An unauthenticated remote code execution vulnerability in Microsoft SharePoint with CVSS 8.1 was demonstrated at Pwn2Own and requires immediate attention for patch management and network segmentation.
CVE-2026-16232 is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating an immediate threat to affected systems.
Iranian APT group Handala conducting active, disruptive attacks on ICS/PLC devices , updated Federal Advisory (July 2026) includes new detection guidance and indicators of compromise.
UK and international intelligence agencies attribute a new zero-click phishing campaign to Russian state actors, signalling escalated cyber-warfare operations against Western organisations.
Russian state-sponsored APT combines phishing with zero-click exploitation against Zimbra systems,active campaign targeting Western organizations for email theft.
Russian state-sponsored threat group 'Laundry Bear' has been exploiting Zimbra zero-day since July 2025 against Western governments and enterprises using 'half-click' phishing tactics requiring only message preview.
A successful cyberattack against a Swiss train manufacturer with active extortion demonstrates that established industrial companies in the DACH region are targeted by attackers and that extortion tactics are actively being used against critical infrastructure suppliers.
Russian APT group conducts campaign exploiting zero-click vulnerability in Zimbra Collaboration Suite to exfiltrate credentials and email archives from European organizations.
State-backed Russian APT group exploiting zero-click phishing against global webmail infrastructure; international alert underscores cyber-warfare escalation with relevance for Western critical infrastructure and supply-chain security.
CISA warns of active exploitation of another SharePoint security vulnerability (in addition to cases reported in July) and CVE-2026-16232 in Check Point SmartConsole (CVSS 9.1), without disclosing details on attack scope or attacker tactics.
PowerShell vulnerability enables remote code execution with user interaction (visiting malicious page or opening malicious file) , affects Windows Server 2019/2022 deployments.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8 upon user interaction (opening a malicious file or link).
RCE vulnerability in Adobe Acrobat Pro DC allows arbitrary code execution through visiting a malicious webpage or opening a manipulated file; immediate patching planning required.
A use-after-free in the Annots.api component enables remote code execution in Adobe Acrobat Pro DC following user interaction with a malicious file or website.
Local attackers can escalate privileges on Windows Server systems after obtaining low-privilege access, enabling internal threats and lateral movement scenarios.
Local attackers can escalate privileges on systems with Adobe Creative Cloud by exploiting an uncontrolled search path element in the AdobeUpdateService process, provided they first achieve low-privileged code execution.
XSS vulnerability in SharePoint SPFieldMultiLineText allows attackers to execute web requests with user privileges; exploitation requires user interaction (visiting a malicious page or opening a malicious file).
Local privilege escalation in Windows WMI requires prior code execution, but enables post-compromise privilege amplification in environments vulnerable to lateral movement or untrusted code execution.
Network-adjacent attackers can execute arbitrary code on Synology DiskStation DS925+ without authentication; vulnerability stems from weak password encryption in MailPlus Redis.
RCE in OpenSSL OCSP stapling verification requires user interaction (request to malicious server), but CVSS 7.5 and potential real-world exploitation make patching a priority.
A nine-year-old race condition in XFS enables local attackers to overwrite files and gain root access; the delayed disclosure suggests prior coordination with vendors.
The BSI warning regarding multiple GNU libc vulnerabilities requires verification of specific CVE numbers and KEV status for prioritizing patches on Ubuntu systems.
msaRAT leverages Chrome and Edge for C2 obfuscation and is actively deployed by the Chaos ransomware gang, potentially evading endpoint security controls.
Chaos group employs novel Rust-based RAT (msaRAT) that exclusively uses Chrome DevTools Protocol for C2 communication, bypassing traditional network-based detection.
BSI advisory on multiple critical vulnerabilities in Firefox and Thunderbird enabling arbitrary code execution, sandbox escapes, and memory corruption.
BSI security advisory alerts to multiple OpenSSL vulnerabilities without naming specific CVE numbers or version details; further information is required to determine affected versions.
BSI warning on multiple Chrome vulnerabilities with potential code execution , exact CVE numbers and CVSS scores not specified, so unclear whether already patched or still actively exploited.
The vulnerability allows locally authenticated users to gain direct root privileges without further interaction and affects Ubuntu standard installations with snap.
A widely deployed Adobe extension was exploited as an attack vector for data exfiltration , not a traditional patch issue but a design/permissions problem with abuse potential.
Microsoft's passkey implementations remain vulnerable to classical attack methods (e.g. phishing, social engineering) despite being marketed as more secure than passwords.
A vulnerability in the Adobe Acrobat extension enables attackers to spy on WhatsApp Web conversations without malware or stolen credentials,a visit to a malicious website is sufficient.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud with severe impacts (privilege escalation, code execution, information disclosure); some require user interaction to exploit.
BSI warns of multiple Chrome vulnerabilities without specific CVE details, suggesting a general patch advisory; organizations should deploy Chrome updates promptly.
Chaos Ransomware uses msaRAT to route command-and-control traffic via browser APIs (Chrome DevTools Protocol) to obfuscate network indicators and evade traditional network detection.
Revoked UEFI bootloaders remain visible in trust lists for years even after revocation, enabling Secure Boot bypasses , a governance oversight with implications for firmware integrity on Windows and Linux servers.
Identity-based attacks have overtaken exploits as the leading cause of ransomware incidents, while MFA deployment alone is no longer sufficient to prevent compromise.
BSI warns of multiple unspecified vulnerabilities in Firefox enabling code execution and security bypass , user interaction via file or link opening required.
7-Zip users must be warned against opening suspicious archives, as the vulnerability requires user interaction with compromised files for exploitation.
Microsoft's disruption of the Tycoon2FA platform resulted in a 92% reduction in associated phishing volume in Q2 2026, but no single service replaced it at comparable scale , threat actors are fragmenting their infrastructure.
The vulnerability enables remote code execution through unsafe deserialization and is already listed on the CISA KEV catalog, indicating active exploitation; BOD 26-04 compliance is mandated.
The patch release includes 56 critical vulnerabilities in Windows Server and Office products, including remote code execution flaws in Dynamics NAV and a BitLocker bypass with public exploit.
This is a monthly patch summary with no indication of active exploitation or geopolitical significance; purely routine vulnerability management information.
CVE-2026-50522 is being actively exploited in attack campaigns to steal machine keys and establish persistent access; this is the fourth SharePoint vulnerability exploited in this month.
The vulnerability allows malicious websites to access WhatsApp Web data through inadequate access controls in the Adobe Acrobat browser extension,an attack that can occur silently and affects hundreds of millions of users.
A vulnerability already patched by Oracle is catalogued here as a new CVE with a future date (2026), with no evidence of active exploitation or novel attack patterns.
First joint UK-EU sanctions against Russian cyber and disinformation actors underscore escalation of state-APT activity in Europe and growing geopolitical dimension of cyber threats to DACH regions.
Russian state-sponsored actors are conducting targeted attacks against routers to gain access to critical infrastructure and industrial networks , a direct threat to European manufacturing facilities operating network perimeter devices.
Kaspersky research shows that attackers continue to exploit years-old vulnerabilities such as EternalBlue (MS17-010 from 2017) to compromise networks, underscoring that patch-management gaps remain a strategic risk for enterprise infrastructure.
Iranian threat actors are conducting escalating attacks against operational technology systems, particularly targeting HMI and SCADA displays in manufacturing facilities,a direct scenario for European manufacturers in geopolitically sensitive sectors.
The vulnerability enables unauthenticated network-based DoS attacks but impacts only availability (no data compromise) and is a standard Oracle patching cycle release.
Rapid7 disclosed a chained exploit combining authentication bypass (CVE-2026-55040) with a separate RCE vulnerability; unauthenticated attackers can achieve remote code execution on SharePoint servers , patching the authentication bypass breaks the exploit chain.
AI-aided vulnerability discovery drives record patch numbers; meanwhile, tests show that automated exploit generation is rendering Microsoft's exploitability rating obsolete.
BSI advisory confirms critical and zero-day vulnerabilities in SharePoint without further technical details; patch status and affected versions should be immediately verified via Microsoft channels.
The vulnerability enables unauthorized VPN access without authentication and is already being actively exploited in the field , an immediate risk for manufacturing networks and critical infrastructure.
The BSI warning covers multiple critical UniFi vulnerabilities without specifying CVE numbers or proof-of-concept status , organizations should immediately monitor Ubiquiti security advisories for affected versions and patches.
ARToken reveals a sophisticated PhaaS infrastructure with 80+ API endpoints for PRT persistence, device code phishing, and SharePoint exfiltration , an actively exploited ecosystem for large-scale compromise of Microsoft 365 environments.
The vulnerability enables a sandbox escape following prior compromise of the renderer process, requiring chaining with browser RCE exploits for complete system takeover.
A heap buffer overflow in the V8 engine enables remote code execution within the Chrome sandbox; patching to version 150.0.7871.182 or later is required.
This is an isolated and timely security vulnerability with no signs of active exploitation in the wild, but requires immediate updating to Chrome 150.0.7871.182 or later.
Local privilege escalation in Veeam Updater allows unauthenticated local users root-level access to the appliance operating system , critical for backup infrastructure with direct access.
The campaign leverages 7,600 legitimate GitHub repositories as a distribution channel for infostealers and downloader malware, affecting both developers and end-users while undermining trust in open-source platforms.
BSI warns of multiple Chrome vulnerabilities without detailed CVE disclosure; details are not yet public, but patching should be prioritized as code execution is possible.
BSI alerts to multiple vulnerabilities in UniFi OS Server without specific CVE identifiers; concrete patch status and update availability are currently undocumented.
The vulnerability allows local attackers to gain root access to the system via the Veeam Updater component; a patch (version 12.3.0.65) is already available.
The Kratos phishing platform (also known as SneakyLog) was dismantled by German and US authorities after running approximately 15,000 phishing campaigns monthly and stealing session cookies to bypass 2FA.
BSI has documented multiple critical vulnerabilities in Aruba AOS-CX switches that allow security bypass and arbitrary code execution , relevant to network segmentation and access control in production environments.
A local privilege escalation vulnerability in Veeam Backup & Replication requires immediate attention as it can be exploited by attackers with local system access to compromise the system.
BSI advisory on multiple Firefox vulnerabilities without specific CVE numbers; practical patches should be sourced from Mozilla release notes or security updates.
BSI advisory on multiple Chrome vulnerabilities without specific CVE numbers; exploitation may require user interaction (e.g., visiting a malicious website).
A remote code execution vulnerability in 7-Zip affecting NTFS archive processing requires user interaction for exploitation and poses immediate risk to all installations.
The vulnerabilities remain undisclosed at publication time, indicating an active coordinated disclosure process; technical details and exploitability status remain unclear.
North Korean Kimsuky APT distributes ScreenConnect as counterfeit freeware installers (OBS Studio, DS4Windows, Glary Utilities) to gain enterprise network access; linked to AppleSeed malware and new PebbleDash-based tools.
After October, Exchange 2016 and 2019 will no longer receive security updates , organisations running these versions must evaluate migration or Extended Security Update (ESU) licensing to maintain compliance and security.
A previously unlisted heap-overflow vulnerability in the WinRAR RAR5 parser enables remote code execution through specially crafted archives and requires user interaction.
Without specific CVE numbers, affected product versions, or indications of active exploitation, this is a generic patch announcement with no strategic added value.
Microsoft is making passkeys the default authentication method in Entra ID starting September 2026 to increase phishing resistance and reduce reliance on SMS and voice-based factors.
The BSI advisory warns of multiple Firefox vulnerabilities without specific CVE numbers or exploit details, suggesting a generic security notice, possibly as part of regular updates or patch roundup.
BSI warns of multiple Linux kernel vulnerabilities without specific CVE identifiers or exploitation status,detailed technical analysis is required to assess impact and urgency.