1. Top Action Item

Patch Microsoft SharePoint Server immediately. CISA has added CVE-2026-45659, a deserialization of untrusted data vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Apply the latest Microsoft security update for SharePoint Server without delay.


2. Exploited This Week

Microsoft SharePoint Server — CVE-2026-45659


3. Critical Patch Roundup

Linux Kernel — CVE-2026-46242 ("Bad Epoll")

FatFs Filesystem Library — 7 Unpatched Flaws

Chromium Browser — Multiple CVEs (CVE-2026-13874, CVE-2026-13953, CVE-2026-14142, CVE-2026-14131, CVE-2026-14020, CVE-2026-13798, CVE-2026-13797, CVE-2026-13952, CVE-2026-14130, CVE-2026-14019, CVE-2026-14073)

Delta Electronics DVP12SE PLC — CVE-2026-12819, CVE-2026-12818

OFFIS DCMTK Toolkit — CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628

Gardyn IoT Hub — CVE-2026-13768, CVE-2026-55726, CVE-2026-54477


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Microsoft SharePoint Server — CVE-2026-45659 (actively exploited / CISA KEV)
  2. Linux Kernel — CVE-2026-46242 "Bad Epoll" (critical / widely deployed / affects servers, desktops, Android)
  3. Chrome/Edge browsers — Multiple CVEs (widely deployed / multiple vulnerabilities)
  4. Gardyn IoT Hub — CVE-2026-13768, CVE-2026-55726, CVE-2026-54477 (CVSS 10.0 / critical)
  5. Delta Electronics DVP12SE PLC — CVE-2026-12819, CVE-2026-12818 (CVSS 9.8 / critical infrastructure)
  6. OFFIS DCMTK Toolkit — Multiple CVEs (CVSS 9.8 / medical devices)
  7. Citrix ADC/Gateway — CVE-2025-5777 "Citrix Bleed 2" (actively exploited by ransomware groups)
  8. Fortinet firewalls — FortiBleed-related patches (active campaign / ransomware collaboration)

Sources