vulnerability SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud SAP released 19 security patches on July 26th, 2026, addressing critical vulnerabilities across several of its flagship products, including NetWeaver, Approuter, and Commerce Cloud. The most severe vulnerability, CVE-202… SecurityWeek · Jul 14, 2026 Critical CVE-2026-44747CVE-2026-27690CVE-2026-44761sapvulnerabilitypatch
vulnerability Vulnerability in FIFA’s Network A critical vulnerability in FIFA’s network allowed attackers to potentially gain control of the company’s systems, raising serious concerns about the security of FIFA’s operations and the data it handles. This incident h… Schneier on Security · Jul 14, 2026 High securitynetworkvulnerability
vulnerability Forgotten UEFI shims undermining Secure Boot Researchers at ESET discovered 11 old, Microsoft-signed UEFI shim bootloaders from 2026-02-16 that could bypass UEFI Secure Boot on most systems. These shims, used by various software packages, allowed attackers to deplo… WeLiveSecurity · Jul 14, 2026 High CVE-2026-8863CVE-2026-10797CVE-2020-10713uefisecure bootrevocation
vulnerability ISC Stormcast For Tuesday, July 14th, 2026 https://isc.sans.edu/podcastdetail/10006, (Tue, Jul 14th) The ISC Stormcast highlighted a significant vulnerability in the latest version of Apache Struts, potentially allowing for remote code execution via a deserialization attack. This vulnerability is actively being exploite… SANS Internet Storm Center · Jul 14, 2026 Critical strutsdeserializationremote code execution
vulnerability RabbitMQ Vulnerability Threatens Enterprise Systems A vulnerability (CVE-2026-5721) in RabbitMQ allows attackers to steal the broker's confidential OAuth secret, potentially leading to complete control over an organization's message queues, users, and settings. This flaw,… SecurityWeek · Jul 13, 2026 High CVE-2026-5721CVE-2026-57221rabbitmqoauthvulnerability
vulnerability Zimbra Patches Critical Code Execution Vulnerability A critical cross-site scripting (XSS) vulnerability in Zimbra’s Classic Web Client could allow attackers to execute code on a victim’s system simply by opening a specially crafted email. Zimbra has released version 10.1.… SecurityWeek · Jul 13, 2026 Critical xssvulnerabilityzimbra
vulnerability Organizations Warned of Exploited Joomla Extension Vulnerabilities Two critical vulnerabilities in Joomla extensions – Balbooa Forms and iCagenda – have been actively exploited by threat actors, allowing for remote code execution without authentication. Both vulnerabilities have been ad… SecurityWeek · Jul 13, 2026 Critical CVE-2026-56291CVE-2026-48939joomlavulnerabilityremote code execution
vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
vulnerability iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days Two zero-day vulnerabilities in Joomla extensions – iCagenda and Balbooa Forms – are being actively exploited in a global campaign targeting vulnerable CMS systems. Both flaws allow for remote code execution via file upl… The Hacker News · Jul 13, 2026 Critical CVE-2026-48939CVE-2026-56291CVE-2025-6389AUjoomlavulnerabilityzero-day
vulnerability ISC Stormcast For Monday, July 13th, 2026 https://isc.sans.edu/podcastdetail/10004, (Mon, Jul 13th) The ISC Stormcast highlighted a significant vulnerability in Apache ActiveMQ, potentially allowing attackers to execute arbitrary code. This could lead to widespread disruption and data compromise across various industri… SANS Internet Storm Center · Jul 13, 2026 High activemqvulnerabilitydeserialization
vulnerability Wireshark 4.6.7 Released, (Sat, Jul 11th) Wireshark, a widely used network protocol analyzer, released a security update addressing 12 vulnerabilities and 16 bugs. This update is crucial for maintaining network security and protecting against potential exploits. SANS Internet Storm Center · Jul 11, 2026 Medium wiresharkvulnerabilitynetwork analysis
vulnerability Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions A critical cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client could allow attackers to execute malicious code through crafted emails, potentially leading to account compromise and data theft. Zimbra… The Hacker News · Jul 11, 2026 High CVE-2025-27915CVE-2023-37580CVE-2024-27443xssvulnerabilityweb client
vulnerability Friday Squid Blogging: “Squidbleed” Vulnerability A vulnerability, dubbed ‘Squidbleed,’ has been discovered in the Squid proxy server, allowing attackers to leak HTTP requests. This flaw stems from a flawed implementation of the HTTP/2 protocol, potentially exposing sen… Schneier on Security · Jul 10, 2026 Medium http2proxyvulnerability
vulnerability Laser Attack Resets Tangem Wallet Passwords on Cards That Can't Be Patched Researchers at Ledger's Donjon security team have discovered a method to bypass the password protection on Tangem crypto wallet cards using a precisely timed laser pulse. The attack requires physical access to the card a… The Hacker News · Jul 10, 2026 High hardware walletlaser attackfirmware
vulnerability Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers A remote client can crash HTTP/3 servers running XQUIC, Alibaba's HTTP/3 and QUIC library. The vulnerability, dubbed XRING, stems from an incorrect size calculation during table resizing within the QPACK header compressi… The Hacker News · Jul 10, 2026 High CVE-2026-42530httphttp3quic
vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
vulnerability WolfSSL, GeoVision, VTK vulnerabilities Cisco Talos has disclosed a significant number of vulnerabilities across WolfSSL, GeoVision, and VTK-DICOM. These vulnerabilities range from buffer overflows and command injection to session cookie issues and heap overfl… Cisco Talos · Jul 9, 2026 Medium CVE-2026-28739CVE-2026-25106CVE-2026-33091buffer_overflowcommand_injectioncve
vulnerability Palo Alto Networks Patches 13 Vulnerabilities Palo Alto Networks has released advisories detailing 13 vulnerabilities across its products, including a critical buffer overflow that could lead to arbitrary code execution. While the company reports no active exploitat… SecurityWeek · Jul 9, 2026 High CVE-2026-0288vulnerabilitypatchbuffer overflow
vulnerability OpenPLC v3 A critical vulnerability exists in OpenPLC v3, allowing authenticated attackers to write arbitrary files and escalate to arbitrary native code execution through the program upload process. This vulnerability affects crit… CISA Advisories · Jul 9, 2026 Critical CVE-2026-14480vulnerabilityindustrial control systemscwe-73
vulnerability Schneider Electric PowerChute Serial Shutdown Schneider Electric PowerChute Serial Shutdown versions 1.4 and earlier contain multiple vulnerabilities that could allow attackers to overwrite critical files, inject malicious data, gain unauthorized access, or trigger… CISA Advisories · Jul 9, 2026 High CVE-2026-2399CVE-2026-2404CVE-2026-2405vulnerabilitypatchsecurity advisory