# Software vulnerability exploits & patch response, 2026

> Live situation record from CLSTR: https://clstr.news/situations/critical-software-bugs-spark-a-wave-of-exploits-and-accelerated-patch-campaigns
> Updated: 2026-09-06T05:02:41.000Z. Sources: 142. Developments: 41.

The wave of exploitation observed in July 2026 continued into August, with significant impacts on government infrastructure and core operating systems. In Switzerland, the breach of federal SharePoint servers was further detailed. Unknown actors exploited CVE-2026-56164 and CVE-2026-50522 to access the Federal Office for Information Technology and Telecommunication (BIT) servers. The breach, detected on 28 July 2026, resulted in the compromise of approximately 200 user and technical accounts. In response, the Swiss government isolated the servers, disconnected them from the internet, and initiated a full environment rebuild. While BIT is working with Microsoft and the Federal Office for Cybersecurity (BACS) on forensics, officials stated that no confidential or sensitive personal data is believed to have been stored on the platform, and no evidence of dark web exfiltration has been found. Simultaneously, Microsoft’s August security updates addressed 398 vulnerabilities, including 62 critical flaws. A notable active exploit, CVE-2026-68820, targets a use-after-free error in the Windows Ancillary Function Driver for WinSock (afd.sys). New disclosures in mid-August highlighted further critical risks. Oasis Security identified CVE-2026-41679, a CVSS 10.0 vulnerability in the Paperclip orchestration platform. Researchers also identified an unauthenticated RCE chain in Microsoft SharePoint, combining a JWT authentication-bypass (CVE-2026-55040) with a flaw in Business Connectivity Services (CVE-2026-63520). Further research uncovered complex chains targeting the Windows kernel and hypervisor, dubbed ‘Download More RAM,’ which can bypass Virtualization-Based Security (VBS). Additionally, a vulnerability in Microsoft System Center Configuration Manager (SCCM) allows remote code execution via an authorization issue and a path traversal flaw known as ‘CabSlip.’ In late August, Microsoft addressed CVE-2026-50522 in SharePoint, involving untrusted data deserialization. Concurrently, Microsoft disclosed a critical remote code execution (RCE) vulnerability in Entra ID, tracked as CVE-2026-69836. In early September 2026, new critical vulnerabilities emerged.

## Claims

- Anthropic's Claude Mythos Preview identified 90 critical vulnerabilities in Microsoft SharePoint in April. (disputed by 4 sources)
- Claude Mythos Preview identified 141 important vulnerabilities in SharePoint in April. (disputed by 4 sources)
- Around 300 medium‑severity SharePoint findings were deprioritized for later remediation. (corroborated by 4 sources)
- Hundreds of serious vulnerabilities were also discovered in Microsoft 365, Teams and Copilot by May. (corroborated by 3 sources)
- Four low‑severity flaws can be chained together to create a high‑severity vulnerability. (corroborated by 3 sources)
- Microsoft has fully mitigated the CVE-2026-69836 vulnerability on its servers. (corroborated by 3 sources)
- The CVE-2026-69836 vulnerability was actively exploited by threat actors before being patched. (corroborated by 3 sources)
- Microsoft principal security engineer Robert Fitzpatrick discovered and reported the vulnerability. (corroborated by 3 sources)
- The CVE-2026-69836 vulnerability has a CVSS score of 10.0. (corroborated by 3 sources)
- The vulnerability is caused by the unsafe deserialization of untrusted data. (corroborated by 3 sources)
- Because Entra ID is a managed cloud service, users do not need to install any patches or updates. (corroborated by 3 sources)
- Microsoft engineers held an internal meeting in mid‑May to accelerate patching, setting May 31 as a deadline before the wider security community could catch up. (corroborated by 2 sources)

## Timeline

### 2026-09-06: Microsoft discloses nine vulnerabilities including two critical CVSS 10.0 flaws

Microsoft disclosed nine vulnerabilities, including two with a CVSS 10.0 rating, affecting Azure AD B2C, Entra ID, and Copilot Studio due to authentication and authorization bypasses.

4 sources. https://clstr.news/cluster/microsoft-discloses-nine-vulnerabilities-including-two-critical-cvss-100-flaws

### 2026-09-03: Mozilla and Microsoft patch critical software vulnerabilities

Mozilla patched a critical Thunderbird vulnerability involving malicious calendar invites, while Microsoft resolved a high-severity RCE flaw in Entra ID that was not actively exploited.

3 sources. https://clstr.news/cluster/mozilla-and-microsoft-patch-critical-software-vulnerabilities

### 2026-08-25: Microsoft Entra ID vulnerability receives maximum CVSS 10.0 rating

Microsoft patched a critical CVE-2026-69836 vulnerability in Entra ID with a maximum CVSS score of 10.0. The flaw allowed unauthenticated remote code execution via untrusted data deserialization.

3 sources. https://clstr.news/cluster/microsoft-entra-id-vulnerability-receives-maximum-cvss-100-rating

### 2026-08-22: Microsoft patches critical Entra ID remote code execution vulnerability

Microsoft has patched a critical 10.0 CVSS-rated remote code execution vulnerability in Entra ID. The flaw was discovered internally and fixed on the server side, requiring no action from customers.

7 sources. https://clstr.news/cluster/microsoft-patches-critical-entra-id-remote-code-execution-vulnerability

### 2026-08-20: Microsoft Entra ID critical RCE vulnerability exploited

Microsoft confirmed that a critical CVSS 10.0 remote code execution vulnerability in Entra ID (CVE-2026-69836) was exploited in the wild. The issue has been mitigated server-side by Microsoft.

13 sources. https://clstr.news/cluster/microsoft-faces-critical-rce-vulnerabilities-in-sharepoint-and-entra-id

### 2026-08-16: Microsoft software faces critical vulnerability chains

Researchers have uncovered critical vulnerability chains in Microsoft Windows and SCCM that allow for kernel-mode code execution and remote system compromise.

3 sources. https://clstr.news/cluster/microsoft-software-faces-critical-vulnerability-chains

### 2026-08-11: Cybersecurity researchers disclose critical RCE vulnerabilities in Paperclip and SharePoint

Researchers have identified critical RCE vulnerabilities in the Paperclip orchestration platform and Microsoft SharePoint, involving unauthenticated access and full server compromise.

3 sources. https://clstr.news/cluster/cybersecurity-researchers-disclose-critical-rce-vulnerabilities-in-paperclip-and-sharepoint

### 2026-08-11: Microsoft SharePoint vulnerability exploited in active attacks

Attackers are actively exploiting a critical SharePoint vulnerability (CVE-2026-55040) that allows unauthenticated identity impersonation and potential remote code execution.

5 sources. https://clstr.news/cluster/microsoft-sharepoint-vulnerability-exploited-in-active-attacks

### 2026-08-07: Swiss Government SharePoint Servers Breached, Hundreds of Accounts

Unknown attackers exploited recent SharePoint flaws to breach Swiss BIT servers, accessing about 200 accounts. No sensitive data leaked; servers are being rebuilt with Microsoft and BACS support.

3 sources. https://clstr.news/cluster/swiss-government-sharepoint-servers-breached-hundreds-of-accounts

### 2026-07-29: Microsoft grapples with backlog fixing AI‑found SharePoint vulnerabilities

Anthropic’s Claude Mythos AI revealed 90 critical and 141 important SharePoint bugs in April; Microsoft is scrambling to patch them, leaving around 300 medium‑severity issues unaddressed and warning that un‑rem

8 sources. https://clstr.news/cluster/microsoft-races-to-patch-aifound-sharepoint-vulnerabilities

### 2026-07-22: US CISA adds critical software flaws to its Known Exploited Vulnerabilities catalog

US CISA added critical DD‑WRT, Langflow, WordPress and Check Point SmartConsole vulnerabilities—including CVE‑2026‑16232—to its Known Exploited Vulnerabilities catalog, urging immediate patching.

9 sources. https://clstr.news/cluster/us-cisa-adds-critical-software-flaws-to-its-known-exploited-vulnerabilities-catalog

### 2026-07-22: Microsoft SharePoint and Windows Vulnerabilities Prompt Urgent Patches

Microsoft SharePoint (CVE‑2026‑50522) and Windows LegacyHive flaws are being actively exploited; patches and a free 0patch micro‑fix are urged.

4 sources. https://clstr.news/cluster/microsoft-sharepoint-and-windows-vulnerabilities-prompt-urgent-patches

### 2026-07-20: Microsoft SharePoint on‑premises flaws exploited; patches and key rotation urged

CISA lists critical on‑premise SharePoint flaws (CVE‑2026‑58644, CVE‑2026‑50522) as actively exploited; attackers steal machine keys, so immediate patching, key rotation and network segmentation are urged.

2 sources. https://clstr.news/cluster/microsoft-sharepoint-onpremises-flaws-exploited-patches-and-key-rotation-urged

### 2026-07-19: EU and US regulators tighten cybersecurity measures as new vulnerabilities and sanctions emerge

CERT‑FR flags critical SharePoint, Windows and Firefox flaws; EU sanctions Russian intel and Turla, proposes junior social‑media rules; NY bans large AI datacenters for a year.

2 sources. https://clstr.news/cluster/eu-and-us-regulators-tighten-cybersecurity-measures-as-new-vulnerabilities-and-sanctions-emerge

### 2026-07-16: US CISA urges urgent hardening of Microsoft SharePoint after active exploits

CISA warns that three SharePoint flaws are actively exploited and urges immediate patching, segmentation and other defenses, giving federal agencies three days to remediate the newest vulnerability.

6 sources. https://clstr.news/cluster/us-cisa-urges-urgent-hardening-of-microsoft-sharepoint-after-active-exploits

### 2026-07-14: SAP releases patches for critical NetWeaver ABAP and other security flaws

SAP issued July 2026 patches fixing three critical CVEs, including a 9.9‑rated NetWeaver ABAP flaw, and urges immediate customer updates.

5 sources. https://clstr.news/cluster/sap-releases-patches-for-critical-netweaver-abap-and-other-security-flaws

### 2026-07-08: US CISA and German BSI order urgent patches for critical software flaws

BSI warns of high‑severity Linux kernel flaws; Oracle releases patches. CISA mandates US agencies patch critical ColdFusion, AI, and Linux kernel bugs by July 10.

5 sources. https://clstr.news/cluster/us-cisa-and-german-bsi-order-urgent-patches-for-critical-software-flaws

### 2026-07-07: Ubiquiti patches 25 critical UniFi vulnerabilities

Ubiquiti released patches for 25 UniFi software flaws, seven rated critical with CVSS up to 10.0, fixing remote takeover risks across its networking and surveillance products.

2 sources. https://clstr.news/cluster/ubiquiti-patches-25-critical-unifi-vulnerabilities

### 2026-06-30: Critical security flaws exploited in JTL‑Shop, Chrome, Langflow and SimpleHelp

JTL‑Shop, Chrome, Langflow and SimpleHelp each face critical, actively exploited vulnerabilities; patches are available and users must update immediately.

6 sources. https://clstr.news/cluster/critical-jtlshop-and-simplehelp-vulnerabilities-demand-patches

### 2026-06-24: CISA orders US federal agencies to patch critical Cisco Unified CM flaw by June 28

CISA orders US federal agencies to patch critical Cisco Unified CM SSRF flaw (CVE‑2026‑20230) and PTC PLM vulnerability by June 28, citing active exploitation.

4 sources. https://clstr.news/cluster/cisco-unified-cm-critical-ssrf-flaw-cve202620230-exploited-in-the-wild

### 2026-06-24: Critical Ubiquiti Device Vulnerabilities Exploited by Attackers

Ubiquiti disclosed three CVSS 10/10 flaws that let unauthenticated attackers alter systems, access accounts and run commands; a May patch was issued but exploitation is already reported.

4 sources. https://clstr.news/cluster/critical-ubiquiti-device-vulnerabilities-exploited-by-attackers

### 2026-06-24: Microsoft and Cisco reveal sophisticated multi‑actor and zero‑day cyber threats

Microsoft uncovered a dual‑actor breach while Mandiant identified a Cisco SD‑WAN zero‑day that gave attackers root access, showing evolving multi‑actor cyber threats.

3 sources. https://clstr.news/cluster/microsoft-and-cisco-reveal-sophisticated-multiactor-and-zeroday-cyber-threats

### 2026-06-24: Cybersecurity firms stress exploitability over vulnerability scans

Cybersecurity experts say vulnerability scans identify gaps but attackers focus on exploitability; firms should prioritize exposing actionable risk over completing security activities.

2 sources. https://clstr.news/cluster/cybersecurity-firms-stress-exploitability-over-vulnerability-scans

### 2026-06-22: Critical Software and Hardware Flaws Discovered in FFmpeg, Lantronix, Cisco and Ubiquiti

Multiple critical flaws affect FFmpeg (PixelSmash), Lantronix EDS5000, Cisco Unified CM and Ubiquiti UniFi OS, with active exploitation and CISA KEV listings; NinjaOne adds KEV data to its management tool.

9 sources. https://clstr.news/cluster/ffmpeg-patches-critical-pixelsmash-flaw-in-magicyuv-decoder-impacting-media-servers

### 2026-06-17: Critical Vulnerabilities Found in JTL Shop, Cisco ISE and Ubiquiti UniFi OS

Critical flaws in JTL Shop (CVE‑2026‑54390), Cisco ISE (CVE‑2026‑20181/20190) and Ubiquiti UniFi OS (CVE‑2026‑34908‑34910) enable unauthenticated remote code execution or root access; vendors urge immediate up‑

4 sources. https://clstr.news/cluster/cisco-ise-critical-vulnerabilities-enable-remote-code-execution-and-root-privilege-escalation

### 2026-06-16: IT asset patch gaps and fragmented endpoint management expose security risks

Studies show IT teams spend over half their time on routine endpoint work, while 18‑19 % of assets lack proper patching and 65 % of non‑BEC incidents exploit remote‑access gaps.

2 sources. https://clstr.news/cluster/it-asset-patch-gaps-and-fragmented-endpoint-management-expose-security-risks

### 2026-06-15: Cisco patches actively exploited SD‑WAN Manager zero‑day vulnerability

Cisco patched CVE‑2026‑20262, a zero‑day SD‑WAN Manager bug exploited to gain root, after CISA flagged it as actively used and set a two‑week federal patch deadline.

4 sources. https://clstr.news/cluster/cisco-patches-actively-exploited-sdwan-manager-zeroday-vulnerability

### 2026-06-09: Cisco SD‑WAN Manager and Linux Kernel Flaws Enable Active Root Exploits

Cisco reports active exploitation of CVE‑2026‑20245 in its SD‑WAN Manager, while a newly found Linux kernel CIFSwitch flaw lets unprivileged users gain root, affecting major distributions.

2 sources. https://clstr.news/cluster/cisco-sdwan-manager-and-linux-kernel-flaws-enable-active-root-exploits

### 2026-06-01: Enterprise Vulnerability Management Shifts Toward Real‑World Exploit Prioritization

Vulnerability exploitation rose sharply in 2025; security firms cite gaps in patch validation, correlation, and prioritization. Solutions like HCL BigFix and risk‑based patching use threat intel and asset data,

3 sources. https://clstr.news/cluster/enterprise-vulnerability-management-shifts-toward-realworld-exploit-prioritization

### 2026-05-27: Critical LiteSpeed cPanel Plugin Flaw (CVE‑2026‑48172) Exploited, Prompting Urgent Patches

A critical LiteSpeed cPanel plug‑in flaw (CVE‑2026‑48172) enabling root‑level attacks is being exploited; CISA ordered urgent patches and cPanel auto‑removes the plug‑in.

3 sources. https://clstr.news/cluster/critical-litespeed-cpanel-plugin-flaw-cve202648172-exploited-prompting-urgent-patches

### 2026-05-20: Arch Linux users urged to patch PinTheft kernel flaw

Patch Arch Linux now for PinTheft kernel bug that lets local attackers gain root.

5 sources. https://clstr.news/cluster/arch-linux-users-urged-to-patch-pintheft-kernel-flaw

### 2026-05-19: Linux kernel and Windows Telephony Service patched for critical vulnerabilities

Linux kernel TIPC and Windows Telephony Service flaws patched to stop code execution attacks.

2 sources. https://clstr.news/cluster/linux-kernel-and-windows-telephony-service-patched-for-critical-vulnerabilities

### 2026-05-18: Linux kernel hardening tool ModuleJail released as new privilege‑escalation flaws emerge

Linux kernel faces new LPE flaws; ModuleJail tool blacklists unused modules to cut attack surface.

2 sources. https://clstr.news/cluster/linux-kernel-hardening-tool-modulejail-released-as-new-privilegeescalation-flaws-emerge

### 2026-05-18: Linux kernel introduces Rust Untrusted Data API amid AI bug‑report backlash

Linux adds a Rust API for safer untrusted data handling, while Torvalds denounces rising AI‑generated bug reports.

2 sources. https://clstr.news/cluster/linux-kernel-introduces-rust-untrusted-data-api-amid-ai-bugreport-backlash

### 2026-05-17: Linux kernel hit by third critical local privilege flaw in weeks

Linux kernel suffers two new local privilege flaws—Fragnesia (root access) and a ptrace race (secret leakage)—prompting urgent patches.

2 sources. https://clstr.news/cluster/linux-kernel-hit-by-third-critical-local-privilege-flaw-in-weeks

### 2026-05-10: Cybersecurity Alerts: Ubuntu Twitter Scam and 'Dirty Frag' Root‑Access Bug

Ubuntu's Twitter was hacked for a scam, and a new 'Dirty Frag' bug grants root access.

2 sources. https://clstr.news/cluster/cybersecurity-alerts-ubuntu-twitter-scam-and-dirty-frag-rootaccess-bug

### 2026-05-06: CopyFail Linux kernel flaw enables local root escalation across major distributions

CopyFail (CVE‑2026‑31431) is a Linux kernel bug that lets local attackers gain root; patches are rolling out across major distros.

5 sources. https://clstr.news/cluster/copyfail-linux-kernel-flaw-enables-local-root-escalation-across-major-distributions

### 2026-05-04: Rapid Exploits Pressure Faster Patch Management Across Enterprises

Fast‑moving exploits, like a China‑focused RCE bug, expose slow patching; vendors tout unified AI‑driven solutions.

3 sources. https://clstr.news/cluster/rapid-exploits-pressure-faster-patch-management-across-enterprises

### 2026-05-04: US CISA flags critical cPanel/WHM and Linux CopyFail bugs actively exploited

CISA warns that cPanel/WHM and Linux CopyFail bugs are being actively exploited, urging immediate patches.

47 sources. https://clstr.news/cluster/us-cisa-flags-critical-cpanelwhm-and-linux-copyfail-bugs-actively-exploited

### 2026-05-04: Linux hosting providers hit by ransomware, Mirai botnet and kernel privilege‑escalation exploits

cPanel/WHM breach spreads ransomware and Mirai botnet; a kernel flaw (CVE‑2026‑31431) enables root escalation, patches rolling out.

17 sources. https://clstr.news/cluster/linux-hosting-providers-hit-by-ransomware-mirai-botnet-and-kernel-privilegeescalation-exploits

### 2026-04-30: Millions of websites at risk as cPanel zero-day is actively exploited

Millions of websites exposed as the cPanel zero-day CVE-2026-41940 is exploited in the wild ahead of patches.

2 sources. https://clstr.news/cluster/millions-of-websites-at-risk-as-cpanel-zero-day-is-actively-exploited

---
Cite as: Software vulnerability exploits & patch response, 2026. CLSTR, https://clstr.news/situations/critical-software-bugs-spark-a-wave-of-exploits-and-accelerated-patch-campaigns
