1. Top Action Item

Patch Microsoft SharePoint Server against CVE-2026-58644 immediately. CISA has added this critical deserialization RCE vulnerability (CVSS 9.8) to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Federal agencies must patch by July 19; all organizations should treat this as an emergency. Apply the July 2026 Microsoft security update that addresses this flaw.


2. Exploited This Week

Microsoft SharePoint Server — CVE-2026-58644

SonicWall SMA — Zero-days exploited by Inc Ransomware


3. Critical Patch Roundup

Microsoft July 2026 Patch Tuesday

Chromium (Microsoft Edge, Chrome, and other Chromium-based browsers) — CVE-2026-15899 through CVE-2026-15905

WordPress Core — wp2shell flaw

OpenSSL — "HollowByte" denial-of-service

Siemens ROX II OT Switches — Zero-day trilogy

Fortinet Multiple Products — Various vulnerabilities


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Microsoft SharePoint Server — CVE-2026-58644 (exploited in the wild / critical / CISA KEV)
  2. SonicWall SMA appliances — zero-days (exploited by ransomware)
  3. Microsoft July 2026 Patch Tuesday — 57 critical, 622 total (widely deployed / critical)
  4. WordPress core — wp2shell flaw (critical / public PoC / widely deployed)
  5. Chromium-based browsers (Edge, Chrome) — CVE-2026-15899 through CVE-2026-15905 (widely deployed / use-after-free)
  6. OpenSSL — "HollowByte" DoS (widely deployed / memory exhaustion)
  7. FortiSandbox — unauthenticated VNC access (CVSS 7.7 / enterprise gear)
  8. FortiAuthenticator — out-of-bounds read (CVSS 7.0 / enterprise gear)
  9. Siemens ROX II OT switches — zero-day trilogy (privilege escalation / OT environments)
  10. FortiOS/FortiProxy SSL-VPN — reflected XSS (CVSS 6.1 / widely deployed VPN)

Sources