Weekly dossier · 2026-W30
Joel Traber AG
20.07.2026 – 26.07.2026
Strategic overview
CRITICALElevated threat activity this week. Please check the technical report for details.
- Alerts
- 192
- CVEs
- 106
- KEV
- 8
- Critical
- 62
Top news
- TAKTISCH The Hacker NewsQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Qilin actors are deliberately exploiting an authentication bypass vulnerability as an entry point into production environments,an indicator of ransomware campaigns targeting the industrial sector.
→ Qilin ransomware campaign actively exploits PAN-OS authentication bypass; Palo Alto Networks equipment is not in the stated tech stack, but the attack pattern and initial access technique are relevant to manufacturing sector security posture.
- TAKTISCH The Hacker NewsAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data
The vulnerability allows malicious websites to access WhatsApp Web data through inadequate access controls in the Adobe Acrobat browser extension,an attack that can occur silently and affects hundreds of millions of users.
→ Adobe Acrobat is widely deployed in manufacturing organizations for document handling; the extension flaw affects a commonly-used Chrome extension with 314M users, though WhatsApp Web access is not typically business-critical for this company's operations.
- TAKTISCH ZDI: Published AdvisoriesZDI-26-349: Adobe Acrobat Pro DC Annots.api Use-After-Free Remote Code Execution Vulnerability
A use-after-free in the Annots.api component enables remote code execution in Adobe Acrobat Pro DC following user interaction with a malicious file or website.
→ Adobe Acrobat Pro DC is deployed in the company's tech stack; this RCE vulnerability in Annots.api with CVSS 7.8 requires user interaction but poses direct operational risk.
- TAKTISCH ZDI: Published AdvisoriesZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Local attackers can escalate privileges on systems with Adobe Creative Cloud by exploiting an uncontrolled search path element in the AdobeUpdateService process, provided they first achieve low-privileged code execution.
→ Adobe Creative Cloud (Photoshop, Creative Cloud suite) is directly used in the company's tech stack; local privilege escalation in AdobeUpdateService poses a risk to workstations where these applications are installed.
- TAKTISCH SecurityWeekNew Check Point Zero-Day Vulnerability Exploited in the Wild
CVE-2026-16232 is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating an immediate threat to affected systems.
→ Check Point is not directly in the company's technology stack, but the vulnerability could be indirectly relevant through network security infrastructure or partners; active exploitation in the wild is an indicator for heightened attention.
- TAKTISCH ZDI: Published AdvisoriesZDI-26-413: (Pwn2Own) Microsoft SharePoint Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
An unauthenticated remote code execution vulnerability in Microsoft SharePoint with CVSS 8.1 was demonstrated at Pwn2Own and requires immediate attention for patch management and network segmentation.
→ Microsoft SharePoint is part of the company's Microsoft 365 stack and is directly listed in its technology stack; a remote code execution vulnerability requiring no authentication represents a critical operational risk.
- TAKTISCH ZDI: Published AdvisoriesZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability
A local privilege escalation flaw in Windows WMI allows local attackers to escalate from low-privilege to SYSTEM-level access; affects Windows Server 2022/2019 and all AD-joined clients in hybrid DACH infrastructure.
→ Local privilege escalation in Microsoft Windows WMI affects Windows Server 2022 and 2019 systems in the company's infrastructure, requiring patching across domain-joined endpoints and servers.
- TAKTISCH SecurityWeekFourth SharePoint Vulnerability Exploited in Past Month's Wave of Attacks
CVE-2026-50522 is being actively exploited in attack campaigns to steal machine keys and establish persistent access; this is the fourth SharePoint vulnerability exploited in this month.
→ CVE-2026-50522 affects Microsoft SharePoint, which is part of the company's Microsoft 365 stack and used for document collaboration and storage; active exploitation for machine key theft and persistence poses direct operational risk.
- TAKTISCH BleepingComputerCritical SharePoint RCE flaw exploited to steal machine keys
The vulnerability is actively exploited to steal machine keys, indicating targeted, ongoing attacks in the wild.
→ Microsoft SharePoint with critical RCE vulnerability is directly in company tech stack (Microsoft 365); active exploitation reported.
- TAKTISCH BleepingComputerCritical wp2shell WordPress flaws exploited to install webshells
The alert describes active in-the-wild exploitation (webshell installation, persistent infection) rather than patch availability alone,critical for security of internet-facing WordPress instances.
→ WordPress is not explicitly listed in the company tech stack, but manufacturing organizations increasingly use web-facing WordPress sites for marketing, documentation, or customer portals; active exploitation of critical flaws poses direct risk to internet-facing infrastructure.
- TAKTISCH The Hacker NewsCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
CVE-2026-50522 is already under active exploitation and is the third SharePoint vulnerability in July 2026 to come under attack immediately after disclosure; prior variants were weaponized as zero-days before patching.
→ CVE-2026-50522 is a critical SharePoint Server RCE vulnerability under active exploitation; the company uses Microsoft 365 and SharePoint, making this directly relevant for immediate patching.
- TAKTISCH The Hacker NewsUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
A locally triggered privilege escalation in snap-confine allows unprivileged local users to obtain root access on default desktop installations.
→ Ubuntu 24.04 LTS is part of the company's tech stack; local privilege escalation in snap-confine on default desktop installs is operationally relevant for endpoint security, though impact depends on snap usage and desktop deployment patterns.
- OPERATIV ZDI: Published AdvisoriesZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability
XSS vulnerability in SharePoint SPFieldMultiLineText allows attackers to execute web requests with user privileges; exploitation requires user interaction (visiting a malicious page or opening a malicious file).
→ Microsoft SharePoint is part of the established tech stack and is used for document management and collaboration; an XSS vulnerability in SPFieldMultiLineText directly affects the security of this platform.
- TAKTISCH ZDI: Published AdvisoriesZDI-26-423: Synology DiskStation DS925+ MailPlus Redis Weak Cryptography for Passwords Remote Code Execution Vulnerability
Network-adjacent attackers can execute arbitrary code on Synology DiskStation DS925+ without authentication; vulnerability stems from weak password encryption in MailPlus Redis.
→ Synology DiskStation DS925+ devices with MailPlus Redis are in the company's tech stack (Synology DSM); critical RCE vulnerability with CVSS 8.8 requiring no authentication directly affects NAS infrastructure.
- TAKTISCH BlogJuly 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
This is a Patch Tuesday roundup covering 622 vulnerabilities including two zero-days; no substantive strategic intelligence beyond the patch summary.
→ Microsoft Patch Tuesday covers critical vulnerabilities in Office and other products directly used in the company's tech stack; two zero-days being patched warrant immediate attention for patch management.
- OPERATIV Zero Day Initiative - BlogCVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
A critical, unauthenticated RCE vulnerability in HTTP.sys enables attackers to execute kernel-level code or trigger denial-of-service conditions by sending crafted HTTP packets to affected servers.
→ CVE-2026-47291 is a critical remote code execution vulnerability in Windows HTTP.sys affecting Microsoft IIS, directly relevant to the company's Windows Server 2022 and 2019 infrastructure.
Research Deep Dives
View all →- BLOG 23/07/2026July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days
In July 2026, Microsoft patched a record 622 vulnerabilities, including two exploited zero-days. This is roughly triple the number from June and nearly five times May's total. The exploited flaws allow privilege escalation in Active Directory Federation Services and SharePoint, with one enabling remote unauthenticated attacks. Immediate patching is strongly recommended for all affected systems.
- ZERO DAY INITIATIVE - BLOG 10/07/2026CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
A vulnerability (CVE-2026-47291) has been discovered in Microsoft Windows HTTP.sys, a kernel-mode HTTP protocol component, allowing remote code execution. An unauthenticated attacker can trigger an integer overflow condition by sending crafted HTTP packets during the parsing of HTTP/1.x headers. This can lead to a denial-of-service state or, worst case, the execution of code with kernel privileges. The flaw particularly affects systems using Internet Information Services (IIS) or other applications that rely on HTTP.sys.
- TENABLE BLOG 14/07/2026Microsoft's July 2026 Patch Tuesday Addresses 569 CVEs (CVE-2026-56155, CVE-2026-56164)
In July 2026, Microsoft released its largest-ever Patch Tuesday update, addressing 569 vulnerabilities, including 56 critical flaws. Of particular concern are three zero-day vulnerabilities, two of which were exploited in the wild. The vulnerabilities span a wide range of products, such as Windows, Office, Exchange, and SQL Server. Organizations, especially in the manufacturing sector like Joel Traber AG, should apply patches immediately to mitigate risks.
Top vendors
- Microsoft 61
- Google 25
- Adobe 22
- Mozilla 8
- Linux 8
- 7-Zip 6
Top CVEs
- CVE-2026-0257 Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access 7.8
- CVE-2026-63030 Critical wp2shell WordPress flaws exploited to install webshells 9.8
- CVE-2026-56191 CVE-2026-56191: Improper Authentication in Microsoft Exchange Online Allows Network Tampering 10.0
- CVE-2026-58275 CVE-2026-58275 10.0
- CVE-2026-50517 CVE-2026-50517: Deserialization of Untrusted Data in M365 Copilot Allows Code Execution 9.9
- CVE-2026-50522 Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC 9.8