Microsoft Dynamics NAV/365 Business Central remote code execution vulnerability with CVSS 9.8. Requires no authentication or user interaction, allowing unauthenticated attackers to execute arbitrary code on vulnerable Business Central servers.
Apply July 2026 Patch Tuesday updates immediately. Restrict network access to Dynamics deployments using firewall rules and VPN. Implement application-layer security controls and monitor for unauthorized authentication attempts.
Source: MSRC • Published: 2026-07-15
Critical authentication bypass in Microsoft SharePoint discovered by Rapid7. First in a pair of exploits which, when chained together, can lead to unauthenticated remote code execution against vulnerable SharePoint servers.
Apply Microsoft patches immediately. Implement multi-factor authentication for all SharePoint access. Segment SharePoint servers from internet-facing perimeter and deploy web application firewalls with SharePoint-specific rulesets.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft SharePoint. Part of heavy concentration of critical SharePoint fixes in July 2026 Patch Tuesday addressing multiple RCE vectors in SharePoint Server deployments.
Apply July 2026 security updates immediately. Review SharePoint farm security configurations and disable unnecessary web services. Implement network-based detection for SharePoint exploitation attempts and suspicious PowerShell activity.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft SharePoint. Second major RCE flaw patched in July 2026 affecting SharePoint Server, enabling attackers to execute arbitrary code on vulnerable servers.
Apply Microsoft security updates immediately. Harden SharePoint servers by disabling unnecessary features and implementing least-privilege access. Deploy endpoint detection and response (EDR) on SharePoint hosts to detect post-exploitation activity.
Source: MSRC • Published: 2026-07-15
Microsoft Exchange Server spoofing vulnerability with CVSS 9.6, actually a stored cross-site scripting flaw in Outlook Web Access. Attacker sends specially crafted email; when victim opens it in OWA, arbitrary JavaScript executes with scope-changed impact breaking out of web app context entirely.
Apply July 2026 Patch Tuesday updates immediately. Implement Content Security Policy (CSP) headers on OWA. Deploy email security gateways to filter malicious emails before delivery and educate users on phishing indicators.
Source: MSRC • Published: 2026-07-15
Remote Desktop Protocol remote code execution vulnerability. Unauthenticated, network-reachable, no user interaction required. Root cause is use of uninitialized resource (CWE-908); specially crafted RDP traffic can interact with uninitialized memory, enabling memory corruption and code execution.
Apply Microsoft patches immediately. Audit systems to identify internet-accessible RDP servers and place behind VPN or zero-trust network access. Enable Network Level Authentication (NLA) and implement IP allowlisting for RDP access.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Windows DHCP Client. Complements multiple critical RCE vulnerabilities affecting Windows DHCP Server infrastructure patched in July 2026.
Apply July 2026 Patch Tuesday updates on all Windows clients. Implement DHCP snooping on network switches. Deploy network segmentation to limit DHCP traffic scope and monitor for rogue DHCP servers.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft SQL Server. One of two critical RCE flaws patched in July 2026 affecting SQL Server deployments alongside several elevation of privilege and information disclosure issues.
Apply Microsoft SQL Server security updates immediately. Ensure SQL Server instances are not internet-accessible. Implement least-privilege database access, disable xp_cmdshell, and monitor for suspicious stored procedure execution.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft SQL Server. Second major RCE flaw affecting SQL Server infrastructure patched in July 2026 Patch Tuesday release.
Apply security updates immediately. Review SQL Server surface area configuration and disable unnecessary features. Implement database activity monitoring and deploy transparent data encryption (TDE) for data-at-rest protection.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Windows Media Foundation. One of four critical RCE vulnerabilities affecting Windows Media Foundation patched in July 2026 Patch Tuesday.
Apply Microsoft patches immediately. Restrict execution of untrusted media files. Deploy application control policies blocking unsigned codec execution and implement endpoint detection monitoring media processing anomalies.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Windows Media Foundation. Second of four critical RCE flaws affecting Windows Media Foundation infrastructure patched in July 2026.
Apply July 2026 security updates immediately. Disable unnecessary media codecs and filters. Implement sandboxing for media processing applications and monitor for codec exploitation attempts.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Windows Media Foundation. Third of four critical RCE vulnerabilities affecting media processing infrastructure in Windows.
Apply Microsoft security patches immediately. Implement user awareness training on safe media file handling. Deploy sandboxed media viewers and restrict codec installation to administrative users only.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Windows Media Foundation. Fourth of four critical RCE flaws patched in July 2026 affecting Windows media processing capabilities.
Apply July 2026 Patch Tuesday updates immediately. Review and minimize installed media codecs. Implement application allowlisting for media applications and deploy behavior-based detection for media exploitation.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft Word. Document-based attack vector that should be prioritized wherever Office is broadly deployed to end users.
Apply Microsoft Office security updates immediately. Enable Protected View for documents from untrusted sources. Implement Office macro blocking policies and deploy email security solutions scanning Office documents for malicious content.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft Word. Second major RCE flaw in Word patched in July 2026, targeting document-based attack vectors.
Apply July 2026 Office patches immediately. Configure Office to open documents in read-only mode by default. Deploy sandboxed Office document viewers and monitor for suspicious Word process behavior.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft Word. Third critical RCE vulnerability affecting Word in July 2026 Patch Tuesday release.
Apply Microsoft security updates immediately. Disable legacy Office file format support where not required. Implement application control preventing Office from launching child processes and educate users on document-based threats.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft PowerPoint. Document-based attack vector affecting PowerPoint presentations with potential for code execution upon opening malicious files.
Apply July 2026 Office security updates immediately. Enable Protected View for PowerPoint files from internet sources. Deploy email attachment filtering blocking suspicious PowerPoint files and restrict PowerPoint macro execution.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft PowerPoint. Second major RCE flaw affecting PowerPoint in July 2026 Patch Tuesday.
Apply Microsoft patches immediately. Review PowerPoint security settings and disable unnecessary add-ins. Implement file reputation services scanning PowerPoint files before user access.
Source: MSRC • Published: 2026-07-15
Critical remote code execution vulnerability in Microsoft PowerPoint. Third critical RCE vulnerability affecting PowerPoint presentations patched in July 2026.
Apply July 2026 security updates immediately. Convert PowerPoint files to PDF for viewing when editing not required. Deploy sandboxed PowerPoint viewers and monitor Office processes for injection attempts.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Part of extensive RCE cluster affecting multiple Office components with document-based attack vectors.
Apply Microsoft Office security updates immediately across all deployments. Implement Office 365 Advanced Threat Protection for cloud-based deployments. Enable Attack Surface Reduction (ASR) rules blocking Office exploits.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Part of critical RCE cluster affecting Office suite with potential for widespread exploitation.
Apply July 2026 patches immediately. Review Office Trust Center settings and restrict trusted locations. Deploy behavior-based detection monitoring Office applications for exploit indicators.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability affecting multiple Office components. Part of extensive RCE cluster requiring immediate patching.
Apply Microsoft security updates immediately. Disable Office macros organization-wide unless specifically required. Implement application allowlisting for Office add-ins and extensions.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Part of July 2026 critical RCE cluster affecting Office suite deployments.
Apply July 2026 Office patches immediately. Configure Office to block content execution from internet zone. Deploy email security solutions with Office document detonation capabilities.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability affecting Microsoft Office suite. Part of extensive critical RCE cluster in July 2026 Patch Tuesday.
Apply Microsoft security updates immediately. Implement Office document isolation through Windows Defender Application Guard. Monitor Office process trees for suspicious child process spawning.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Part of critical RCE cluster requiring immediate patching across Office deployments.
Apply July 2026 patches immediately. Enable Office telemetry to detect exploitation attempts. Deploy endpoint detection and response (EDR) with Office-specific detection rules.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability affecting Microsoft Office suite. Part of extensive July 2026 critical RCE cluster.
Apply Microsoft Office security updates immediately. Review and minimize Office add-in installations. Implement network segmentation isolating Office client systems from critical infrastructure.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Part of critical RCE cluster affecting Office suite in July 2026 Patch Tuesday.
Apply July 2026 security updates immediately. Implement user awareness training on Office-based threats. Deploy sandboxed Office environments for opening untrusted documents.
Source: MSRC • Published: 2026-07-15
Critical Office-wide remote code execution vulnerability. Final vulnerability in extensive critical RCE cluster affecting Office suite in July 2026.
Apply Microsoft patches immediately. Review Office security baseline configurations. Implement defense-in-depth controls including network monitoring for Office-related exploit traffic.
Source: MSRC • Published: 2026-07-15
Incorrect authorization vulnerability in Adobe Campaign Classic with CVSS 10.0. Affects ACC v7: 7.4.3 build 9396 and earlier on Windows and Linux. Enables arbitrary code execution on on-premise and hybrid Campaign instances.
Upgrade Adobe Campaign Classic to ACC v7: 7.4.3 build 9397 immediately. Review Campaign instance access controls and authentication mechanisms. Implement network isolation for Campaign infrastructure and monitor for unauthorized code execution.
Source: Adobe • Published: 2026-07-15
Memory corruption vulnerability in SAP NetWeaver Application Server ABAP memory management with CVSS 9.9. Authenticated attacker exploitation can lead to unauthorized data access, modification, or system unavailability.
Apply SAP Security Note #3747367 immediately. As temporary workaround, disable all ICF nodes with specific property in transaction SICF. Review SAP memory management configurations and implement monitoring for memory corruption indicators.
Source: SAP • Published: 2026-07-14
HTTP request smuggling vulnerability in SAP Approuter node.js package with CVSS 9.1. Affects versions earlier than 20.10.0. Attackers can abuse request handling differences to interfere with traffic flow and bypass security controls.
Update SAP Approuter to version 20.10.0 or later immediately. Review Approuter configurations for request normalization settings. Deploy web application firewall detecting HTTP request smuggling attempts.
Source: SAP • Published: 2026-07-14
Insecure sample credentials vulnerability in SAP Commerce Cloud with CVSS 9.1. Affects HY_COM 2205, COM_CLOUD 2211, and 2211-JDK21. Default or sample credentials provide immediate entry point when exposed services are improperly configured.
Remove all sample credentials from SAP Commerce Cloud immediately. Implement strong authentication with credential rotation policies. Audit all Commerce Cloud instances for default credentials and deploy privileged access management.
Source: SAP • Published: 2026-07-14
Path traversal vulnerability in Langflow file-upload endpoint with CVSS 8.8. Filename parameter written to disk without sanitization, enabling path traversal to drop files anywhere on host. Can lead to remote code execution via cron entry. Roughly 7,000 Langflow instances exposed on internet, majority in North America.
Update Langflow to patched version immediately. Implement strict filename validation blocking path traversal sequences. Disable or authenticate file-upload endpoints. Monitor /etc/cron.d for unauthorized entries and review Langflow access logs for exploitation attempts.
Source: VulnCheck • Published: 2026-06-08
Symlink vulnerability pattern dubbed 'GhostApproval' affecting six popular AI coding assistants. Booby-trapped code project can quietly take control of developer's computer. Assistant asks permission to edit harmless-looking file, but write lands on sensitive file via symlink manipulation.
Update affected AI coding assistants to patched versions. Implement symlink validation before file operations. Restrict AI assistant file system access to project directories only. Monitor for suspicious symlink creation in development environments.
Source: Wiz • Published: 2026-07-08
First documented AI-run ransomware attack (JadePuffer) where AI agent handled technical execution from start to finish. Agent exploited Langflow vulnerability, moved through network, encrypted 1,300+ MySQL configuration records, wrote custom ransom note, and provided Bitcoin payment address. Represents unprecedented autonomous AI-driven cyber attack capability.
Patch Langflow vulnerabilities immediately (CVE-2026-33017, CVE-2026-55255, CVE-2026-5027). Implement AI agent detection and behavioral analysis. Segment networks to limit lateral movement. Deploy database activity monitoring and encryption detection. Maintain offline backups inaccessible to AI agents.
Source: GTIG • Published: 2026-07-15
2026 benchmark for adversary breakout time is 72 minutes from initial foothold to active exfiltration. Represents fourfold reduction from prior-year averages. Defenders operating on detection pipelines calibrated for longer dwell times already behind. Driven by AI-accelerated attack tools and techniques.
Compress detection and response timelines to sub-60-minute windows. Implement real-time behavioral analytics and automated response playbooks. Deploy deception technology for early attacker detection. Reduce lateral movement opportunities through zero-trust architecture and micro-segmentation.
Source: GTIG • Published: 2026-07-15
Microsoft July 2026 Patch Tuesday is largest in company history, patching 569 CVEs including 56 critical vulnerabilities and three zero-days (two actively exploited). Year-to-date total already exceeds every full-year total in last two decades. Driven by Microsoft's multi-model agentic scanning system (MDASH) accelerating vulnerability discovery.
Prioritize patching actively exploited zero-days CVE-2026-56155 and CVE-2026-56164 immediately. Conduct risk-based prioritization for remaining 567 CVEs based on asset criticality and exploit likelihood. Accelerate patch testing and deployment cycles to match compressed exploitation windows.
Source: MSRC • Published: 2026-07-15
Adobe transitions from monthly to twice-monthly security bulletin publication (second and fourth Tuesday) starting July 14, 2026. Direct result of accelerated vulnerability discovery using AI models. Adobe CSO states frontier AI capabilities available to attackers compress window between disclosure and exploitation from days to hours.
Adjust patch management cycles to accommodate Adobe's bimonthly release schedule. Implement continuous monitoring for Adobe security advisories. Accelerate patch deployment timelines given compressed exploitation windows. Consider implementing virtual patching for critical Adobe products during testing periods.
Source: Adobe • Published: 2026-07-14
GitHub ships /security-review command to Copilot desktop app, making AI-driven pre-commit vulnerability scanning available to all Copilot subscribers including Free tier. Timing aligns with Veracode research finding 45% of AI-generated code introduces at least one OWASP vulnerability across 100+ LLM models tested.
Enable and mandate /security-review command usage before code commits. Integrate Copilot security scanning into CI/CD pipelines. Supplement with additional SAST/DAST tools as defense-in-depth. Train developers on interpreting and remediating Copilot security findings.
Source: GitHub • Published: 2026-07-14
CVE-2026-55944: Microsoft Dynamics NAV/365 Business Central remote code execution vulnerability with CVSS 9.8. Requires no authentication or user interaction, allowing unauthenticated attackers to execute arbitrary code on vulnerable Business Central servers.