← July 2026
News 2026-07-04

πŸ›‘οΈ Cybersecurity Vulnerability Watch

Patch Microsoft SharePoint Server immediately. CISA has added CVE-2026-45659, a deserialization of untrusted data vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog based on…

πŸ›‘οΈ Cybersecurity Vulnerability Watch
Open report

πŸ›‘οΈ Cybersecurity Vulnerability Watch

Week of: 2026-06-28 to 2026-07-04


1. Top Action Item

Patch Microsoft SharePoint Server immediately. CISA has added CVE-2026-45659, a deserialization of untrusted data vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Apply the latest Microsoft security update for SharePoint Server without delay.


2. Exploited This Week

Microsoft SharePoint Server β€” CVE-2026-45659

  • Source: CISA Advisories
  • Link: CISA Adds One Known Exploited Vulnerability to Catalog
  • Severity: see source
  • What's happening: CISA added this deserialization vulnerability to the KEV catalog based on evidence of active exploitation.
  • Fix: Apply the latest Microsoft SharePoint Server security update.

3. Critical Patch Roundup

Linux Kernel β€” CVE-2026-46242 ("Bad Epoll")

FatFs Filesystem Library β€” 7 Unpatched Flaws

Chromium Browser β€” Multiple CVEs (CVE-2026-13874, CVE-2026-13953, CVE-2026-14142, CVE-2026-14131, CVE-2026-14020, CVE-2026-13798, CVE-2026-13797, CVE-2026-13952, CVE-2026-14130, CVE-2026-14019, CVE-2026-14073)

  • Source: Microsoft MSRC
  • Link: Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer
  • Severity: see source
  • What's happening: Multiple Chromium vulnerabilities including heap buffer overflow, inappropriate implementations, and insufficient validation across various components.
  • Fix: Update Chrome/Edge to the latest version. See Google Chrome Releases for details.

Delta Electronics DVP12SE PLC β€” CVE-2026-12819, CVE-2026-12818

  • Source: CISA Advisories
  • Link: Delta Electronics DVP12SE PLC
  • Severity: CVSS 9.8 (Critical)
  • What's happening: Missing authentication for critical functions allows remote attackers to issue commands, modify operational values, and alter device behavior.
  • Fix: See vendor advisory for mitigation guidance.

OFFIS DCMTK Toolkit β€” CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628

  • Source: CISA Advisories
  • Link: OFFIS DCMTK Toolkit
  • Severity: CVSS 9.8 (Critical)
  • What's happening: Multiple vulnerabilities including path traversal allow attackers to write files, access unauthorized information, exhaust memory, or crash processes.
  • Fix: Update DCMTK to a version newer than 3.7.0.

Gardyn IoT Hub β€” CVE-2026-13768, CVE-2026-55726, CVE-2026-54477

  • Source: CISA Advisories
  • Link: Gardyn IoT Hub
  • Severity: CVSS 10.0 (Critical)
  • What's happening: Hard-coded credentials, information exposure, and improper input neutralization allow unauthenticated access and control of IoT Hub managed devices.
  • Fix: Update to Cloud API version 2.12.2026 or later.

4. Home / SOHO Impact

  • Update your browser: Apply the latest Chrome or Edge update immediately. Multiple Chromium vulnerabilities were disclosed this week affecting all Chromium-based browsers.
  • Patch your Android device: The "Bad Epoll" Linux kernel flaw (CVE-2026-46242) affects Android. Install the latest security update from your device manufacturer.
  • Check for IoT device updates: If you use a Gardyn IoT Hub, update to firmware version 2.12.2026 or later to address critical vulnerabilities (CVSS 10.0).
  • Be cautious of fake software downloads: A new macOS stealer called PamStealer is being distributed through fake Maccy clipboard manager sites. Only download software from official sources.
  • Watch for phishing emails impersonating Interpol: Ransomware campaigns are using fake Interpol notifications to target small businesses. Do not click links or open attachments in unsolicited emails claiming to be from law enforcement.

5. Enterprise Impact

  • Patch SharePoint Server now: CVE-2026-45659 is actively exploited and added to CISA's KEV catalog. Prioritize this patch across all on-premises SharePoint deployments.
  • Update Linux servers and endpoints: The "Bad Epoll" kernel flaw (CVE-2026-46242) allows unprivileged users to gain root. Apply kernel updates to all Linux systems, including cloud instances and container hosts.
  • Monitor for Citrix Bleed 2 exploitation: Anubis ransomware affiliates are actively exploiting CVE-2025-5777 (Citrix Bleed 2) for initial access. Ensure Citrix ADC/Gateway appliances are patched.
  • Review Fortinet firewall access: The FortiBleed campaign actors are collaborating with Inc. and Lynx ransomware gangs, monetizing access to thousands of Fortinet firewalls and exploiting a Nextcloud zero-day.
  • Audit npm and Packagist dependencies: North Korean threat actors published 108 malicious packages and browser extensions in the PolinRider campaign, including packages mimicking Rollup polyfill tooling. Review your software supply chain for these packages.
  • Check for FatFs library in embedded/IoT devices: Seven unpatched vulnerabilities were disclosed in FatFs, which is used in security cameras, industrial controllers, and other embedded devices. Inventory affected devices and monitor for vendor patches.
  • Update DCMTK in medical environments: If your organization uses OFFIS DCMTK for medical imaging, update to version newer than 3.7.0 to address critical path traversal vulnerabilities.

6. What To Patch First

  1. Microsoft SharePoint Server β€” CVE-2026-45659 (actively exploited / CISA KEV)
  2. Linux Kernel β€” CVE-2026-46242 "Bad Epoll" (critical / widely deployed / affects servers, desktops, Android)
  3. Chrome/Edge browsers β€” Multiple CVEs (widely deployed / multiple vulnerabilities)
  4. Gardyn IoT Hub β€” CVE-2026-13768, CVE-2026-55726, CVE-2026-54477 (CVSS 10.0 / critical)
  5. Delta Electronics DVP12SE PLC β€” CVE-2026-12819, CVE-2026-12818 (CVSS 9.8 / critical infrastructure)
  6. OFFIS DCMTK Toolkit β€” Multiple CVEs (CVSS 9.8 / medical devices)
  7. Citrix ADC/Gateway β€” CVE-2025-5777 "Citrix Bleed 2" (actively exploited by ransomware groups)
  8. Fortinet firewalls β€” FortiBleed-related patches (active campaign / ransomware collaboration)

Sources

More from News