Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
32 clusters · 118 sources · 91 days · First seen · Last updated
Categories: TECHNOLOGY
Software vulnerability exploits & patch response, July 2026
Entities: Microsoft Corp. · Claude Mythos Preview · Claude Mythos · Project Glasswing · Anthropic PBC
Overview
July 2026 continued a rapid cycle of flaw discovery, weaponisation, and remediation across a wide software base. On 22 July security researchers confirmed active exploitation of the SharePoint deserialization bug (CVE‑2026‑50522) after a proof‑of‑concept was released on 20 July; the exploit harvested machine‑key credentials, allowing attackers to forge valid tokens even after patching. Microsoft’s July 2026 update fixed the flaw, and agencies were urged to apply the patch and rotate all SharePoint keys. The same day a zero‑day (LegacyHive) targeting the Windows user‑profile service was disclosed; with no official fix, ACROS Security issued a free 0patch micropatch for affected Windows editions.
CISA’s KEV catalog was expanded on 22 July to include a stack‑buffer overflow in DD‑WRT, a remote‑code execution issue in Langflow, two high‑severity WordPress Core bugs, and a critical authentication flaw in Check Point SmartConsole (CVE‑2026‑16232) that enables unauthenticated admin‑token theft. The agency warned of active exploitation and urged immediate patching and stricter access controls.
By 30 July Anthropic’s Claude Mythos AI reported 90 critical and 141 important SharePoint defects discovered in April, alongside hundreds of findings across Microsoft 365, Teams and Copilot. Microsoft disclosed a backlog of roughly 300 medium‑severity issues yet to be patched, noting the risk that chained low‑severity bugs could form high‑severity attack vectors. The forthcoming Cyber Resilience Act (effective 11 Sept 2026) will tighten reporting deadlines, underscoring the shrinking window between discovery and exploitation.
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 4 SOURCES] Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April. (ProPublica, internal Microsoft materials)
- [● 4 SOURCES] Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April. (ProPublica, internal Microsoft materials)
- [● 4 SOURCES] Around 300 medium‑severity SharePoint findings were deprioritized for later remediation. (Internal Microsoft documents)
- [● 3 SOURCES] Hundreds of serious vulnerabilities were also discovered in Microsoft 365, Teams and Copilot by May. (ProPublica, internal Microsoft materials)
- [● 3 SOURCES] Four low‑severity flaws can be chained together to create a high‑severity vulnerability. (Expert commentary, internal Microsoft analysis)
- [● 2 SOURCES] Microsoft engineers held an internal meeting in mid‑May to accelerate patching, setting May 31 as a deadline before the wider security community could catch up. (Recorded meeting, ProPublica)
- [● 2 SOURCES] Project Glasswing provides early AI model access to selected partners, including Microsoft, to help protect critical systems. (Company announcements, internal documents)
- [○ 1 SOURCE] Engineers warned that if the AI model were released publicly on June 1, attackers could exploit the unpatched bugs the next day. (Internal meeting recording)
Timeline
-
2 days ago
[TECHNOLOGY] 8 sourcesMicrosoft grapples with backlog fixing AI‑found SharePoint vulnerabilitiesAnthropic’s Claude Mythos AI revealed 90 critical and 141 important SharePoint bugs in April; Microsoft is scrambling to patch them, leaving around 300 medium‑severity issues unaddressed and warning that un‑rem
-
9 days ago
[TECHNOLOGY] 9 sourcesUS CISA adds critical software flaws to its Known Exploited Vulnerabilities catalogUS CISA added critical DD‑WRT, Langflow, WordPress and Check Point SmartConsole vulnerabilities—including CVE‑2026‑16232—to its Known Exploited Vulnerabilities catalog, urging immediate patching.
-
10 days ago
[TECHNOLOGY] 4 sourcesMicrosoft SharePoint and Windows Vulnerabilities Prompt Urgent PatchesMicrosoft SharePoint (CVE‑2026‑50522) and Windows LegacyHive flaws are being actively exploited; patches and a free 0patch micro‑fix are urged.
-
12 days ago
[TECHNOLOGY] 2 sourcesMicrosoft SharePoint on‑premises flaws exploited; patches and key rotation urgedCISA lists critical on‑premise SharePoint flaws (CVE‑2026‑58644, CVE‑2026‑50522) as actively exploited; attackers steal machine keys, so immediate patching, key rotation and network segmentation are urged.
-
12 days ago
[TECHNOLOGY] 2 sourcesEU and US regulators tighten cybersecurity measures as new vulnerabilities and sanctions emergeCERT‑FR flags critical SharePoint, Windows and Firefox flaws; EU sanctions Russian intel and Turla, proposes junior social‑media rules; NY bans large AI datacenters for a year.
-
16 days ago
[TECHNOLOGY] 6 sourcesUS CISA urges urgent hardening of Microsoft SharePoint after active exploitsCISA warns that three SharePoint flaws are actively exploited and urges immediate patching, segmentation and other defenses, giving federal agencies three days to remediate the newest vulnerability.
-
17 days ago
[TECHNOLOGY] 5 sourcesSAP releases patches for critical NetWeaver ABAP and other security flawsSAP issued July 2026 patches fixing three critical CVEs, including a 9.9‑rated NetWeaver ABAP flaw, and urges immediate customer updates.
-
23 days ago
[TECHNOLOGY] 5 sourcesUS CISA and German BSI order urgent patches for critical software flawsBSI warns of high‑severity Linux kernel flaws; Oracle releases patches. CISA mandates US agencies patch critical ColdFusion, AI, and Linux kernel bugs by July 10.
-
24 days ago
[TECHNOLOGY] 2 sourcesUbiquiti patches 25 critical UniFi vulnerabilitiesUbiquiti released patches for 25 UniFi software flaws, seven rated critical with CVSS up to 10.0, fixing remote takeover risks across its networking and surveillance products.
-
about 1 month ago
[TECHNOLOGY] 6 sourcesCritical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelpJTL‑Shop, Chrome, Langflow and SimpleHelp each face critical, actively exploited vulnerabilities; patches are available and users must update immediately.
-
about 1 month ago
[TECHNOLOGY] 4 sourcesCISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28CISA orders US federal agencies to patch critical Cisco Unified CM SSRF flaw (CVE‑2026‑20230) and PTC PLM vulnerability by June 28, citing active exploitation.
-
about 1 month ago
[TECHNOLOGY] 4 sourcesCritical Ubiquiti Device Vulnerabilities Exploited by AttackersUbiquiti disclosed three CVSS 10/10 flaws that let unauthenticated attackers alter systems, access accounts and run commands; a May patch was issued but exploitation is already reported.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesMicrosoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threatsMicrosoft uncovered a dual‑actor breach while Mandiant identified a Cisco SD‑WAN zero‑day that gave attackers root access, showing evolving multi‑actor cyber threats.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesCybersecurity firms stress exploitability over vulnerability scansCybersecurity experts say vulnerability scans identify gaps but attackers focus on exploitability; firms should prioritize exposing actionable risk over completing security activities.
-
about 1 month ago
[TECHNOLOGY] 9 sourcesCritical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and UbiquitiMultiple critical flaws affect FFmpeg (PixelSmash), Lantronix EDS5000, Cisco Unified CM and Ubiquiti UniFi OS, with active exploitation and CISA KEV listings; NinjaOne adds KEV data to its management tool.
-
about 1 month ago
[TECHNOLOGY] 4 sourcesCritical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OSCritical flaws in JTL Shop (CVE‑2026‑54390), Cisco ISE (CVE‑2026‑20181/20190) and Ubiquiti UniFi OS (CVE‑2026‑34908‑34910) enable unauthenticated remote code execution or root access; vendors urge immediate up‑
-
about 2 months ago
[TECHNOLOGY] 2 sourcesIT asset patch gaps and fragmented endpoint management expose security risksStudies show IT teams spend over half their time on routine endpoint work, while 18‑19 % of assets lack proper patching and 65 % of non‑BEC incidents exploit remote‑access gaps.
-
about 2 months ago
[TECHNOLOGY] 4 sourcesCisco patches actively exploited SD‑WAN Manager zero‑day vulnerabilityCisco patched CVE‑2026‑20262, a zero‑day SD‑WAN Manager bug exploited to gain root, after CISA flagged it as actively used and set a two‑week federal patch deadline.
-
about 2 months ago
[TECHNOLOGY] 2 sourcesCisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root ExploitsCisco reports active exploitation of CVE‑2026‑20245 in its SD‑WAN Manager, while a newly found Linux kernel CIFSwitch flaw lets unprivileged users gain root, affecting major distributions.
-
2 months ago
[TECHNOLOGY] 3 sourcesEnterprise Vulnerability Management Shifts Toward Real‑World Exploit PrioritizationVulnerability exploitation rose sharply in 2025; security firms cite gaps in patch validation, correlation, and prioritization. Solutions like HCL BigFix and risk‑based patching use threat intel and asset data,
-
2 months ago
[TECHNOLOGY] 3 sourcesCritical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent PatchesA critical LiteSpeed cPanel plug‑in flaw (CVE‑2026‑48172) enabling root‑level attacks is being exploited; CISA ordered urgent patches and cPanel auto‑removes the plug‑in.
-
2 months ago
[TECHNOLOGY] 5 sourcesArch Linux users urged to patch PinTheft kernel flawPatch Arch Linux now for PinTheft kernel bug that lets local attackers gain root.
-
2 months ago
[TECHNOLOGY] 2 sourcesLinux kernel and Windows Telephony Service patched for critical vulnerabilitiesLinux kernel TIPC and Windows Telephony Service flaws patched to stop code execution attacks.
-
2 months ago
[TECHNOLOGY] 2 sourcesLinux kernel hardening tool ModuleJail released as new privilege‑escalation flaws emergeLinux kernel faces new LPE flaws; ModuleJail tool blacklists unused modules to cut attack surface.
-
2 months ago
[TECHNOLOGY] 2 sourcesLinux kernel introduces Rust Untrusted Data API amid AI bug‑report backlashLinux adds a Rust API for safer untrusted data handling, while Torvalds denounces rising AI‑generated bug reports.
-
3 months ago
[TECHNOLOGY] 2 sourcesLinux kernel hit by third critical local privilege flaw in weeksLinux kernel suffers two new local privilege flaws—Fragnesia (root access) and a ptrace race (secret leakage)—prompting urgent patches.
-
3 months ago
[TECHNOLOGY] 2 sourcesCybersecurity Alerts: Ubuntu Twitter Scam and 'Dirty Frag' Root‑Access BugUbuntu's Twitter was hacked for a scam, and a new 'Dirty Frag' bug grants root access.
-
3 months ago
[TECHNOLOGY] 5 sourcesCopyFail Linux kernel flaw enables local root escalation across major distributionsCopyFail (CVE‑2026‑31431) is a Linux kernel bug that lets local attackers gain root; patches are rolling out across major distros.
-
3 months ago
[TECHNOLOGY] 3 sourcesRapid Exploits Pressure Faster Patch Management Across EnterprisesFast‑moving exploits, like a China‑focused RCE bug, expose slow patching; vendors tout unified AI‑driven solutions.
-
3 months ago
[TECHNOLOGY] 47 sourcesUS CISA flags critical cPanel/WHM and Linux CopyFail bugs actively exploitedCISA warns that cPanel/WHM and Linux CopyFail bugs are being actively exploited, urging immediate patches.
-
3 months ago
[TECHNOLOGY] 17 sourcesLinux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploitscPanel/WHM breach spreads ransomware and Mirai botnet; a kernel flaw (CVE‑2026‑31431) enables root escalation, patches rolling out.
-
3 months ago
[TECHNOLOGY] 2 sourcesMillions of websites at risk as cPanel zero-day is actively exploitedMillions of websites exposed as the cPanel zero-day CVE-2026-41940 is exploited in the wild ahead of patches.
Sources
activestate.com · all-about-security.de · appgate.com · arstechnica.com · avleonov.com · b2b-cyber-security.de · bdew.de · bishopfox.com · bitmat.it · bleepingcomputer.com · blog.0patch.com · blog.cloudlinux.com · blog.kangaroo.cmo.de · blog.qualys.com · blog.samwhited.com · blogspan.net · bobsummerwill.com · borncity.com · business.scoop.co.nz · canonical.com · charliehebdo.fr · cinemagia.wordpress.com · clickx.be · clubic.com · commonwealthunion.com · complexdiscovery.com · computerworld.com.au · conterest.de · cosmeticacupuncturemelbourne.com.au · cryptobreaking.com · csoonline.com.au · cyberinsider.com · cybersecurity-news.de · cybersecuritynews.com · davfi.fr · de.tenable.com · decrypt.co · digital-magazin.de · electropages.com · emarketerz.fr · estugo.de · etbe.coker.com.au · evere.co · executivegov.com · file.net · fiscaltiger.com · flagthis.com · franksworld.com