CVE-2026-10577, CVE-2026-13221, CVE-2026-15028, CVE-2026-15409, CVE-2026-15410, CVE-2026-32201, CVE-2026-39822, CVE-2026-42505, CVE-2026-42975, CVE-2026-45659, CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871, CVE-2026-48561, CVE-2026-48564, CVE-2026-49164, CVE-2026-49174, CVE-2026-50327, CVE-2026-50328, CVE-2026-50370, CVE-2026-50518, CVE-2026-50522, CVE-2026-50655, CVE-2026-50661, CVE-2026-50663, CVE-2026-50694, CVE-2026-54128, CVE-2026-54982, CVE-2026-54983, CVE-2026-54992, CVE-2026-54995, CVE-2026-55008, CVE-2026-55010, CVE-2026-55040, CVE-2026-55944, CVE-2026-56155, CVE-2026-56159, CVE-2026-56164, CVE-2026-56188, CVE-2026-57092, CVE-2026-57219, CVE-2026-57432, CVE-2026-58644, CVE-2026-59831, CVE-2026-59875
Get tomorrow's brief in your inbox
Today: Microsoft ships a record 622 patches including two zero-days under active exploitation in SharePoint and AD FS. SonicWall warns of two zero-day vulnerabilities in SMA1000 appliances being actively exploited with CISA deadlines set for July 17. Treasury sanctions VPN service and cryptor vendors enabling ransomware operations.
Microsoft July 2026 Patch Tuesday - Record 622 Vulnerabilities
Microsoft released patches for 622 vulnerabilities in its July 2026 Patch Tuesday, the largest release in program history. Two zero-days are under active exploitation: CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. CVE-2026-56164 allows unauthenticated attackers to escalate privileges over the network through missing authentication in a critical function. CVE-2026-56155 permits authenticated attackers to elevate privileges locally in AD FS through insufficient access control granularity. CISA added both to its KEV catalog with remediation deadlines of July 17 for SharePoint and July 28 for AD FS. The massive patch count stems from Microsoft's AI-driven multi-model agentic scanning harness (MDASH) that accelerates vulnerability discovery across the Windows codebase. The release includes 57 critical vulnerabilities, primarily remote code execution flaws affecting Windows services, Office applications, SharePoint, SQL Server, and other Microsoft products.
CISA SharePoint Hardening Alert - Active Exploitation Chain
CISA issued an alert warning of active exploitation targeting on-premises SharePoint Server instances through three vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. Attackers establish remote code execution and perform post-exploitation activities including stealing IIS machine keys and using deserialization techniques to deploy malware and gain persistence. CISA provided specific AMSI and Microsoft Defender Antivirus detection signatures including Exploit:Script/SuspSignoutReqBody.A, Exploit:Script/ToolPaneAuthBypass.A, Exploit:Script/ToolPaneAuthBypass.C, and Backdoor:MSIL/LeakFang.A for machine-key harvesting. CVE-2026-32201 has a CISA KEV deadline of April 28, CVE-2026-45659 deadline of July 4, and CVE-2026-56164 deadline of July 17.
SonicWall SMA1000 Zero-Days Exploited (CVE-2026-15409, CVE-2026-15410)
SonicWall warned of active exploitation targeting two zero-day vulnerabilities in Secure Mobile Access (SMA) 1000 series appliances affecting versions 6210, 7210, and 8200v. CVE-2026-15409 (CVSS 10.0) is a critical server-side request forgery vulnerability in the Appliance Work Place interface allowing remote unauthenticated attackers to cause the appliance to make requests to unintended locations. CVE-2026-15410 (CVSS 7.2) is a high-severity code injection flaw in the Appliance Management Console allowing authenticated administrators to execute arbitrary OS commands. The vulnerabilities can be chained together. CISA added both to its KEV catalog with a July 17 remediation deadline for federal agencies. Volexity assisted SonicWall's investigation and provided indicators of compromise.
BitLocker Bypass Publicly Disclosed (CVE-2026-50661)
Microsoft patched CVE-2026-50661 (CVSS 6.1), a publicly disclosed security feature bypass in Windows BitLocker. The vulnerability allows attackers with physical access to bypass BitLocker's Device Encryption feature and access encrypted data. The flaw was disclosed before Patch Tuesday by an anonymous researcher and continues a series of BitLocker bypasses including bitskrieg and YellowKey from earlier in 2026. While not under active exploitation, organizations should prioritize patching for devices at physical risk.
Progress ShareFile Zero-Day Disruption Resolved
Progress Software confirmed a zero-day path traversal vulnerability caused the recent ShareFile Storage Zones Controller disruption. The company disabled access to ShareFile for all Storage Zones Controller customers on July 12 due to a credible external security threat. Access was restored on July 14 after Progress developed and released patches for the high-severity vulnerability affecting versions 5.x and 6.x. The vulnerability requires administrative privileges and allows authenticated admins to read arbitrary files accessible to the application service account, write attacker-controlled content to arbitrary directories, or enumerate the server filesystem. Progress claims no evidence of customer data compromise. Security researchers note the aggressive response for an admin-only vulnerability suggests there may be additional undisclosed attack context.
VMware Avi Load Balancer - 7 Severe Vulnerabilities
Broadcom patched seven critical and high-severity vulnerabilities in VMware Avi Load Balancer. CVE-2026-47865 is a critical authentication bypass allowing attackers with network access to breach the Avi control plane. Three high-severity flaws (CVE-2026-47866, CVE-2026-47867, CVE-2026-47868) allow authentication bypass, arbitrary code execution, and privilege escalation to root requiring network or local access. CVE-2026-47871 and CVE-2026-47870 are high-severity directory traversal and privilege escalation flaws. CVE-2026-47869 is a high-severity remote code execution vulnerability requiring authenticated network access. No in-the-wild exploitation reported, but VMware products are frequently targeted.
Rockwell Automation Critical ICS Vulnerabilities
Rockwell Automation patched critical vulnerabilities in industrial control systems. CVE-2026-10577 (CVSS 10.0) in the 1715-AENTR EtherNet/IP Adapter exposes a network-accessible debug port without privilege controls, allowing unauthenticated remote access to intrusive CLI commands. Attackers can read or delete files, stop tasks, modify memory, and change I/O states. Three critical DoS vulnerabilities in CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers can cause major non-recoverable faults. High-severity vulnerabilities were also patched in Flex 5000 Adapter, FactoryTalk DataMosaix, FactoryTalk Services Platform, Arena, ThinManager, Studio 5000 Logix Designer, and other products.
Treasury Sanctions VPN Service and Cryptor Vendors Enabling Ransomware
The U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its administrator, Ukrainian citizen Dmytro Rashevskyi, for providing infrastructure to ransomware operators. 1VPNS advertised in cybercrime forums for over a decade, touting its refusal to cooperate with law enforcement. Ransomware groups purchased infrastructure to hide attack origins, deploy malware, and manage exfiltrated data. Victims include U.S. businesses, financial services companies, hospitals, and municipal governments. Treasury also sanctioned Belarus national Yegeniy Vladimirovich Silayev for selling cryptors (tools to disguise ransomware and malware) to ransomware operators. Blockchain intelligence firm TRM Labs tracked payments ranging from $58 to $723 for services. Europol arrested the 1VPNS administrator in May following a sting operation.
Kerberos RC4 Hardening Complete - Potential Login Breakage
Microsoft's July update completes the multi-year Kerberos RC4 hardening by removing the RC4DefaultDisablementPhase rollback switch. After this update, RC4 works only for accounts specifically allowed through registry or group policy. Organizations that relied on the rollback switch since the crackdown began in January will need to ensure their environment supports AES for Kerberos authentication. This change can break logins if systems or applications still depend on RC4 and have not been migrated to AES.
Active Directory Domain Services RCE (CVE-2026-49164)
Microsoft patched CVE-2026-49164, a critical heap-based buffer overflow in Active Directory Domain Services allowing unauthorized attackers to execute code over a network. Microsoft did not assign an exploitation likelihood rating.
AD FS Denial of Service (CVE-2026-54983)
Microsoft patched CVE-2026-54983, a stack-based buffer overflow in Active Directory Federation Services allowing unauthorized attackers to deny service over a network.
WSUS Tampering Vulnerability (CVE-2026-50328)
Microsoft patched CVE-2026-50328, an uncaught exception in Windows Server Update Service allowing unauthorized attackers to perform tampering over a network.
OAuth Client ID Spoofing in Microsoft Entra ID
Two threat actor clusters are exploiting OAuth client ID spoofing to enumerate accounts and validate stolen credentials in Microsoft Entra ID environments without generating successful sign-in events. The technique leverages spoofed OAuth client IDs in authentication requests to Microsoft's OAuth 2.0 token endpoint using Resource Owner Password Credentials (ROPC) flow. By analyzing error response codes (AADSTS), attackers infer whether accounts exist and passwords are correct without triggering standard telemetry. UNK_pyreq2323 targeted over 1 million accounts across 4,000 tenants from January to March 2026 using 700,000+ spoofed client IDs from AWS infrastructure, causing lockouts for 28% of targeted users. UNK_OutFlareAZ targeted over 2 million users with 3.7 million randomized spoofed application IDs from Cloudflare infrastructure starting in December 2025.
ICS Patch Tuesday - Siemens, Schneider, ABB, Rockwell
Industrial control system vendors released July Patch Tuesday advisories. Siemens published nine advisories including six with critical vulnerabilities. A CVSS 10.0 token invalidation flaw in Opencenter X allows authentication bypass and full application access. Critical vulnerabilities were also patched in Mendix, Sidis Secured SmartPlug, Simatic S7-1500, Cadra, and Desigo CC enabling DoS attacks, code execution, data theft, and privilege escalation. Schneider Electric patched high-severity vulnerabilities in IGSS allowing arbitrary code execution via crafted files and an authentication bypass in EcoStruxure Cybersecurity Admin Expert. ABB addressed vulnerabilities in Advant Master Online Builder (DLL search path handling leading to unauthorized code execution) and T-MAC Plus (file disclosure, broken access controls, stored XSS). Germany's VDE CERT published advisories for Murrelektronik, Mettler Toledo, Codesys, and Wago products.
Microsoft Patch Tuesday - High Priority CVEs Beyond Zero-Days
Beyond the two exploited zero-days, Microsoft's July release includes several high-priority vulnerabilities. CVE-2026-57092 (CVSS 9.9) in Windows VMSwitch allows attackers to escape VM boundaries and compromise the host system. CVE-2026-48561 (CVSS 9.6) is a command injection RCE in Microsoft Copilot allowing unauthorized code execution over a network. CVE-2026-55008 (CVSS 9.6) is a spoofing vulnerability in Exchange Server that Microsoft flagged as more likely to be exploited, allowing unauthorized network-based spoofing. CVE-2026-58644 (CVSS 9.8) and CVE-2026-50522 (CVSS 9.8) are deserialization RCE vulnerabilities in SharePoint exploitable by unauthenticated attackers over a network. Eleven critical RCE vulnerabilities are rated "more likely" to be exploited, including heap-based buffer overflows in Windows DHCP Server (CVE-2026-50370, CVE-2026-50518), Windows DHCP client (CVE-2026-54128), Windows Media Foundation (CVE-2026-50327, CVE-2026-50655), MSMQ (CVE-2026-54992), Windows Server Network driver (CVE-2026-56188), Minecraft Bedrock Dedicated Server (CVE-2026-55010), and Microsoft Dynamics NAV/365 Business Central (CVE-2026-55944).
SharePoint JWT Authentication Bypass (CVE-2026-55040)
Rapid7 disclosed CVE-2026-55040, a JWT authentication bypass in SharePoint that was used in a Pwn2Own Berlin exploit chain. Rapid7 rates it CVSS 5.3 while ZDI reads Microsoft's rating as 9.1 critical, a four-point spread. Rapid7 chained this bypass to a separate RCE vulnerability to achieve unauthenticated RCE against vulnerable SharePoint servers. The RCE component is scheduled for patching in August 2026. The July patch breaks the exploit chain by fixing the authentication bypass, but the RCE remains unpatched until next month.
Windows DHCP Client and Server RCE Vulnerabilities
Microsoft patched multiple critical heap-based buffer overflow vulnerabilities in Windows DHCP services. CVE-2026-50370 and CVE-2026-50518 affect Windows DHCP Server, exploitable by unauthorized attackers over adjacent network and over a network respectively. CVE-2026-54128 is a use-after-free in the Windows DHCP client allowing unauthorized attackers to execute code locally. CVE-2026-48564 and CVE-2026-56159 are additional critical DHCP Server RCE flaws. All are rated "more likely" to be exploited. DHCP client vulnerabilities are particularly concerning for public WiFi attack scenarios.
Windows RMCAST Driver RCE (CVE-2026-54982, CVE-2026-54995)
Microsoft patched two critical remote code execution vulnerabilities in the Windows Reliable Multicast Transport Driver (RMCAST). Both are heap-based buffer overflows exploitable by network-adjacent attackers. Exploits require network-adjacent access, limiting the attack surface compared to remote vulnerabilities.
Third-Party Component Vulnerabilities in Microsoft Products
Microsoft's update includes patches for vulnerabilities in third-party components used in Microsoft products. CVE-2026-15028 affects Libarchive (heap overflow while parsing tar archives with pax extended headers). CVE-2026-59831 affects GitHub CLI (gh codespace jupyter could allow RCE when connecting to malicious Codespace). CVE-2026-42505 is a privacy leak in Go's crypto/tls affecting Encrypted Client Hello. CVE-2026-57432 affects Perl (integer overflow in S_measure_struct leading to out-of-bounds heap read in pack and unpack). CVE-2026-39822 affects Go's os package (root escape via symlink plus trailing slash). CVE-2026-57219 affects RabbitMQ (unauthenticated disclosure of OAuth client credentials via HTTP API endpoint with certain OAuth 2 configurations). CVE-2026-13221 affects Perl (incorrect regex matches when alternation exceeds 65535 fixed string branches). CVE-2026-59875 affects node-tar (uncaught exception DoS via NUL byte in PAX path/linkpath records).
Additional Critical Microsoft CVEs
Microsoft patched additional critical vulnerabilities across its product portfolio. CVE-2026-42975 is a heap-based buffer overflow in Windows Bluetooth Port Driver allowing RCE over adjacent network. CVE-2026-50663 is a relative path traversal in Age of Empires II: Definitive Edition allowing RCE over a network. CVE-2026-50694 is a use-after-free in Windows SSTP allowing RCE over a network. CVE-2026-55944 is a deserialization vulnerability in Microsoft Dynamics NAV allowing RCE over a network. CVE-2026-49174 is a DNS Client tampering vulnerability allowing authorized attackers to perform local tampering due to missing authentication.
This Patch Tuesday represents a pivotal shift from monthly patch cycles to continuous high-volume security updates driven by AI-powered vulnerability discovery. Microsoft's MDASH scanning harness is surfacing vulnerabilities at unprecedented rates, with 622 CVEs nearly triple the previous record. Organizations face growing prioritization challenges as AI dramatically increases the volume of flaws requiring attention. The traditional approach of reviewing every CVE is no longer viable. Defenders must focus on exploited vulnerabilities, CISA KEV additions, internet-facing systems, and critical infrastructure first. The two SharePoint zero-days and SonicWall SMA exploitation demonstrate that despite the higher volume, active exploitation remains the primary triage criterion. The aggressive vendor responses to SharePoint and Progress ShareFile incidents, combined with CISA's detailed hardening guidance, signal that on-premises collaboration and file-sharing infrastructure has become a sustained attacker focus requiring defense-in-depth beyond patching alone.