Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 29, 2026 - July 29, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Wednesday, July 29, 2026 -67% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-40139 — BeyondTrust Remote Support

Authentication bypass vulnerability specific to BeyondTrust Remote Support with CVSS 9.2. Allows unauthenticated remote attackers to bypass access controls including elevated privilege accounts. BeyondTrust silently patched cloud deployments in April 2026 without public disclosure.

REMEDIATION

Upgrade to RS 25.3.3 or later immediately. Specific authentication configuration required but not disclosed by vendor; treat all instances as vulnerable unless confirmed otherwise. Implement network restrictions and audit logs thoroughly.

Source: BleepingComputer  •  Published: 2026-07-07

[HIGH]

CVE-2026-2699 — Progress ShareFile Storage Zone Controller

A high-severity path traversal zero-day affecting all ShareFile Storage Zone Controller 5.x and 6.x versions. Authenticated admin users can read arbitrary files, write malicious content to directories, or enumerate filesystem layout. Exploited in the wild starting July 10, 2026.

REMEDIATION

Install versions 5.12.5 and 6.0.2 immediately. Assume exposed systems are compromised and conduct forensic analysis. Review access logs for unauthorized file access. Consider systems in context of 2023 MOVEit Transfer attacks.

Source: BleepingComputer  •  Published: 2026-07-14

Priority Action Matrix

01DO NOWCVE-2026-40139 (BeyondTrust Remote Support): Upgrade to RS 25.3.3 or later immediately. Specific authentication configuration required but not disclosed by vendor; treat all instances as vulnerable unless confirmed otherwise. Implement network r...
02TODAYCVE-2026-2699 (Progress ShareFile Storage Zone Controller): Install versions 5.12.5 and 6.0.2 immediately. Assume exposed systems are compromised and conduct forensic analysis. Review access logs for unauthorized file access. Consider systems in context of 202...

Biggest Risk This Period

BIGGEST RISK

CVE-2026-40139: Authentication bypass vulnerability specific to BeyondTrust Remote Support with CVSS 9.2. Allows unauthenticated remote attackers to bypass access controls including elevated privilege accounts. BeyondTrust silently patched cloud deployments in April 2026 without public disclosure.