Microsoft July 2026 Patch Tuesday Zero-Day Hits SharePoint

Microsoft July 2026 Patch Tuesday zero-day

The Microsoft July 2026 Patch Tuesday zero-day count is the largest disclosure on record — trackers put the total at 570 to 622 CVEs depending on methodology — and two of the fixed flaws were already being exploited before the patch shipped: one in Active Directory Federation Services, one in SharePoint Server. A separate, publicly…

Read More

Gitea Docker CVE-2026-20896 Auth Bypass

Gitea Docker CVE-2026-20896

Gitea Docker CVE-2026-20896 is now under active exploitation: a single crafted HTTP header lets an unauthenticated attacker impersonate any user of a self-hosted Gitea instance — including an administrator — and walk away with private repositories and any secrets committed by mistake. What Happened Gitea’s official Docker image ships with REVERSE_PROXY_TRUSTED_PROXIES=*. On deployments that also…

Read More

Langflow CVE-2026-55255 KEV: AI Agent Flaw Explained

Langflow CVE-2026-55255 KEV

The Langflow CVE-2026-55255 KEV entry, added by CISA on July 7, marks the first time an AI agent orchestration platform has ever appeared in the Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of just 6.1 from CISA, yet KEVIntel and CIRCL independently score the same bug 9.9, because it lets an authenticated…

Read More

ZEGO Cyberattack Insolvency: A Six-Week Shutdown

ZEGO cyberattack insolvency

ZEGO cyberattack insolvency is now a real-world case study, not a hypothetical: a 35-year-old German textile finisher in Aschaffenburg has filed for insolvency after a cyberattack in March 2026 halted production for nearly six weeks — and the type of attack that caused it still hasn’t been publicly disclosed. What Happened ZEGO Textilveredelungszentrum GmbH, founded…

Read More

SharePoint RCE CVE-2026-45659: Active Exploits

SharePoint RCE CVE-2026-45659

SharePoint RCE CVE-2026-45659 is now under active exploitation, and the federal patch deadline set by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is July 4 — tomorrow. The CVSS 8.8 deserialization flaw lets any authenticated user with nothing more than baseline Site Member permissions run code remotely on the server. Shadowserver currently counts more…

Read More