LegacyHive drops Windows profsvc zero-day PoC after Patch Tuesday
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
Nightmare Eclipse published LegacyHive on GitHub the same day as Microsoft's July 2026 Patch Tuesday. It's an unpatched profsvc LPE that still works on fully-updated Windows.
CISA added SonicWall SMA1000 zero-days CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 to KEV on July 14, chained by Rapid7 MDR. Federal deadline July 17.
CISA added SharePoint auth-bypass CVE-2026-56164 to KEV on July 14 and re-issued a hardening alert citing three chained on-prem SharePoint CVEs under active exploitation. FCEB deadline July 17.
SonicWall confirms in-the-wild chaining of an unauth SSRF (CVE-2026-15409, CVSS 10.0) and a post-auth command injection (CVE-2026-15410, CVSS 7.2) on SMA1000 6210/7210/8200v. CISA KEV due 2026-07-17.
SAP's July 14 Patch Day ships 16 notes: a NetWeaver ABAP memory-corruption bug at CVSS 9.9, an Approuter request-smuggling flaw and Commerce Cloud default credentials both at 9.1.
EU lists 9 individuals + 4 entities under the cyber regime; UK adds 24 more. FSB Centre 16 designated for the Poland grid attempt; ANSSI ties Turla to FSB unit 61240.
Zimbra shipped Daffodil 10.1.19 on July 7 to fix a stored XSS in the Classic Web Client where a crafted email runs JavaScript in the recipient's mailbox session. Reporter: Google TAG. No CVE assigned.
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
A use-after-free in the Linux kernel's futex priority-inheritance path, present since May 2011, hands root to any local user. Fixed in mainline commit 3bfdc63936dd; distros started shipping July 9.