SQL injection vulnerability in WordPress Core WP_Query when plugins or themes pass untrusted input to parameters. Chains with CVE-2026-63030 to enable unauthenticated RCE on default WordPress installations.
Update to WordPress 7.0.2, 6.9.5, or 6.8.6 immediately. Audit plugins and themes for unsafe WP_Query parameter handling. Review database access logs for injection attempts.
Source: Web • Published: 2026-07-17
Largest Oracle Critical Patch Update ever with 1,235 unique CVEs across 1,449 security updates. Includes 261 critical patches across 228 CVEs. Oracle Database Products received 15 patches, 6 remotely exploitable without authentication.
Review Oracle July 2026 CPU documentation immediately. Apply patches to all Oracle products prioritizing the 261 critical-severity updates. Test in non-production first but expedite deployment.
Source: Web • Published: 2026-07-22
Critical authentication bypass vulnerability (CVSS 9.8) allowing unauthenticated network-adjacent attacker to bypass authentication entirely and gain full access to Avi Control Plane. Part of seven-vulnerability disclosure spanning authentication, RCE, and privilege escalation.
Apply VMware Avi Load Balancer patches immediately to fixed versions across all affected release branches (22.1.x through 32.1.x). Prioritize internet-facing deployments. Review access logs for unauthorized Control Plane access.
Source: Web • Published: 2026-07-14
Critical RCE vulnerability in VMware Avi Load Balancer Control Plane enabling remote code execution. Combined with CVE-2026-47865 authentication bypass, provides path from unauthenticated network access to full system compromise.
Apply VMware Avi patches immediately across all versions. Segment Control Plane from untrusted networks. Monitor for unusual command execution patterns.
Source: Web • Published: 2026-07-14
Critical RCE vulnerability in VMware Avi Load Balancer Control Plane. Second RCE vector enabling remote code execution on compromised Control Plane.
Deploy VMware Avi patches immediately. Implement network segmentation for Control Plane. Audit Control Plane access logs for compromise indicators.
Source: Web • Published: 2026-07-14
16-year-old Linux kernel vulnerability (Januscape) in shadow MMU code enabling KVM guest-to-host escape. Attackers with root in guest VM can execute code as root on host and compromise all guests or crash host kernel.
Patch KVM hosts immediately to kernel 7.1.3, 6.18.38, 6.12.95, 6.6.144, 6.1.177, 5.15.211, or 5.10.260. If patching delayed, disable nested virtualization (kvm_intel.nested=0 or kvm_amd.nested=0).
Source: Web • Published: 2026-07-06
High-severity path traversal vulnerability in ShareFile Storage Zone Controller allowing authenticated administrators to read arbitrary files, write attacker-controlled content to arbitrary directories, or enumerate filesystem. Progress disabled customer access due to credible external security threat.
Upgrade to SZC 5.12.5 or 6.0.2 before bringing controllers back online. Review authentication, web access, and management logs for compromise indicators. Cloud-only ShareFile deployments not affected.
Source: Web • Published: 2026-07-10
Local privilege escalation vulnerability in VMware Avi Load Balancer enabling authenticated attacker to escalate privileges to root. Completes attack chain from authentication bypass to full system control.
Apply VMware Avi patches immediately. Review local user accounts and access patterns. Implement least privilege principles for Avi Load Balancer access.
Source: Web • Published: 2026-07-14
Directory traversal vulnerability in VMware Avi Load Balancer allowing authenticated attacker to access files outside intended boundaries. Enables sensitive file disclosure.
Deploy VMware Avi patches immediately. Audit file access logs for traversal attempts. Review file system permissions on Avi appliances.
Source: Web • Published: 2026-07-14
New attack vector exploiting LLM hallucinations where attackers register nonexistent package names and domains that AI assistants consistently fabricate. Analysis of 913 brands via 685,339 URL queries generated 250,000 hallucinated domains. Creates supply chain risk through autonomous package fetching and installation.
Disable autonomous/auto-approve modes in AI coding assistants. Implement package allowlists in development environments. Monitor for package squatting on internal registries. Require manual approval for all package installations.
Source: Web • Published: 2026-07-22
Chinese APT UAT-7810 actively refining malware to expand Operational Relay Box (ORB) network by compromising internet-facing networking devices. LapDogs ORB network establishes infrastructure for secondary threat actors to conduct attacks against high-value targets.
Monitor for suspicious traffic patterns to edge networking devices. Implement network segmentation to limit lateral movement. Update firmware on all internet-facing network appliances. Deploy EDR on network infrastructure where possible.
Source: GTIG • Published: 2026-07-22
Russia-linked APT28 (UAC-0001) exploited CVE-2026-21509 Microsoft Office security feature bypass three days after public disclosure. Operation Neusploit targeted users in Ukraine, Slovakia, and Romania with weaponized Office documents.
Apply CVE-2026-21509 patches immediately. Deploy email security scanning for malicious Office documents. Educate users on Office macro risks. Monitor for suspicious Office process behavior.
Source: GTIG • Published: 2026-01-29
Ransomware incidents increased 20% year-over-year in H1 2026 with 5,275 recorded attacks. Q2 2026 alone saw 2,581 incidents. Significant increase in attack frequency and sophistication driven by ransomware-as-a-service proliferation.
Implement offline backup strategy with immutable storage. Deploy EDR across all endpoints. Conduct regular tabletop exercises for ransomware response. Segment networks to limit lateral movement. Maintain incident response retainers.
Source: Web • Published: 2026-07-22
CVE-2026-60137: SQL injection vulnerability in WordPress Core WP_Query when plugins or themes pass untrusted input to parameters. Chains with CVE-2026-63030 to enable unauthenticated RCE on default WordPress installations.