Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 22, 2026 - July 22, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Wednesday, July 22, 2026 +117% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-60137 — WordPress Core WP_Query

SQL injection vulnerability in WordPress Core WP_Query when plugins or themes pass untrusted input to parameters. Chains with CVE-2026-63030 to enable unauthenticated RCE on default WordPress installations.

REMEDIATION

Update to WordPress 7.0.2, 6.9.5, or 6.8.6 immediately. Audit plugins and themes for unsafe WP_Query parameter handling. Review database access logs for injection attempts.

Source: Web  •  Published: 2026-07-17

[CRITICAL]

ORACLE-CPU-2026-Q3 — Oracle Product Suite (32 product families)

Largest Oracle Critical Patch Update ever with 1,235 unique CVEs across 1,449 security updates. Includes 261 critical patches across 228 CVEs. Oracle Database Products received 15 patches, 6 remotely exploitable without authentication.

REMEDIATION

Review Oracle July 2026 CPU documentation immediately. Apply patches to all Oracle products prioritizing the 261 critical-severity updates. Test in non-production first but expedite deployment.

Source: Web  •  Published: 2026-07-22

[CRITICAL]

CVE-2026-47865 — VMware Avi Load Balancer (all versions)

Critical authentication bypass vulnerability (CVSS 9.8) allowing unauthenticated network-adjacent attacker to bypass authentication entirely and gain full access to Avi Control Plane. Part of seven-vulnerability disclosure spanning authentication, RCE, and privilege escalation.

REMEDIATION

Apply VMware Avi Load Balancer patches immediately to fixed versions across all affected release branches (22.1.x through 32.1.x). Prioritize internet-facing deployments. Review access logs for unauthorized Control Plane access.

Source: Web  •  Published: 2026-07-14

[CRITICAL]

CVE-2026-47867 — VMware Avi Load Balancer Control Plane

Critical RCE vulnerability in VMware Avi Load Balancer Control Plane enabling remote code execution. Combined with CVE-2026-47865 authentication bypass, provides path from unauthenticated network access to full system compromise.

REMEDIATION

Apply VMware Avi patches immediately across all versions. Segment Control Plane from untrusted networks. Monitor for unusual command execution patterns.

Source: Web  •  Published: 2026-07-14

[CRITICAL]

CVE-2026-47869 — VMware Avi Load Balancer Control Plane

Critical RCE vulnerability in VMware Avi Load Balancer Control Plane. Second RCE vector enabling remote code execution on compromised Control Plane.

REMEDIATION

Deploy VMware Avi patches immediately. Implement network segmentation for Control Plane. Audit Control Plane access logs for compromise indicators.

Source: Web  •  Published: 2026-07-14

[HIGH]

CVE-2026-53359 — Linux Kernel KVM (all Ubuntu releases)

16-year-old Linux kernel vulnerability (Januscape) in shadow MMU code enabling KVM guest-to-host escape. Attackers with root in guest VM can execute code as root on host and compromise all guests or crash host kernel.

REMEDIATION

Patch KVM hosts immediately to kernel 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, or 5.10.260. If patching delayed, disable nested virtualization (kvm_intel.nested=0 or kvm_amd.nested=0).

Source: Web  •  Published: 2026-07-06

[HIGH]

PROGRESS-SHAREFILE-SZC-2026 — Progress ShareFile Storage Zone Controller 5.x and 6.x

High-severity path traversal vulnerability in ShareFile Storage Zone Controller allowing authenticated administrators to read arbitrary files, write attacker-controlled content to arbitrary directories, or enumerate filesystem. Progress disabled customer access due to credible external security threat.

REMEDIATION

Upgrade to SZC 5.12.5 or 6.0.2 before bringing controllers back online. Review authentication, web access, and management logs for compromise indicators. Cloud-only ShareFile deployments not affected.

Source: Web  •  Published: 2026-07-10

[HIGH]

CVE-2026-47868 — VMware Avi Load Balancer

Local privilege escalation vulnerability in VMware Avi Load Balancer enabling authenticated attacker to escalate privileges to root. Completes attack chain from authentication bypass to full system control.

REMEDIATION

Apply VMware Avi patches immediately. Review local user accounts and access patterns. Implement least privilege principles for Avi Load Balancer access.

Source: Web  •  Published: 2026-07-14

[MEDIUM]

CVE-2026-47871 — VMware Avi Load Balancer

Directory traversal vulnerability in VMware Avi Load Balancer allowing authenticated attacker to access files outside intended boundaries. Enables sensitive file disclosure.

REMEDIATION

Deploy VMware Avi patches immediately. Audit file access logs for traversal attempts. Review file system permissions on Avi appliances.

Source: Web  •  Published: 2026-07-14

AI & Supply Chain

[HIGH]

AI-PHANTOM-SQUATTING-2026 — LLM-based Coding Assistants and AI Development Tools

New attack vector exploiting LLM hallucinations where attackers register nonexistent package names and domains that AI assistants consistently fabricate. Analysis of 913 brands via 685,339 URL queries generated 250,000 hallucinated domains. Creates supply chain risk through autonomous package fetching and installation.

REMEDIATION

Disable autonomous/auto-approve modes in AI coding assistants. Implement package allowlists in development environments. Monitor for package squatting on internal registries. Require manual approval for all package installations.

Source: Web  •  Published: 2026-07-22

Threat Actors & Dark Web

[HIGH]

UAT-7810-ORB-EXPANSION — Internet-facing networking devices

Chinese APT UAT-7810 actively refining malware to expand Operational Relay Box (ORB) network by compromising internet-facing networking devices. LapDogs ORB network establishes infrastructure for secondary threat actors to conduct attacks against high-value targets.

REMEDIATION

Monitor for suspicious traffic patterns to edge networking devices. Implement network segmentation to limit lateral movement. Update firmware on all internet-facing network appliances. Deploy EDR on network infrastructure where possible.

Source: GTIG  •  Published: 2026-07-22

[HIGH]

APT28-NEUSPLOIT-CAMPAIGN — Microsoft Office (Ukraine, Slovakia, Romania targets)

Russia-linked APT28 (UAC-0001) exploited CVE-2026-21509 Microsoft Office security feature bypass three days after public disclosure. Operation Neusploit targeted users in Ukraine, Slovakia, and Romania with weaponized Office documents.

REMEDIATION

Apply CVE-2026-21509 patches immediately. Deploy email security scanning for malicious Office documents. Educate users on Office macro risks. Monitor for suspicious Office process behavior.

Source: GTIG  •  Published: 2026-01-29

[HIGH]

RANSOMWARE-H1-2026-SURGE — Organizations globally

Ransomware incidents increased 20% year-over-year in H1 2026 with 5,275 recorded attacks. Q2 2026 alone saw 2,581 incidents. Significant increase in attack frequency and sophistication driven by ransomware-as-a-service proliferation.

REMEDIATION

Implement offline backup strategy with immutable storage. Deploy EDR across all endpoints. Conduct regular tabletop exercises for ransomware response. Segment networks to limit lateral movement. Maintain incident response retainers.

Source: Web  •  Published: 2026-07-22

Priority Action Matrix

01DO NOWCVE-2026-60137 (WordPress Core WP_Query): Update to WordPress 7.0.2, 6.9.5, or 6.8.6 immediately. Audit plugins and themes for unsafe WP_Query parameter handling. Review database access logs for injection attempts.
02DO NOWORACLE-CPU-2026-Q3 (Oracle Product Suite (32 product families)): Review Oracle July 2026 CPU documentation immediately. Apply patches to all Oracle products prioritizing the 261 critical-severity updates. Test in non-production first but expedite deployment.
03DO NOWCVE-2026-47865 (VMware Avi Load Balancer (all versions)): Apply VMware Avi Load Balancer patches immediately to fixed versions across all affected release branches (22.1.x through 32.1.x). Prioritize internet-facing deployments. Review access logs for unauth...
04DO NOWCVE-2026-47867 (VMware Avi Load Balancer Control Plane): Apply VMware Avi patches immediately across all versions. Segment Control Plane from untrusted networks. Monitor for unusual command execution patterns.
05DO NOWCVE-2026-47869 (VMware Avi Load Balancer Control Plane): Deploy VMware Avi patches immediately. Implement network segmentation for Control Plane. Audit Control Plane access logs for compromise indicators.
06TODAYCVE-2026-53359 (Linux Kernel KVM (all Ubuntu releases)): Patch KVM hosts immediately to kernel 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, or 5.10.260. If patching delayed, disable nested virtualization (kvm_intel.nested=0 or kvm_amd.nested=0).
07TODAYAI-PHANTOM-SQUATTING-2026 (LLM-based Coding Assistants and AI Development Tools): Disable autonomous/auto-approve modes in AI coding assistants. Implement package allowlists in development environments. Monitor for package squatting on internal registries. Require manual approval f...
08TODAYPROGRESS-SHAREFILE-SZC-2026 (Progress ShareFile Storage Zone Controller 5.x and 6.x): Upgrade to SZC 5.12.5 or 6.0.2 before bringing controllers back online. Review authentication, web access, and management logs for compromise indicators. Cloud-only ShareFile deployments not affected.
09TODAYCVE-2026-47868 (VMware Avi Load Balancer): Apply VMware Avi patches immediately. Review local user accounts and access patterns. Implement least privilege principles for Avi Load Balancer access.
10TODAYUAT-7810-ORB-EXPANSION (Internet-facing networking devices): Monitor for suspicious traffic patterns to edge networking devices. Implement network segmentation to limit lateral movement. Update firmware on all internet-facing network appliances. Deploy EDR on n...
11TODAYAPT28-NEUSPLOIT-CAMPAIGN (Microsoft Office (Ukraine, Slovakia, Romania targets)): Apply CVE-2026-21509 patches immediately. Deploy email security scanning for malicious Office documents. Educate users on Office macro risks. Monitor for suspicious Office process behavior.
12TODAYRANSOMWARE-H1-2026-SURGE (Organizations globally): Implement offline backup strategy with immutable storage. Deploy EDR across all endpoints. Conduct regular tabletop exercises for ransomware response. Segment networks to limit lateral movement. Maint...
13THIS WEEKCVE-2026-47871 (VMware Avi Load Balancer): Deploy VMware Avi patches immediately. Audit file access logs for traversal attempts. Review file system permissions on Avi appliances.

Biggest Risk This Period

BIGGEST RISK

CVE-2026-60137: SQL injection vulnerability in WordPress Core WP_Query when plugins or themes pass untrusted input to parameters. Chains with CVE-2026-63030 to enable unauthenticated RCE on default WordPress installations.