Article Read Time

1. SharePoint zero-day under active attack forces federal patch deadline. CISA added CVE-2026-58644, a critical (CVSS 9.8) deserialization flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, giving Federal Civilian Executive Branch agencies until July 19 to remediate. The bug allows unauthenticated remote code execution and was weaponized as a zero-day before Microsoft’s July 14 Patch Tuesday fixes landed, with attackers stealing IIS machine keys to establish persistence. Every supported on-premises edition (Subscription, 2019, and 2016) is affected.
Source: The Hacker News (https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html)
2. KDDI zero-day exposes 12.2 million email addresses. Japanese telecom KDDI confirmed that attackers exploited a zero-day vulnerability in email infrastructure shared across multiple internet service providers, exposing the email addresses of 12.2 million individuals and passwords belonging to 7.6 million users. The incident underscores the systemic risk of shared upstream infrastructure, where a single flaw cascades across every provider that depends on it. Affected users are being urged to reset credentials immediately.
Source: eSecurity Planet (https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/)
4. Microsoft ships out-of-band patch for Windows Defender privilege flaw. Microsoft released an emergency, out-of-band fix for CVE-2026-50656, nicknamed “RoguePlanet,” a privilege escalation vulnerability in Windows Defender. The flaw lets an attacker who already holds basic user access elevate to full SYSTEM privileges, a powerful stepping stone for turning a minor foothold into complete host control. Because it lives in the very tool meant to protect the endpoint, organizations were advised to apply the patch without waiting for the next scheduled cycle.
Source: eSecurity Planet (https://www.esecurityplanet.com/weekly-roundup/zero-days-ai-governance-gaps-and-global-cybercrime-define-this-weeks-security-landscape-in-july-2026/)
5. WordPress pushes emergency core releases over critical vulnerabilities. WordPress shipped versions 6.9.5 and 7.0.2 after critical vulnerabilities were discovered in its core, including chainable flaws that could let anonymous requests execute code on affected sites. Given that WordPress powers a large share of the public web, core-level bugs offer attackers an enormous attack surface, and automatic updates alone do not always cover every configuration. Site owners were urged to confirm they are running the patched builds.
Source: eSecurity Planet (https://www.esecurityplanet.com/weekly-roundup/ai-driven-attacks-critical-exploits-and-global-breaches-define-this-week-in-july-2026-in-cybersecurity/)
