Skip to content
Auto-CTI

What has changed?

Comparing 21 July 2026 with the previous day 14 July 2026.

Newly added

29
NEW North Korea (state-sponsored), Russia (beneficiary) C3
75

North Korea's IT worker scheme funds Russia's war effort

North Korean IT worker networks directly finance Russia's war effort through sanctions evasion; this demonstrates an operationalized alliance between North Korea and Russia that elevates DACH organizations as potential targets for retaliation or espionage.

Critical

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

24
NEW A2
84

CVE-2026-58233

The vulnerability requires authentication and manual processing of a malicious archive file, which limits attack surface in typical production environments but is relevant for SAP administrators and change-management workflows.

Critical CVSS 7.6 EPSS 0%
NEW A2
67

CVE-2026-44769

The vulnerability requires already-high privileges for exploitation and is limited to confidentiality impact, indicating relatively constrained risk in typical deployment scenarios.

High CVSS 5.5 EPSS 0%
NEW A2
52

CVE-2026-44771

The vulnerability allows restricted authenticated users to access information from other entities and escalate privileges without authorization checks being performed.

Medium CVSS 4.3 EPSS 0%
NEW A3
51

[UPDATE] Microsoft Windows: Multiple Vulnerabilities

BSI warning of multiple critical Windows vulnerabilities with potential for privilege escalation and code execution , the exact CVE portfolio and patch date must be obtained from the official BSI WID entry.

Critical
A3
20

[UPDATE] 7-Zip: Multiple Vulnerabilities

The BSI warning describes multiple 7-Zip vulnerabilities without specific CVE numbers or CVSS scores; further details on exploitability and affected versions are required.

High
NEW A3
20

SAP Patch Day July 2026

The Patch Day aggregates multiple vulnerabilities (RCE, DoS, information disclosure, SQL injection, XSS) with varying impacts and requires prioritized patch management.

High
ESC