets local attackers gain root; patches are rolling out across major distros.
-
4 months ago
[TECHNOLOGY] 3 sourcesRapid Exploits Pressure Faster Patch Management Across EnterprisesFast‑moving exploits, like a China‑focused RCE bug, expose slow patching; vendors tout unified AI‑driven solutions.
-
4 months ago
[TECHNOLOGY] 47 sourcesUS CISA flags critical cPanel/WHM and Linux CopyFail bugs actively exploitedCISA warns that cPanel/WHM and Linux CopyFail bugs are being actively exploited, urging immediate patches.
-
4 months ago
[TECHNOLOGY] 17 sourcesLinux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploitscPanel/WHM breach spreads ransomware and Mirai botnet; a kernel flaw (CVE‑2026‑31431) enables root escalation, patches rolling out.
-
5 months ago
[TECHNOLOGY] 2 sourcesMillions of websites at risk as cPanel zero-day is actively exploitedMillions of websites exposed as the cPanel zero-day CVE-2026-41940 is exploited in the wild ahead of patches.
Sources
4sysops.com · activestate.com · all-about-security.de · apcmag.com · appgate.com · arstechnica.com · atmarkit.co.jp · avleonov.com · b2b-cyber-security.de · bdew.de · bishopfox.com · bitcoinethereumnews.com · bitmat.it · bitnewsbot.com · bleepingcomputer.com · blog.0patch.com · blog.cloudlinux.com · blog.kangaroo.cmo.de · blog.qualys.com · blog.samwhited.com · blogspan.net · bobsummerwill.com · borncity.com · business.scoop.co.nz · businesstechweekly.com · canonical.com · charliehebdo.fr · cinemagia.wordpress.com · clickx.be · cloudcomputing-insider.de · clubic.com · commonwealthunion.com · complexdiscovery.com · computerworld.com.au · conterest.de · cosmeticacupuncturemelbourne.com.au · countryrebel.com · cryptobreaking.com · csoonline.com.au · cyberinsider.com · cybernoz.com · cybersecurity-news.de · cybersecuritynews.com · davfi.fr · de.tenable.com · decrypt.co · dev.to · digital-magazin.de
This summary has been updated 10 times: see revision history