Estée Lauder notified the California AG on July 21 that Cl0p exploited Oracle EBS CVE-2025-61882 to steal HR data — names, SSNs, passports, bank accounts, health records — starting August 2025.
Arctic Wolf documented Qilin ransomware deployments through Palo Alto CVE-2026-0257 in June — six weeks after Rapid7 first flagged the auth-bypass exploitation and CISA added the CVE to KEV.
ServiceNow's July 13 patch closes CVE-2026-6875 — a pre-auth sandbox escape in the AI Platform that yields unauthenticated RCE. Defused observed in-the-wild exploitation five days later.
Microsoft's July 14 Patch Tuesday closed CVE-2026-57092 — a CVSS 9.9 use-after-free in the Windows VMSwitch that lets a low-privileged guest reach the Hyper-V host.
Zimbra shipped Daffodil 10.1.20 with a critical command injection in the SNMP monitor, four Classic UI XSS bugs, an SSRF in Nextcloud, and CVE-2026-50055 / CVE-2026-10631 / CVE-2026-50054.
CISA added two critical unauthenticated OS command injection flaws in Fortinet FortiSandbox to KEV on July 16, 2026. BOD 26-04 gave FCEB agencies until July 19 to patch. Both are CVSS 9.1.
Microsoft's DART discovered CVE-2026-56155 during a live intrusion. CISA added it to KEV on July 14. Patch KB 5121391 audits DKM ACLs today, auto-remediates October 13.
WordPress 7.0.2 and 6.9.5 shipped July 17 to close CVE-2026-63030 — a pre-auth RCE in Core built on the CVE-2026-60137 SQL injection. Detection PoC is already public.
Zoom bulletin ZSB-26014 patches CVE-2026-53412, a CVSS 9.8 pre-auth account takeover in Zoom Workplace and the VDI client for Windows. Update to 7.0.0 / 7.0.10 / 6.6.15 / 6.5.18.
CISA added SonicWall SMA1000 zero-days CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 to KEV on July 14, chained by Rapid7 MDR. Federal deadline July 17.
CISA added SharePoint auth-bypass CVE-2026-56164 to KEV on July 14 and re-issued a hardening alert citing three chained on-prem SharePoint CVEs under active exploitation. FCEB deadline July 17.
SonicWall confirms in-the-wild chaining of an unauth SSRF (CVE-2026-15409, CVSS 10.0) and a post-auth command injection (CVE-2026-15410, CVSS 7.2) on SMA1000 6210/7210/8200v. CISA KEV due 2026-07-17.
SAP's July 14 Patch Day ships 16 notes: a NetWeaver ABAP memory-corruption bug at CVSS 9.9, an Approuter request-smuggling flaw and Commerce Cloud default credentials both at 9.1.
CISA added CVE-2026-48939 (iCagenda) and CVE-2026-56291 (Balbooa Forms) to KEV on July 10. Both unauth file-upload to RCE. Patches: iCagenda 4.0.8/3.9.15, Balbooa Forms 2.4.1.
A use-after-free in the Linux kernel's futex priority-inheritance path, present since May 2011, hands root to any local user. Fixed in mainline commit 3bfdc63936dd; distros started shipping July 9.
CERT/CC disclosed CVE-2026-11405 on July 6: five Tenda firmware images ship a plaintext strcmp() backdoor in /bin/httpd. Tenda didn't respond and no patch is available.
Ubiquiti's SAB-066 patches 25 UniFi flaws led by CVE-2026-50746 — an unauthenticated command injection in Connect ≤3.4.16 (CVSS 10.0). Fix ships in Connect 3.4.20.
CISA added CVE-2026-48908 (JoomShaper SP Page Builder) and CVE-2026-56290 (Page Builder CK) to KEV on July 7. Both CVSS 10.0, unauth file-upload to RCE. FCEB deadline: July 10.
Gitea's Docker template shipped REVERSE_PROXY_TRUSTED_PROXIES=* — any client can send X-WEBAUTH-USER: admin and impersonate any account. CVSS 9.8. Patched in 1.26.3, skip to 1.26.4.
Microsoft shipped Malware Protection Engine 1.1.26060.3008 on July 9 to close a race condition in mpengine.dll that hands SYSTEM to any local user. Public PoC has been circulating for a month.
A shadow-MMU use-after-free in KVM/x86 lets a root guest reach into the host on Intel VMX and AMD SVM. Stable kernels shipped the fix on July 4; embargo lifted July 6 with a public PoC.
CISA added the Langflow /api/v1/responses IDOR (CVE-2026-55255, CVSS 9.9) to KEV on July 7. Sysdig first observed exploitation on June 25. Third Langflow flaw to hit KEV in seven months.
KEVIntel logged in-the-wild exploitation of Adobe ColdFusion CVE-2026-48282 within two hours of watchTowr's July 2 technical writeup. Path traversal → RCE, pre-auth, CVSS 10.
Cisco advisory cisco-sa-catc-file-read-wLH2vf8X patches CVE-2026-20191, a CVSS 7.5 pre-auth path traversal in Catalyst Center. Fixed in 3.1.6 GSMU200 and 2.3.7.11-VA GSMU100. No workaround.
A race-condition use-after-free in the Linux kernel epoll subsystem lets an unprivileged process reach root on desktops, servers, and Android. Reported to Google kernelCTF by Jaeyoung Chung.
Seven FatFs bugs disclosed July 1 by runZero — FAT32, exFAT and long-filename paths across ESP-IDF, STM32Cube, Zephyr, MicroPython. Only CVE-2026-6684 has an upstream fix.
Defused honeypots caught in-the-wild exploitation of CVE-2026-46817 (CVSS 9.8) on June 27, six weeks after Oracle's May patch. ~950 EBS instances are internet-exposed.
Citrix's CTX696604 fixes six NetScaler ADC/Gateway CVEs on June 30. CVE-2026-8451, a pre-auth memory overread on the SAML IdP path, echoes CitrixBleed 2. Patch 14.1-72.61 or 13.1-63.18.
CISA added SharePoint RCE CVE-2026-45659 to the KEV catalog on July 1 after confirmed exploitation. Deserialization bug patched OOB May 21; FCEB agencies have three days.
Progress patches an unauth pre-auth command-injection RCE in Kemp LoadMaster. CVSS 9.8. GA 7.2.63.2 and LTSF 7.2.54.18 ship the fix; watchTowr posted the full chain on June 29.
OpenAM 16.1.1 shipped June 17 with fixes for 17 CVEs. Public advisories began June 22 and continued through June 29: pre-auth RADIUS spoof, MSISDN LDAP injection, OAuth2 takeover, Groovy sandbox RCE.
CISA added the SimpleHelp OIDC auth bypass (CVSS 10) to KEV on June 29. ~14,000 servers are internet-exposed; 5.5.16 and 6.0 RC2 shipped the fix on June 9.
Researcher Massimiliano Oldani published a working root exploit (packet_edit_meme) for CVE-2026-46331 one day after the kernel.org CVE landed. Ubuntu 18.04–26.04 vulnerable.
CISA gave federal agencies three days to patch the Bulletin 064 UniFi OS triple — access control bypass, path traversal, command injection — all CVSS 10.0, all exploited.
JFrog published a full local-root exploit for the DirtyFrag-family kernel flaw CVE-2026-43503 on June 25. Patched in v7.1-rc5. Container hosts are the priority.
CISA added the CVSS 9.8 command-injection bug — plus three perfect-10 UniFi OS flaws — to KEV on June 23. BOD 26-04 forces federal patching by June 26.
CISA added the CVSS 10 deserialization RCE in Windchill PDMLink and FlexPLM to KEV on June 25. PTC ships patches, BSI repeats the alarm. Three days to act.
Three weeks after the June 3 patch, Defused honeypots see automated Tor-routed sweeps deploying multi-stage JSP shells via the WebDialer SSRF. Patch alone won't evict them.
Zafran Security discloses four Dify CVEs (41947–41950). Three patched in 1.14.2; the CVSS-9.4 Plugin Daemon path traversal CVE-2026-41948 remains unfixed at release time.
Squid project published SQUID-2026:4 on June 23 — a heap over-read in the FTP gateway that leaks raw memory to a malicious FTP server. Fix in Squid 7.6.
CVE-2026-20253 is a CVSS 9.8 missing-authentication flaw in Splunk Enterprise 10. CISA added it to KEV on June 18 with a three-day patch deadline. WatchTowr published a working RCE exploit.
Node.js v22.23.0, v24.17.0 and v26.3.1 fix 12 CVEs including a TLS wildcard hostname bypass (CVE-2026-48618) and a WebCrypto integer overflow DoS (CVE-2026-48933).
Wordfence blocked 17M attempts at the unauth REST endpoint that dumps Gravity SMTP's full System Report — live API keys and OAuth tokens included. Patch is 2.1.5.
F5 shipped NGINX 1.31.2 and 1.30.3 on June 17 fixing a use-after-free in the HTTP/3 module, a heap overflow in proxy_v2/grpc, and a buffer overread in charset.
Second Cisco Catalyst SD-WAN Manager zero-day in two weeks. CVE-2026-20262 is an arbitrary file write under exploitation; CISA gave agencies until June 29 to patch.
CISA added CVE-2026-48907 to KEV on June 16 — an unauth profile-import chain in the JCE Joomla extension that lets attackers upload and execute PHP. Patch in JCE 2.9.99.5.
Google's June 8 Stable Channel pushes 149.0.7827.102/.103 for an actively exploited V8 out-of-bounds read/write. CISA added the CVE to KEV the next day.
VulnCheck added CVE-2026-5027 to its KEV on June 8 after detecting in-the-wild exploitation. Path traversal in /api/v2/files yields unauth RCE; ~7,000 instances are publicly exposed.
Wordfence's firewall blocked 29,300+ exploit attempts against a CVSS 9.8 PHP-eval RCE in Everest Forms Pro. Sites pre-1.9.13 should hunt for the rogue admin diksimarina.
Oracle ships an out-of-band Security Alert for an unauthenticated RCE in PeopleTools 8.61/8.62. Mandiant ties exploitation since May 27 to ShinyHunters (UNC6240).
Tunnel-decap logic flaw in Arista EOS lets crafted VXLAN/GRE/decap-group packets reach configured decap IPs. Exploited in the wild. Arista will not patch — mitigate with ACLs.
Microsoft's June 9 Patch Tuesday fixes around 200 CVEs and 33 Critical flaws, including publicly disclosed zero-days in BitLocker, HTTP.sys (HTTP/2 Bomb) and CTFMON.
Check Point hotfixes a CVSS 9.3 cert-validation bypass on Remote Access and Mobile Access VPN. Exploitation since May 7, 2026 — one case linked to a Qilin affiliate.
Exodus Intelligence published a complete local root exploit for CVE-2026-23111 — a one-character nf_tables UAF patched upstream Feb 5. Container escape on default distros.
Cisco disclosed a command-injection zero-day in Catalyst SD-WAN Manager on June 5. Mandiant credited as reporter. CVSS 7.8, exploitation observed, no fix available.
CISA added the two-year-old Oracle WebLogic auth-bypass CVE-2024-21182 to KEV on June 1, citing active exploitation. Federal agencies have until June 4 to patch.
Google's June 2026 Android Security Bulletin fixes 124 flaws, including a Framework integer overflow under limited, targeted exploitation. CISA wants federal agencies patched by 5 June.
Calif researchers crash 32 GB of Envoy memory in seconds with one connection. nginx 1.29.8 and Apache mod_http2 2.0.41 are patched; IIS, Envoy and Cloudflare Pingora are not.
Belgium's CCB confirms active exploitation of the CVSS 9.8 Netlogon stack-overflow patched by Microsoft in May. Unauthenticated, no user interaction, domain controller takeover.
Sysdig documents an LLM agent driving post-exploitation after a CVE-2026-39987 Marimo notebook compromise: cloud creds and SSH key pulled in under three minutes.
PAN-OS portals with authentication-override cookies on a shared certificate let attackers forge a valid session. Rapid7 observed exploitation since May 17. Federal patch deadline June 19.
Arctic Wolf says attackers are using the pre-auth FortiClient EMS flaw to push a previously undocumented infostealer disguised as a Fortinet endpoint update.
Mandiant traces a zero-day in Japan's KnowledgeDeliver LMS to ASP.NET machineKey values reused across customers — enabling unauthenticated ViewState RCE and BLUEBEAM web-shell drops.
CISA added CVE-2025-34291 to the KEV catalog on May 21. An overly permissive CORS plus a misconfigured refresh-token cookie chain to account takeover and code execution in Langflow ≤ 1.6.9.
An unauthenticated SQL injection in Ghost's Content API leaks admin API keys. Attackers chain it into stored XSS and a fake Cloudflare ClickFix lure. Upgrade to 6.19.1.
Trend Micro patches a directory-traversal flaw in the Apex One server after observing in-the-wild exploitation. CISA orders federal agencies to remediate by June 4.
An unauthenticated SQL injection in Drupal core's database abstraction API affects every PostgreSQL-backed site. Drupal scored it 23/25. Attacks started two days after the patch dropped.
A privilege-escalation flaw in the LiteSpeed User-End cPanel plugin lets any cPanel account execute arbitrary scripts as root. Mass scanning began within 72 hours of disclosure.