News 2026-07-04
π‘οΈ Cybersecurity Vulnerability Watch
Patch Microsoft SharePoint Server immediately. CISA has added CVE-2026-45659, a deserialization of untrusted data vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog based onβ¦
Open report
π‘οΈ Cybersecurity Vulnerability Watch
Week of: 2026-06-28 to 2026-07-04
1. Top Action Item
Patch Microsoft SharePoint Server immediately. CISA has added CVE-2026-45659, a deserialization of untrusted data vulnerability, to its Known Exploited Vulnerabilities (KEV) catalog based on confirmed active exploitation. Apply the latest Microsoft security update for SharePoint Server without delay.
2. Exploited This Week
Microsoft SharePoint Server β CVE-2026-45659
- Source: CISA Advisories
- Link: CISA Adds One Known Exploited Vulnerability to Catalog
- Severity: see source
- What's happening: CISA added this deserialization vulnerability to the KEV catalog based on evidence of active exploitation.
- Fix: Apply the latest Microsoft SharePoint Server security update.
3. Critical Patch Roundup
Linux Kernel β CVE-2026-46242 ("Bad Epoll")
- Source: The Hacker News
- Link: New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
- Severity: Critical
- What's happening: An unprivileged user can exploit this flaw to gain full root access on Linux desktops, servers, and Android devices.
- Fix: Apply the latest Linux kernel update. A fix is available.
FatFs Filesystem Library β 7 Unpatched Flaws
- Source: The Hacker News
- Link: Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices
- Severity: see source
- What's happening: Seven vulnerabilities disclosed in the FatFs library, which is embedded in security cameras, drones, industrial controllers, and hardware crypto wallets.
- Fix: No patch available at time of disclosure. Monitor vendor advisories for affected devices.
Chromium Browser β Multiple CVEs (CVE-2026-13874, CVE-2026-13953, CVE-2026-14142, CVE-2026-14131, CVE-2026-14020, CVE-2026-13798, CVE-2026-13797, CVE-2026-13952, CVE-2026-14130, CVE-2026-14019, CVE-2026-14073)
- Source: Microsoft MSRC
- Link: Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer
- Severity: see source
- What's happening: Multiple Chromium vulnerabilities including heap buffer overflow, inappropriate implementations, and insufficient validation across various components.
- Fix: Update Chrome/Edge to the latest version. See Google Chrome Releases for details.
Delta Electronics DVP12SE PLC β CVE-2026-12819, CVE-2026-12818
- Source: CISA Advisories
- Link: Delta Electronics DVP12SE PLC
- Severity: CVSS 9.8 (Critical)
- What's happening: Missing authentication for critical functions allows remote attackers to issue commands, modify operational values, and alter device behavior.
- Fix: See vendor advisory for mitigation guidance.
OFFIS DCMTK Toolkit β CVE-2026-50003, CVE-2026-50254, CVE-2026-35505, CVE-2026-52868, CVE-2026-44628
- Source: CISA Advisories
- Link: OFFIS DCMTK Toolkit
- Severity: CVSS 9.8 (Critical)
- What's happening: Multiple vulnerabilities including path traversal allow attackers to write files, access unauthorized information, exhaust memory, or crash processes.
- Fix: Update DCMTK to a version newer than 3.7.0.
Gardyn IoT Hub β CVE-2026-13768, CVE-2026-55726, CVE-2026-54477
- Source: CISA Advisories
- Link: Gardyn IoT Hub
- Severity: CVSS 10.0 (Critical)
- What's happening: Hard-coded credentials, information exposure, and improper input neutralization allow unauthenticated access and control of IoT Hub managed devices.
- Fix: Update to Cloud API version 2.12.2026 or later.
4. Home / SOHO Impact
- Update your browser: Apply the latest Chrome or Edge update immediately. Multiple Chromium vulnerabilities were disclosed this week affecting all Chromium-based browsers.
- Patch your Android device: The "Bad Epoll" Linux kernel flaw (CVE-2026-46242) affects Android. Install the latest security update from your device manufacturer.
- Check for IoT device updates: If you use a Gardyn IoT Hub, update to firmware version 2.12.2026 or later to address critical vulnerabilities (CVSS 10.0).
- Be cautious of fake software downloads: A new macOS stealer called PamStealer is being distributed through fake Maccy clipboard manager sites. Only download software from official sources.
- Watch for phishing emails impersonating Interpol: Ransomware campaigns are using fake Interpol notifications to target small businesses. Do not click links or open attachments in unsolicited emails claiming to be from law enforcement.
5. Enterprise Impact
- Patch SharePoint Server now: CVE-2026-45659 is actively exploited and added to CISA's KEV catalog. Prioritize this patch across all on-premises SharePoint deployments.
- Update Linux servers and endpoints: The "Bad Epoll" kernel flaw (CVE-2026-46242) allows unprivileged users to gain root. Apply kernel updates to all Linux systems, including cloud instances and container hosts.
- Monitor for Citrix Bleed 2 exploitation: Anubis ransomware affiliates are actively exploiting CVE-2025-5777 (Citrix Bleed 2) for initial access. Ensure Citrix ADC/Gateway appliances are patched.
- Review Fortinet firewall access: The FortiBleed campaign actors are collaborating with Inc. and Lynx ransomware gangs, monetizing access to thousands of Fortinet firewalls and exploiting a Nextcloud zero-day.
- Audit npm and Packagist dependencies: North Korean threat actors published 108 malicious packages and browser extensions in the PolinRider campaign, including packages mimicking Rollup polyfill tooling. Review your software supply chain for these packages.
- Check for FatFs library in embedded/IoT devices: Seven unpatched vulnerabilities were disclosed in FatFs, which is used in security cameras, industrial controllers, and other embedded devices. Inventory affected devices and monitor for vendor patches.
- Update DCMTK in medical environments: If your organization uses OFFIS DCMTK for medical imaging, update to version newer than 3.7.0 to address critical path traversal vulnerabilities.
6. What To Patch First
- Microsoft SharePoint Server β CVE-2026-45659 (actively exploited / CISA KEV)
- Linux Kernel β CVE-2026-46242 "Bad Epoll" (critical / widely deployed / affects servers, desktops, Android)
- Chrome/Edge browsers β Multiple CVEs (widely deployed / multiple vulnerabilities)
- Gardyn IoT Hub β CVE-2026-13768, CVE-2026-55726, CVE-2026-54477 (CVSS 10.0 / critical)
- Delta Electronics DVP12SE PLC β CVE-2026-12819, CVE-2026-12818 (CVSS 9.8 / critical infrastructure)
- OFFIS DCMTK Toolkit β Multiple CVEs (CVSS 9.8 / medical devices)
- Citrix ADC/Gateway β CVE-2025-5777 "Citrix Bleed 2" (actively exploited by ransomware groups)
- Fortinet firewalls β FortiBleed-related patches (active campaign / ransomware collaboration)
Sources
- CISA Adds One Known Exploited Vulnerability to Catalog β https://www.cisa.gov/news-events/alerts/2026/07/01/cisa-adds-one-known-exploited-vulnerability-catalog
- New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android β https://thehackernews.com/2026/07/new-bad-epoll-linux-kernel-flaw-lets.html
- Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices β https://thehackernews.com/2026/07/unpatched-flaws-disclosed-in-filesystem.html
- Chromium: CVE-2026-13874 Inappropriate implementation in DataTransfer β https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-13874
- Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials β https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.html
- FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs β https://www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs
- North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign β https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets β https://thehackernews.com/2026/07/north-korea-linked-npm-packages-mimic.html
- PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords β https://thehackernews.com/2026/07/pamstealer-uses-fake-maccy-sites-and.html
- Ransomware Thugs Masquerade as Interpol to Entice Small Biz β https://www.darkreading.com/cyberattacks-data-breaches/attackers-use-interpol-lure-target-small-businesses
- Gardyn IoT Hub β https://www.cisa.gov/news-events/ics-advisories/icsa-26-183-03
- Delta Electronics DVP12SE PLC β https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-07
- OFFIS DCMTK Toolkit β https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-181-01
More from News
β‘ Energy Industry Briefing
2026-07-22
π World & Geopolitics Briefing
2026-07-18
π‘οΈ Cybersecurity Vulnerability Watch
2026-07-18
IAM & Security Weekly Briefing
2026-07-18
AI Model & Benchmark Watch β July 17, 2026
2026-07-17
AI Projects - July 17, 2026
2026-07-17
AI Tool Updates - July 17, 2026
2026-07-17
General AI News - July 17, 2026
2026-07-17
MCP Protocol News - July 17, 2026
2026-07-17
Science & Space Digest β Jul 17, 2026
2026-07-17
ποΈ Tech Policy & Regulation Watch
2026-07-16
Cool Websites β July 16, 2026
2026-07-16