< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

32 clusters · 118 sources · 91 days · First seen · Last updated

Categories: TECHNOLOGY

Software vulnerability exploits & patch response, July 2026

Entities: Microsoft Corp. · Claude Mythos Preview · Claude Mythos · Project Glasswing · Anthropic PBC

Overview

July 2026 continued a rapid cycle of flaw discovery, weaponisation, and remediation across a wide software base. On 22 July security researchers confirmed active exploitation of the SharePoint deserialization bug (CVE‑2026‑50522) after a proof‑of‑concept was released on 20 July; the exploit harvested machine‑key credentials, allowing attackers to forge valid tokens even after patching. Microsoft’s July 2026 update fixed the flaw, and agencies were urged to apply the patch and rotate all SharePoint keys. The same day a zero‑day (LegacyHive) targeting the Windows user‑profile service was disclosed; with no official fix, ACROS Security issued a free 0patch micropatch for affected Windows editions.

CISA’s KEV catalog was expanded on 22 July to include a stack‑buffer overflow in DD‑WRT, a remote‑code execution issue in Langflow, two high‑severity WordPress Core bugs, and a critical authentication flaw in Check Point SmartConsole (CVE‑2026‑16232) that enables unauthenticated admin‑token theft. The agency warned of active exploitation and urged immediate patching and stricter access controls.

By 30 July Anthropic’s Claude Mythos AI reported 90 critical and 141 important SharePoint defects discovered in April, alongside hundreds of findings across Microsoft 365, Teams and Copilot. Microsoft disclosed a backlog of roughly 300 medium‑severity issues yet to be patched, noting the risk that chained low‑severity bugs could form high‑severity attack vectors. The forthcoming Cyber Resilience Act (effective 11 Sept 2026) will tighten reporting deadlines, underscoring the shrinking window between discovery and exploitation.

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 8 sources
    Microsoft grapples with backlog fixing AI‑found SharePoint vulnerabilities

    Anthropic’s Claude Mythos AI revealed 90 critical and 141 important SharePoint bugs in April; Microsoft is scrambling to patch them, leaving around 300 medium‑severity issues unaddressed and warning that un‑rem

  2. 9 days ago

    [TECHNOLOGY] 9 sources
    US CISA adds critical software flaws to its Known Exploited Vulnerabilities catalog

    US CISA added critical DD‑WRT, Langflow, WordPress and Check Point SmartConsole vulnerabilities—including CVE‑2026‑16232—to its Known Exploited Vulnerabilities catalog, urging immediate patching.

  3. 10 days ago

    [TECHNOLOGY] 4 sources
    Microsoft SharePoint and Windows Vulnerabilities Prompt Urgent Patches

    Microsoft SharePoint (CVE‑2026‑50522) and Windows LegacyHive flaws are being actively exploited; patches and a free 0patch micro‑fix are urged.

  4. 12 days ago

    [TECHNOLOGY] 2 sources
    Microsoft SharePoint on‑premises flaws exploited; patches and key rotation urged

    CISA lists critical on‑premise SharePoint flaws (CVE‑2026‑58644, CVE‑2026‑50522) as actively exploited; attackers steal machine keys, so immediate patching, key rotation and network segmentation are urged.

  5. 12 days ago

    [TECHNOLOGY] 2 sources
    EU and US regulators tighten cybersecurity measures as new vulnerabilities and sanctions emerge

    CERT‑FR flags critical SharePoint, Windows and Firefox flaws; EU sanctions Russian intel and Turla, proposes junior social‑media rules; NY bans large AI datacenters for a year.

  6. 16 days ago

    [TECHNOLOGY] 6 sources
    US CISA urges urgent hardening of Microsoft SharePoint after active exploits

    CISA warns that three SharePoint flaws are actively exploited and urges immediate patching, segmentation and other defenses, giving federal agencies three days to remediate the newest vulnerability.

  7. 17 days ago

    [TECHNOLOGY] 5 sources
    SAP releases patches for critical NetWeaver ABAP and other security flaws

    SAP issued July 2026 patches fixing three critical CVEs, including a 9.9‑rated NetWeaver ABAP flaw, and urges immediate customer updates.

  8. 23 days ago

    [TECHNOLOGY] 5 sources
    US CISA and German BSI order urgent patches for critical software flaws

    BSI warns of high‑severity Linux kernel flaws; Oracle releases patches. CISA mandates US agencies patch critical ColdFusion, AI, and Linux kernel bugs by July 10.

  9. 24 days ago

    [TECHNOLOGY] 2 sources
    Ubiquiti patches 25 critical UniFi vulnerabilities

    Ubiquiti released patches for 25 UniFi software flaws, seven rated critical with CVSS up to 10.0, fixing remote takeover risks across its networking and surveillance products.

  10. about 1 month ago

    [TECHNOLOGY] 6 sources
    Critical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelp

    JTL‑Shop, Chrome, Langflow and SimpleHelp each face critical, actively exploited vulnerabilities; patches are available and users must update immediately.

  11. about 1 month ago

    [TECHNOLOGY] 4 sources
    CISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28

    CISA orders US federal agencies to patch critical Cisco Unified CM SSRF flaw (CVE‑2026‑20230) and PTC PLM vulnerability by June 28, citing active exploitation.

  12. about 1 month ago

    [TECHNOLOGY] 4 sources
    Critical Ubiquiti Device Vulnerabilities Exploited by Attackers

    Ubiquiti disclosed three CVSS 10/10 flaws that let unauthenticated attackers alter systems, access accounts and run commands; a May patch was issued but exploitation is already reported.

  13. about 1 month ago

    [TECHNOLOGY] 3 sources
    Microsoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threats

    Microsoft uncovered a dual‑actor breach while Mandiant identified a Cisco SD‑WAN zero‑day that gave attackers root access, showing evolving multi‑actor cyber threats.

  14. about 1 month ago

    [TECHNOLOGY] 2 sources
    Cybersecurity firms stress exploitability over vulnerability scans

    Cybersecurity experts say vulnerability scans identify gaps but attackers focus on exploitability; firms should prioritize exposing actionable risk over completing security activities.

  15. about 1 month ago

    [TECHNOLOGY] 9 sources
    Critical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and Ubiquiti

    Multiple critical flaws affect FFmpeg (PixelSmash), Lantronix EDS5000, Cisco Unified CM and Ubiquiti UniFi OS, with active exploitation and CISA KEV listings; NinjaOne adds KEV data to its management tool.

  16. about 1 month ago

    [TECHNOLOGY] 4 sources
    Critical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OS

    Critical flaws in JTL Shop (CVE‑2026‑54390), Cisco ISE (CVE‑2026‑20181/20190) and Ubiquiti UniFi OS (CVE‑2026‑34908‑34910) enable unauthenticated remote code execution or root access; vendors urge immediate up‑

  17. about 2 months ago

    [TECHNOLOGY] 2 sources
    IT asset patch gaps and fragmented endpoint management expose security risks

    Studies show IT teams spend over half their time on routine endpoint work, while 18‑19 % of assets lack proper patching and 65 % of non‑BEC incidents exploit remote‑access gaps.

  18. about 2 months ago

    [TECHNOLOGY] 4 sources
    Cisco patches actively exploited SD‑WAN Manager zero‑day vulnerability

    Cisco patched CVE‑2026‑20262, a zero‑day SD‑WAN Manager bug exploited to gain root, after CISA flagged it as actively used and set a two‑week federal patch deadline.

  19. about 2 months ago

    [TECHNOLOGY] 2 sources
    Cisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root Exploits

    Cisco reports active exploitation of CVE‑2026‑20245 in its SD‑WAN Manager, while a newly found Linux kernel CIFSwitch flaw lets unprivileged users gain root, affecting major distributions.

  20. 2 months ago

    [TECHNOLOGY] 3 sources
    Enterprise Vulnerability Management Shifts Toward Real‑World Exploit Prioritization

    Vulnerability exploitation rose sharply in 2025; security firms cite gaps in patch validation, correlation, and prioritization. Solutions like HCL BigFix and risk‑based patching use threat intel and asset data,

  21. 2 months ago

    [TECHNOLOGY] 3 sources
    Critical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent Patches

    A critical LiteSpeed cPanel plug‑in flaw (CVE‑2026‑48172) enabling root‑level attacks is being exploited; CISA ordered urgent patches and cPanel auto‑removes the plug‑in.

  22. 2 months ago

    [TECHNOLOGY] 5 sources
    Arch Linux users urged to patch PinTheft kernel flaw

    Patch Arch Linux now for PinTheft kernel bug that lets local attackers gain root.

  23. 2 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel and Windows Telephony Service patched for critical vulnerabilities

    Linux kernel TIPC and Windows Telephony Service flaws patched to stop code execution attacks.

  24. 2 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel hardening tool ModuleJail released as new privilege‑escalation flaws emerge

    Linux kernel faces new LPE flaws; ModuleJail tool blacklists unused modules to cut attack surface.

  25. 2 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel introduces Rust Untrusted Data API amid AI bug‑report backlash

    Linux adds a Rust API for safer untrusted data handling, while Torvalds denounces rising AI‑generated bug reports.

  26. 3 months ago

    [TECHNOLOGY] 2 sources
    Linux kernel hit by third critical local privilege flaw in weeks

    Linux kernel suffers two new local privilege flaws—Fragnesia (root access) and a ptrace race (secret leakage)—prompting urgent patches.

  27. 3 months ago

    [TECHNOLOGY] 2 sources
    Cybersecurity Alerts: Ubuntu Twitter Scam and 'Dirty Frag' Root‑Access Bug

    Ubuntu's Twitter was hacked for a scam, and a new 'Dirty Frag' bug grants root access.

  28. 3 months ago

    [TECHNOLOGY] 5 sources
    CopyFail Linux kernel flaw enables local root escalation across major distributions

    CopyFail (CVE‑2026‑31431) is a Linux kernel bug that lets local attackers gain root; patches are rolling out across major distros.

  29. 3 months ago

    [TECHNOLOGY] 3 sources
    Rapid Exploits Pressure Faster Patch Management Across Enterprises

    Fast‑moving exploits, like a China‑focused RCE bug, expose slow patching; vendors tout unified AI‑driven solutions.

  30. 3 months ago

    [TECHNOLOGY] 47 sources
    US CISA flags critical cPanel/WHM and Linux CopyFail bugs actively exploited

    CISA warns that cPanel/WHM and Linux CopyFail bugs are being actively exploited, urging immediate patches.

  31. 3 months ago

    [TECHNOLOGY] 17 sources
    Linux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploits

    cPanel/WHM breach spreads ransomware and Mirai botnet; a kernel flaw (CVE‑2026‑31431) enables root escalation, patches rolling out.

  32. 3 months ago

    [TECHNOLOGY] 2 sources
    Millions of websites at risk as cPanel zero-day is actively exploited

    Millions of websites exposed as the cPanel zero-day CVE-2026-41940 is exploited in the wild ahead of patches.

Sources

activestate.com · all-about-security.de · appgate.com · arstechnica.com · avleonov.com · b2b-cyber-security.de · bdew.de · bishopfox.com · bitmat.it · bleepingcomputer.com · blog.0patch.com · blog.cloudlinux.com · blog.kangaroo.cmo.de · blog.qualys.com · blog.samwhited.com · blogspan.net · bobsummerwill.com · borncity.com · business.scoop.co.nz · canonical.com · charliehebdo.fr · cinemagia.wordpress.com · clickx.be · clubic.com · commonwealthunion.com · complexdiscovery.com · computerworld.com.au · conterest.de · cosmeticacupuncturemelbourne.com.au · cryptobreaking.com · csoonline.com.au · cyberinsider.com · cybersecurity-news.de · cybersecuritynews.com · davfi.fr · de.tenable.com · decrypt.co · digital-magazin.de · electropages.com · emarketerz.fr · estugo.de · etbe.coker.com.au · evere.co · executivegov.com · file.net · fiscaltiger.com · flagthis.com · franksworld.com