< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

41 clusters · 142 sources · 129 days · First seen · Last updated

Software vulnerability exploits & patch response, 2026

Overview

The wave of exploitation observed in July 2026 continued into August, with significant impacts on government infrastructure and core operating systems. In Switzerland, the breach of federal SharePoint servers was further detailed. Unknown actors exploited CVE-2026-56164 and CVE-2026-50522 to access the Federal Office for Information Technology and Telecommunication (BIT) servers. The breach, detected on 28 July 2026, resulted in the compromise of approximately 200 user and technical accounts. In response, the Swiss government isolated the servers, disconnected them from the internet, and initiated a full environment rebuild. While BIT is working with Microsoft and the Federal Office for Cybersecurity (BACS) on forensics, officials stated that no confidential or sensitive personal data is believed to have been stored on the platform, and no evidence of dark web exfiltration has been found. Simultaneously, Microsoft’s August security updates addressed 398 vulnerabilities, including 62 critical flaws. A notable active exploit, CVE-2026-68820, targets a use-after-free error in the Windows Ancillary Function Driver for WinSock (afd.sys). New disclosures in mid-August highlighted further critical risks. Oasis Security identified CVE-2026-41679, a CVSS 10.0 vulnerability in the Paperclip orchestration platform. Researchers also identified an unauthenticated RCE chain in Microsoft SharePoint, combining a JWT authentication-bypass (CVE-2026-55040) with a flaw in Business Connectivity Services (CVE-2026-63520). Further research uncovered complex chains targeting the Windows kernel and hypervisor, dubbed ‘Download More RAM,’ which can bypass Virtualization-Based Security (VBS). Additionally, a vulnerability in Microsoft System Center Configuration Manager (SCCM) allows remote code execution via an authorization issue and a path traversal flaw known as ‘CabSlip.’ In late August, Microsoft addressed CVE-2026-50522 in SharePoint, involving untrusted data deserialization. Concurrently, Microsoft disclosed a critical remote code execution (RCE) vulnerability in Entra ID, tracked as CVE-2026-69836. In early September 2026, new critical vulnerabilities emerged.

Entities

Microsoft · Microsoft Entra ID · SharePoint · Robert Fitzpatrick · CISA

Claims

What the coverage asserts, and how many sources carry each claim.

Coverage disagrees

Sources make claims that cannot both be true. CLSTR reports the disagreement; it does not decide who is right.

  • "Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April."

    vs

    "Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April."

    The claims provide different specific counts (90 vs 141) for the number of vulnerabilities identified by Claude Mythos Preview in SharePoint in April.

Timeline

  1. 9 days ago

    [TECHNOLOGY] 4 sources
    Microsoft discloses nine vulnerabilities including two critical CVSS 10.0 flaws

    Microsoft disclosed nine vulnerabilities, including two with a CVSS 10.0 rating, affecting Azure AD B2C, Entra ID, and Copilot Studio due to authentication and authorization bypasses.

  2. 12 days ago

    [TECHNOLOGY] 3 sources
    Mozilla and Microsoft patch critical software vulnerabilities

    Mozilla patched a critical Thunderbird vulnerability involving malicious calendar invites, while Microsoft resolved a high-severity RCE flaw in Entra ID that was not actively exploited.

  3. 21 days ago

    [TECHNOLOGY] 3 sources
    Microsoft Entra ID vulnerability receives maximum CVSS 10.0 rating

    Microsoft patched a critical CVE-2026-69836 vulnerability in Entra ID with a maximum CVSS score of 10.0. The flaw allowed unauthenticated remote code execution via untrusted data deserialization.

  4. 23 days ago

    [TECHNOLOGY] 7 sources
    Microsoft patches critical Entra ID remote code execution vulnerability

    Microsoft has patched a critical 10.0 CVSS-rated remote code execution vulnerability in Entra ID. The flaw was discovered internally and fixed on the server side, requiring no action from customers.

  5. 25 days ago

    [TECHNOLOGY] 13 sources
    Microsoft Entra ID critical RCE vulnerability exploited

    Microsoft confirmed that a critical CVSS 10.0 remote code execution vulnerability in Entra ID (CVE-2026-69836) was exploited in the wild. The issue has been mitigated server-side by Microsoft.

  6. 29 days ago

    [TECHNOLOGY] 3 sources
    Microsoft software faces critical vulnerability chains

    Researchers have uncovered critical vulnerability chains in Microsoft Windows and SCCM that allow for kernel-mode code execution and remote system compromise.

  7. about 1 month ago

    [TECHNOLOGY] 3 sources
    Cybersecurity researchers disclose critical RCE vulnerabilities in Paperclip and SharePoint

    Researchers have identified critical RCE vulnerabilities in the Paperclip orchestration platform and Microsoft SharePoint, involving unauthenticated access and full server compromise.

  8. about 1 month ago

    [TECHNOLOGY] 5 sources
    Microsoft SharePoint vulnerability exploited in active attacks

    Attackers are actively exploiting a critical SharePoint vulnerability (CVE-2026-55040) that allows unauthenticated identity impersonation and potential remote code execution.

  9. about 1 month ago

    [TECHNOLOGY] 3 sources
    Swiss Government SharePoint Servers Breached, Hundreds of Accounts

    Unknown attackers exploited recent SharePoint flaws to breach Swiss BIT servers, accessing about 200 accounts. No sensitive data leaked; servers are being rebuilt with Microsoft and BACS support.

  10. about 2 months ago

    [TECHNOLOGY] 8 sources
    Microsoft grapples with backlog fixing AI‑found SharePoint vulnerabilities

    Anthropic’s Claude Mythos AI revealed 90 critical and 141 important SharePoint bugs in April; Microsoft is scrambling to patch them, leaving around 300 medium‑severity issues unaddressed and warning that un‑rem

  11. about 2 months ago

    [TECHNOLOGY] 9 sources
    US CISA adds critical software flaws to its Known Exploited Vulnerabilities catalog

    US CISA added critical DD‑WRT, Langflow, WordPress and Check Point SmartConsole vulnerabilities—including CVE‑2026‑16232—to its Known Exploited Vulnerabilities catalog, urging immediate patching.

  12. about 2 months ago

    [TECHNOLOGY] 4 sources
    Microsoft SharePoint and Windows Vulnerabilities Prompt Urgent Patches

    Microsoft SharePoint (CVE‑2026‑50522) and Windows LegacyHive flaws are being actively exploited; patches and a free 0patch micro‑fix are urged.

  13. about 2 months ago

    [TECHNOLOGY] 2 sources
    Microsoft SharePoint on‑premises flaws exploited; patches and key rotation urged

    CISA lists critical on‑premise SharePoint flaws (CVE‑2026‑58644, CVE‑2026‑50522) as actively exploited; attackers steal machine keys, so immediate patching, key rotation and network segmentation are urged.

  14. about 2 months ago

    [TECHNOLOGY] 2 sources
    EU and US regulators tighten cybersecurity measures as new vulnerabilities and sanctions emerge

    CERT‑FR flags critical SharePoint, Windows and Firefox flaws; EU sanctions Russian intel and Turla, proposes junior social‑media rules; NY bans large AI datacenters for a year.

  15. 2 months ago

    [TECHNOLOGY] 6 sources
    US CISA urges urgent hardening of Microsoft SharePoint after active exploits

    CISA warns that three SharePoint flaws are actively exploited and urges immediate patching, segmentation and other defenses, giving federal agencies three days to remediate the newest vulnerability.

  16. 2 months ago

    [TECHNOLOGY] 5 sources
    SAP releases patches for critical NetWeaver ABAP and other security flaws

    SAP issued July 2026 patches fixing three critical CVEs, including a 9.9‑rated NetWeaver ABAP flaw, and urges immediate customer updates.

  17. 2 months ago

    [TECHNOLOGY] 5 sources
    US CISA and German BSI order urgent patches for critical software flaws

    BSI warns of high‑severity Linux kernel flaws; Oracle releases patches. CISA mandates US agencies patch critical ColdFusion, AI, and Linux kernel bugs by July 10.

  18. 2 months ago

    [TECHNOLOGY] 2 sources
    Ubiquiti patches 25 critical UniFi vulnerabilities

    Ubiquiti released patches for 25 UniFi software flaws, seven rated critical with CVSS up to 10.0, fixing remote takeover risks across its networking and surveillance products.

  19. 3 months ago

    [TECHNOLOGY] 6 sources
    Critical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelp

    JTL‑Shop, Chrome, Langflow and SimpleHelp each face critical, actively exploited vulnerabilities; patches are available and users must update immediately.

  20. 3 months ago

    [TECHNOLOGY] 4 sources
    CISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28

    CISA orders US federal agencies to patch critical Cisco Unified CM SSRF flaw (CVE‑2026‑20230) and PTC PLM vulnerability by June 28, citing active exploitation.

  21. 3 months ago

    [TECHNOLOGY] 4 sources
    Critical Ubiquiti Device Vulnerabilities Exploited by Attackers

    Ubiquiti disclosed three CVSS 10/10 flaws that let unauthenticated attackers alter systems, access accounts and run commands; a May patch was issued but exploitation is already reported.

  22. 3 months ago

    [TECHNOLOGY] 3 sources
    Microsoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threats

    Microsoft uncovered a dual‑actor breach while Mandiant identified a Cisco SD‑WAN zero‑day that gave attackers root access, showing evolving multi‑actor cyber threats.

  23. 3 months ago

    [TECHNOLOGY] 2 sources
    Cybersecurity firms stress exploitability over vulnerability scans

    Cybersecurity experts say vulnerability scans identify gaps but attackers focus on exploitability; firms should prioritize exposing actionable risk over completing security activities.

  24. 3 months ago

    [TECHNOLOGY] 9 sources
    Critical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and Ubiquiti

    Multiple critical flaws affect FFmpeg (PixelSmash), Lantronix EDS5000, Cisco Unified CM and Ubiquiti UniFi OS, with active exploitation and CISA KEV listings; NinjaOne adds KEV data to its management tool.

  25. 3 months ago

    [TECHNOLOGY] 4 sources
    Critical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OS

    Critical flaws in JTL Shop (CVE‑2026‑54390), Cisco ISE (CVE‑2026‑20181/20190) and Ubiquiti UniFi OS (CVE‑2026‑34908‑34910) enable unauthenticated remote code execution or root access; vendors urge immediate up‑

  26. 3 months ago

    [TECHNOLOGY] 2 sources
    IT asset patch gaps and fragmented endpoint management expose security risks

    Studies show IT teams spend over half their time on routine endpoint work, while 18‑19 % of assets lack proper patching and 65 % of non‑BEC incidents exploit remote‑access gaps.

  27. 3 months ago

    [TECHNOLOGY] 4 sources
    Cisco patches actively exploited SD‑WAN Manager zero‑day vulnerability

    Cisco patched CVE‑2026‑20262, a zero‑day SD‑WAN Manager bug exploited to gain root, after CISA flagged it as actively used and set a two‑week federal patch deadline.

  28. 3 months ago

    [TECHNOLOGY] 2 sources
    Cisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root Exploits

    Cisco reports active exploitation of CVE‑2026‑20245 in its SD‑WAN Manager, while a newly found Linux kernel CIFSwitch flaw lets unprivileged users gain root, affecting major distributions.

  29. 4 months ago

    [TECHNOLOGY] 3 sources
    Enterprise Vulnerability Management Shifts Toward Real‑World Exploit Prioritization

    Vulnerability exploitation rose sharply in 2025; security firms cite gaps in patch validation, correlation, and prioritization. Solutions like HCL BigFix and risk‑based patching use threat intel and asset data,

  30. 4 months ago

    [TECHNOLOGY] 3 sources
    Critical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent Patches

    A critical LiteSpeed cPanel plug‑in flaw (CVE‑2026‑48172) enabling root‑level attacks is being exploited; CISA ordered urgent patches and cPanel auto‑removes the plug‑in.

  31. 4 months ago

    [TECHNOLOGY] 5 sources
    Arch Linux users urged to patch PinTheft kernel flaw

    Patch Arch Linux now for PinTheft kernel bug that lets local attackers gain root.

  32. 4 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel and Windows Telephony Service patched for critical vulnerabilities

    Linux kernel TIPC and Windows Telephony Service flaws patched to stop code execution attacks.

  33. 4 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel hardening tool ModuleJail released as new privilege‑escalation flaws emerge

    Linux kernel faces new LPE flaws; ModuleJail tool blacklists unused modules to cut attack surface.

  34. 4 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel introduces Rust Untrusted Data API amid AI bug‑report backlash

    Linux adds a Rust API for safer untrusted data handling, while Torvalds denounces rising AI‑generated bug reports.

  35. 4 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel hit by third critical local privilege flaw in weeks

    Linux kernel suffers two new local privilege flaws—Fragnesia (root access) and a ptrace race (secret leakage)—prompting urgent patches.

  36. 4 months ago

    [TECHNOLOGY] 2 sources
    Cybersecurity Alerts: Ubuntu Twitter Scam and 'Dirty Frag' Root‑Access Bug

    Ubuntu's Twitter was hacked for a scam, and a new 'Dirty Frag' bug grants root access.

  37. 4 months ago

    [TECHNOLOGY] 5 sources
    CopyFail Linux kernel flaw enables local root escalation across major distributions

    CopyFail (CVE‑2026‑31431) is a Linux kernel bug that lets local attackers gain root; patches are rolling out across major distros.

  38. 4 months ago

    [TECHNOLOGY] 3 sources
    Rapid Exploits Pressure Faster Patch Management Across Enterprises

    Fast‑moving exploits, like a China‑focused RCE bug, expose slow patching; vendors tout unified AI‑driven solutions.

  39. 4 months ago

    [TECHNOLOGY] 47 sources
    US CISA flags critical cPanel/WHM and Linux CopyFail bugs actively exploited

    CISA warns that cPanel/WHM and Linux CopyFail bugs are being actively exploited, urging immediate patches.

  40. 4 months ago

    [TECHNOLOGY] 17 sources
    Linux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploits

    cPanel/WHM breach spreads ransomware and Mirai botnet; a kernel flaw (CVE‑2026‑31431) enables root escalation, patches rolling out.

  41. 5 months ago

    [TECHNOLOGY] 2 sources
    Millions of websites at risk as cPanel zero-day is actively exploited

    Millions of websites exposed as the cPanel zero-day CVE-2026-41940 is exploited in the wild ahead of patches.

Sources

4sysops.com · activestate.com · all-about-security.de · apcmag.com · appgate.com · arstechnica.com · atmarkit.co.jp · avleonov.com · b2b-cyber-security.de · bdew.de · bishopfox.com · bitcoinethereumnews.com · bitmat.it · bitnewsbot.com · bleepingcomputer.com · blog.0patch.com · blog.cloudlinux.com · blog.kangaroo.cmo.de · blog.qualys.com · blog.samwhited.com · blogspan.net · bobsummerwill.com · borncity.com · business.scoop.co.nz · businesstechweekly.com · canonical.com · charliehebdo.fr · cinemagia.wordpress.com · clickx.be · cloudcomputing-insider.de · clubic.com · commonwealthunion.com · complexdiscovery.com · computerworld.com.au · conterest.de · cosmeticacupuncturemelbourne.com.au · countryrebel.com · cryptobreaking.com · csoonline.com.au · cyberinsider.com · cybernoz.com · cybersecurity-news.de · cybersecuritynews.com · davfi.fr · de.tenable.com · decrypt.co · dev.to · digital-magazin.de

This summary has been updated 10 times: see revision history