1. Top Action Item
Patch Microsoft SharePoint Server against CVE-2026-58644 immediately. CISA has added this critical deserialization RCE vulnerability (CVSS 9.8) to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Federal agencies must patch by July 19; all organizations should treat this as an emergency. Apply the July 2026 Microsoft security update that addresses this flaw.
2. Exploited This Week
Microsoft SharePoint Server — CVE-2026-58644
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical (CVSS 9.8)
- What's happening: CISA added this critical deserialization RCE vulnerability to its KEV catalog, confirming exploitation in the wild.
- Fix: Apply the July 2026 Microsoft security update that addresses CVE-2026-58644.
SonicWall SMA — Zero-days exploited by Inc Ransomware
- Source: Dark Reading
- Link: Dark Reading
- Severity: see source
- What's happening: Inc Ransomware is chaining two zero-day vulnerabilities in SonicWall SMA (Secure Mobile Access) appliances to gain root-level access.
- Fix: Apply the latest SonicWall SMA firmware updates; see SonicWall advisory for specific versions.
3. Critical Patch Roundup
Microsoft July 2026 Patch Tuesday
- Source: Cisco Talos
- Link: Cisco Talos
- Severity: 57 critical, 622 total vulnerabilities
- What's happening: Microsoft released its July 2026 security update covering 622 vulnerabilities across its product line, including 57 rated critical. Products affected include Windows, Office, Exchange, SharePoint, and more.
- Fix: Apply the July 2026 Microsoft security updates.
Chromium (Microsoft Edge, Chrome, and other Chromium-based browsers) — CVE-2026-15899 through CVE-2026-15905
- Source: Microsoft MSRC
- Link: Microsoft MSRC
- Severity: see source
- What's happening: Seven Chromium CVEs were addressed, including use-after-free vulnerabilities in Aura, Ozone, Cast, Network, GPU, and CameraCapture, plus an out-of-bounds read/write in V8.
- Fix: Update Microsoft Edge to the latest version; Chrome users should update via Google Chrome Releases.
WordPress Core — wp2shell flaw
- Source: The Hacker News
- Link: The Hacker News
- Severity: Critical
- What's happening: An unauthenticated remote code execution vulnerability in WordPress core (affecting versions 6.9 and 7.0) allows anonymous HTTP requests to run code on any WordPress site, even with zero plugins. A public proof-of-concept is available.
- Fix: Update WordPress to the latest patched version.
OpenSSL — "HollowByte" denial-of-service
- Source: The Hacker News
- Link: The Hacker News
- Severity: High
- What's happening: An 11-byte TLS request can cause unpatched OpenSSL servers to leak up to 131 KB of memory per connection, which is not reclaimed until process restart on glibc systems. The fix was shipped in June without a CVE.
- Fix: Update OpenSSL to the version shipped in June 2026.
Siemens ROX II OT Switches — Zero-day trilogy
- Source: Palo Alto Unit 42
- Link: Unit 42
- Severity: High
- What's happening: Three chained zero-day vulnerabilities in Siemens ROX II OT switches allow privilege escalation and persistent root access.
- Fix: Apply Siemens firmware updates; see Siemens advisory for specific versions.
Fortinet Multiple Products — Various vulnerabilities
- Source: Fortinet FortiGuard
- Link: Fortinet FortiGuard
- Severity: High (CVSS 7.7 for unauthenticated VNC access in FortiSandbox; CVSS 7.0 for out-of-bounds read in FortiAuthenticator; others)
- What's happening: Fortinet published advisories for multiple products including FortiOS, FortiProxy, FortiPAM, FortiAuthenticator, FortiSandbox, FortiSIEM, and FortiClient EMS. Notable: unauthenticated VNC access in FortiSandbox (CVSS 7.7), out-of-bounds read in FortiAuthenticator (CVSS 7.0), and SSL-VPN reflected XSS (CVSS 6.1).
- Fix: Apply the latest firmware/software updates for each affected Fortinet product.
4. Home / SOHO Impact
- Update your browser immediately. If you use Chrome, Edge, or any Chromium-based browser, install the latest update which fixes seven security vulnerabilities including use-after-free flaws that could allow attackers to crash or take control of your browser.
- Update WordPress sites to the latest version. The wp2shell flaw allows attackers to run code on any WordPress site (versions 6.9 and 7.0) with just an HTTP request — no login or plugins needed.
- Check your router/firewall for updates. If you use a SonicWall SMA appliance, apply the latest firmware to block ransomware groups actively exploiting zero-days.
- Update OpenSSL on any Linux servers or devices you manage. The "HollowByte" flaw lets attackers freeze server memory with tiny TLS requests.
- Be cautious of fake coding tests and job offers. North Korean threat actors are using steganography in SVG images to deliver malware through fake job postings and coding challenges.
5. Enterprise Impact
- Patch SharePoint Server CVE-2026-58644 as an emergency. CISA has confirmed active exploitation. This critical deserialization RCE (CVSS 9.8) requires immediate attention across all on-premises SharePoint deployments.
- Apply the full July 2026 Microsoft Patch Tuesday update. With 57 critical vulnerabilities across 622 total CVEs, this is a heavy patch cycle affecting Windows, Office, Exchange, and other Microsoft products.
- Patch SonicWall SMA appliances immediately. Inc Ransomware is actively chaining two zero-days to gain root access on mobile access appliances. Prioritize these if exposed to the internet.
- Update WordPress installations enterprise-wide. The wp2shell flaw affects core WordPress (versions 6.9 and 7.0) and requires no authentication or plugins to exploit. Public proof-of-concept code is available.
- Update OpenSSL on all servers. The "HollowByte" DoS vulnerability can exhaust server memory with minimal effort. The fix shipped in June 2026 — verify all instances are updated.
- Review Fortinet appliances for the latest patches. Multiple products are affected including FortiSandbox (unauthenticated VNC access, CVSS 7.7), FortiAuthenticator (information disclosure, CVSS 7.0), and SSL-VPN (XSS, CVSS 6.1).
- Patch Siemens ROX II OT switches in industrial environments. Three chained zero-days allow privilege escalation to root access.
- Monitor for ACR Stealer activity. This infostealer is targeting browser credentials, session tokens, and Microsoft 365 files via ClickFix lures. Review endpoint detection rules for command-line execution of pasted commands.
6. What To Patch First
- Microsoft SharePoint Server — CVE-2026-58644 (exploited in the wild / critical / CISA KEV)
- SonicWall SMA appliances — zero-days (exploited by ransomware)
- Microsoft July 2026 Patch Tuesday — 57 critical, 622 total (widely deployed / critical)
- WordPress core — wp2shell flaw (critical / public PoC / widely deployed)
- Chromium-based browsers (Edge, Chrome) — CVE-2026-15899 through CVE-2026-15905 (widely deployed / use-after-free)
- OpenSSL — "HollowByte" DoS (widely deployed / memory exhaustion)
- FortiSandbox — unauthenticated VNC access (CVSS 7.7 / enterprise gear)
- FortiAuthenticator — out-of-bounds read (CVSS 7.0 / enterprise gear)
- Siemens ROX II OT switches — zero-day trilogy (privilege escalation / OT environments)
- FortiOS/FortiProxy SSL-VPN — reflected XSS (CVSS 6.1 / widely deployed VPN)
Sources
- CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV — https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html
- Inc Ransomware Exploits SonicWall SMA Zero-Days — https://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities — https://blog.talosintelligence.com/microsoft-patch-tuesday-july-2026/
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
- OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — https://thehackernews.com/2026/07/openssl-hollowbyte-flaw-could-freeze.html
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy — https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/
- Chromium: CVE-2026-15905 Use after free in Aura — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-15905
- Fortinet FortiGuard advisories (FG-IR-26-145 through FG-IR-26-155) — https://fortiguard.fortinet.com/psirt/FG-IR-26-145
- ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files — https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
- Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images — https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html