Three Microsoft SharePoint Server vulnerabilities are under active exploitation to gain unauthorized access and deploy malware for persistent access; CISA has issued a hardening alert.
Although this vulnerability requires authorized network access, it enables code execution within a core productivity AI system increasingly integrated into enterprise workflows.
Network-accessible heap overflow in Microsoft Account enables remote code execution without user interaction , priority for immediate patching and network isolation of critical authentication systems.
An authentication vulnerability in Exchange Online could allow attackers to access email accounts or tamper with their contents without legitimate credentials , a critical vector for business disruption and data loss in cloud-based environments.
An authentication vulnerability in Azure DNS allows unauthorized attackers to escalate network privileges, potentially compromising access to cloud-hosted services.
The vulnerability allows authenticated network attackers to execute code in Azure APIM, indicating insufficient access control for API management operations.
An authentication vulnerability in Azure Key Vault enables unauthorized access and privilege escalation over the network, affecting core identity and access control infrastructure.
Western intelligence agencies warn of active Russian hacking campaigns against Zimbra mail servers, indicating the use of cyber operations in the context of geopolitical tensions.
A vulnerability in Microsoft Graph allows authenticated attackers to disclose sensitive information over the network; the CVE is already covered by NVD and vendor security advisories.
Critical
CVSS
6.5
EPSS
0%
NEW Iran-linked APT (Cavern Manticore operators) B3
Cavern Manticore is a modular Iran-controlled C2 framework indicating infrastructure-targeting and distributed attack capabilities threatening Western targets in critical sectors.
Critical
NEW Laundry Bear (Void Blizzard, CL-STA-1114, TA488, UNK_PitStop) C3
Russian intelligence-linked APT group Laundry Bear has been exploiting a zero-day in Zimbra since July 2025 to target email systems in Western government institutions, escalating from basic phishing techniques to sophisticated attacks.
UAC-0099 uses trojaned Notepad++ plugins as a social-engineering vector to deliver MATCHBOIL.V2 malware into Windows environments, with the camouflage pattern presenting significant detection risk for organizations relying on signature-based detection of popular development software.
Large-scale npm supply-chain compromise with injected malware loader exfiltrating environment variables (GitHub tokens, API keys, database credentials) and establishing persistence via Node.js masquerade , immediate threat to all organizations with AsyncAPI dependencies.
A BSI alert on multiple Ubiquiti UniFi OS vulnerabilities indicates elevated risk to network-perimeter security in European manufacturing environments.
The July 2026 patch cycle marks a turning point: 622 vulnerabilities (62 critical, 3 zero-days) demonstrate accelerated vulnerability discovery by AI frontier models; simultaneously, novel malware families (StarLand RAT, WLDR C2, ARToken MFA-bypass) are active in campaigns , combined pressure on Windows/Microsoft 365 environments.
Russian-speaking threat group employing multistage campaign with novel RAT and proprietary PowerShell C2 against European targets since June 2025, using HTA/ClickFix as initial exploitation vector.
BSI warns of multiple unspecified Edge vulnerabilities with variable exploitability , without CVE numbers or patch status, the concrete threat level is unclear and requires Microsoft security advisories for prioritization.
An unauthenticated, remotely exploitable heap buffer overflow in 7-Zip enables code execution during XZ file processing, but requires user interaction to trigger.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud without specific CVE details; exploitation requires user interaction (maliciously crafted files).
The vulnerability enables a sandbox escape from the Chrome renderer process, allowing escalation from renderer compromises to full system control if an attacker can already execute code in the renderer.
A use-after-free vulnerability in the WebMCP component allows attackers to execute arbitrary code within the Chrome sandbox without requiring local privilege escalation.
An out-of-bounds write vulnerability enables potential sandbox escape in Chrome, allowing local code execution with elevated privileges following successful website exploitation.
A use-after-free vulnerability in the Blink engine enables remote code execution within Chrome's sandbox via crafted HTML pages; the vulnerability is already documented in NVD and Chromium security advisories and affects all current Chrome installations.
BSI warning for multiple unspecified vulnerabilities in Chrome/Edge without listing specific CVE IDs or version details; likely a generic aggregate notice for ongoing browser updates.
The BSI warns of multiple undisclosed vulnerabilities in two widely-used enterprise browsers that can be exploited by simply opening a malicious webpage,a high attack surface in daily office use.
The BSI warns of multiple unspecified vulnerabilities in Chrome without publication of CVE details; this suggests coordinated disclosure or embargoed vulnerability information not yet fully released.
Multiple vulnerabilities in 7-Zip enable arbitrary code execution through opening malformed archives; patching is critical given the application's widespread use.
An angry security researcher has publicly disclosed a zero-day exploit enabling local administrator privilege escalation on Windows systems before a patch is available, creating immediate risk for exposed or poorly segmented infrastructure.
The Cursor vulnerability illustrates a fundamental disclosure dilemma: responsible disclosure fails when vendors do not respond promptly, forcing security researchers toward full disclosure as a last resort.
An unauthenticated remote code execution vulnerability in Microsoft SharePoint with CVSS 8.1 was demonstrated at Pwn2Own and requires immediate attention for patch management and network segmentation.
CVE-2026-16232 is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating an immediate threat to affected systems.
Iranian APT group Handala conducting active, disruptive attacks on ICS/PLC devices , updated Federal Advisory (July 2026) includes new detection guidance and indicators of compromise.
UK and international intelligence agencies attribute a new zero-click phishing campaign to Russian state actors, signalling escalated cyber-warfare operations against Western organisations.
Russian state-sponsored APT combines phishing with zero-click exploitation against Zimbra systems,active campaign targeting Western organizations for email theft.
Russian state-sponsored threat group 'Laundry Bear' has been exploiting Zimbra zero-day since July 2025 against Western governments and enterprises using 'half-click' phishing tactics requiring only message preview.
A successful cyberattack against a Swiss train manufacturer with active extortion demonstrates that established industrial companies in the DACH region are targeted by attackers and that extortion tactics are actively being used against critical infrastructure suppliers.
Russian APT group conducts campaign exploiting zero-click vulnerability in Zimbra Collaboration Suite to exfiltrate credentials and email archives from European organizations.
State-backed Russian APT group exploiting zero-click phishing against global webmail infrastructure; international alert underscores cyber-warfare escalation with relevance for Western critical infrastructure and supply-chain security.
CISA warns of active exploitation of another SharePoint security vulnerability (in addition to cases reported in July) and CVE-2026-16232 in Check Point SmartConsole (CVSS 9.1), without disclosing details on attack scope or attacker tactics.
PowerShell vulnerability enables remote code execution with user interaction (visiting malicious page or opening malicious file) , affects Windows Server 2019/2022 deployments.
A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8 upon user interaction (opening a malicious file or link).
RCE vulnerability in Adobe Acrobat Pro DC allows arbitrary code execution through visiting a malicious webpage or opening a manipulated file; immediate patching planning required.
A use-after-free in the Annots.api component enables remote code execution in Adobe Acrobat Pro DC following user interaction with a malicious file or website.
Local attackers can escalate privileges on Windows Server systems after obtaining low-privilege access, enabling internal threats and lateral movement scenarios.
Local attackers can escalate privileges on systems with Adobe Creative Cloud by exploiting an uncontrolled search path element in the AdobeUpdateService process, provided they first achieve low-privileged code execution.
XSS vulnerability in SharePoint SPFieldMultiLineText allows attackers to execute web requests with user privileges; exploitation requires user interaction (visiting a malicious page or opening a malicious file).
Local privilege escalation in Windows WMI requires prior code execution, but enables post-compromise privilege amplification in environments vulnerable to lateral movement or untrusted code execution.
Network-adjacent attackers can execute arbitrary code on Synology DiskStation DS925+ without authentication; vulnerability stems from weak password encryption in MailPlus Redis.
RCE in OpenSSL OCSP stapling verification requires user interaction (request to malicious server), but CVSS 7.5 and potential real-world exploitation make patching a priority.
A nine-year-old race condition in XFS enables local attackers to overwrite files and gain root access; the delayed disclosure suggests prior coordination with vendors.
The BSI warning regarding multiple GNU libc vulnerabilities requires verification of specific CVE numbers and KEV status for prioritizing patches on Ubuntu systems.
msaRAT leverages Chrome and Edge for C2 obfuscation and is actively deployed by the Chaos ransomware gang, potentially evading endpoint security controls.
Chaos group employs novel Rust-based RAT (msaRAT) that exclusively uses Chrome DevTools Protocol for C2 communication, bypassing traditional network-based detection.
BSI advisory on multiple critical vulnerabilities in Firefox and Thunderbird enabling arbitrary code execution, sandbox escapes, and memory corruption.
BSI security advisory alerts to multiple OpenSSL vulnerabilities without naming specific CVE numbers or version details; further information is required to determine affected versions.
BSI warning on multiple Chrome vulnerabilities with potential code execution , exact CVE numbers and CVSS scores not specified, so unclear whether already patched or still actively exploited.
The vulnerability allows locally authenticated users to gain direct root privileges without further interaction and affects Ubuntu standard installations with snap.
A widely deployed Adobe extension was exploited as an attack vector for data exfiltration , not a traditional patch issue but a design/permissions problem with abuse potential.
Microsoft's passkey implementations remain vulnerable to classical attack methods (e.g. phishing, social engineering) despite being marketed as more secure than passwords.
A vulnerability in the Adobe Acrobat extension enables attackers to spy on WhatsApp Web conversations without malware or stolen credentials,a visit to a malicious website is sufficient.
BSI warns of multiple vulnerabilities in Adobe Creative Cloud with severe impacts (privilege escalation, code execution, information disclosure); some require user interaction to exploit.
BSI warns of multiple Chrome vulnerabilities without specific CVE details, suggesting a general patch advisory; organizations should deploy Chrome updates promptly.
Chaos Ransomware uses msaRAT to route command-and-control traffic via browser APIs (Chrome DevTools Protocol) to obfuscate network indicators and evade traditional network detection.
Revoked UEFI bootloaders remain visible in trust lists for years even after revocation, enabling Secure Boot bypasses , a governance oversight with implications for firmware integrity on Windows and Linux servers.
Identity-based attacks have overtaken exploits as the leading cause of ransomware incidents, while MFA deployment alone is no longer sufficient to prevent compromise.
BSI warns of multiple unspecified vulnerabilities in Firefox enabling code execution and security bypass , user interaction via file or link opening required.
7-Zip users must be warned against opening suspicious archives, as the vulnerability requires user interaction with compromised files for exploitation.
Microsoft's disruption of the Tycoon2FA platform resulted in a 92% reduction in associated phishing volume in Q2 2026, but no single service replaced it at comparable scale , threat actors are fragmenting their infrastructure.