Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Copilot RCE, Entra SSRF, and SharePoint Zero-Day: Critical Vulnerabilities in Microsoft's July 2026 Advisory

AI assistants are quietly becoming one of Microsoft’s largest attack surfaces. In its July 2026 advisory, Microsoft patched a command injection vulnerability in Copilot. Crafted prompts can trigger unintended actions through this flaw. The advisory also included a critical SSRF vulnerability in Entra’s identity provisioning service. It carries the among the highest severity score in the entire release. Both point to the same shift.

Oracle's July 2026 CPU: Critical Unauth Vulnerabilities in PeopleSoft, WebLogic, and E-Business Suite

Oracle released its July 2026 Critical Patch Update (CPU) on July 21, delivering 1,449 security fixes across 1,235 unique CVEs, the largest CPU in the company’s history. The release spans 32 product families, with the heaviest concentration in Oracle E-Business Suite, Oracle Fusion Middleware, Oracle Communications, and PeopleSoft. Nine of these CVEs received a perfect CVSS 10.0 score.

CVE-2026-56164: Unauthenticated SharePoint Zero-Day Grants Farm Administrator Access

Microsoft released patches for over 570 vulnerabilities in its July 2026 Patch Tuesday, the largest security update in the company’s history, including two zero-days already under active exploitation. Among them, one stands out for how it is being exploited right now: an unauthenticated vulnerability in SharePoint Server that allows an unauthenticated attacker to elevate privileges to Farm Administrator.

CVE-2026-6875: ServiceNow Sandbox Escape Leads to Pre-Auth RCE in AI Platform

ServiceNow AI Platform (the enterprise PaaS formerly branded in the Now Platform) contains a critical, unauthenticated remote code execution vulnerability tracked as CVE-2026-6875. The vulnerability allows a remote attacker to escape ServiceNow’s JavaScript execution sandbox. No credentials or user interaction are required, and the attacker achieves full code execution on the underlying instance.

WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE

A newly disclosed WordPress exploit chain, nicknamed “WP2Shell,” lets unauthenticated attackers achieve remote code execution (RCE) on any WordPress Core installation, no plugins required. Disclosed on July 17, 2026, the chain combines two vulnerabilities: CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API batch-route confusion).

CVE-2026-48282: ColdFusion RDS Vulnerability Actively Exploited

Enterprises running Adobe ColdFusion often carry legacy development features forward long after the original use case is gone. Remote Development Services (RDS) is a good example: a convenience feature that lets an IDE talk to a live ColdFusion server, left switched on from an old dev workflow years after anyone remembers why.

CERT-In AI Security Blueprint 2026: Remediation Timelines Every Indian Organisation Should Know

If a known exploited vulnerability appeared on your internet-facing application right now, what would your team actually do in the next 12 hours? What would actually happen, given your tooling, your sprint cycle, your change management queue, and who is available. CERT-In’s blueprint sets these timelines because generative AI and autonomous agents have collapsed the attacker timeline to the point where anything longer is already too slow.

The API Self-Check: How Hackers Find the Endpoint You Forgot About

In June 2026, ServiceNow disclosed that a customer-facing API endpoint had been shipped with authentication switched off, letting anyone query internal tables on hosted customer instances without a password. It wasn’t an isolated case. In 2025, a deprecated Stripe payment endpoint, still connected to live systems, let attackers validate stolen card numbers for months before anyone noticed.

A 10-Minute WordPress Security Self-Check (No Scanner Required)

Right now, a bot is running a single command against a website and reading the first few lines that come back. Maybe yours. It is not personal. The bot is working down a list of a few hundred thousand WordPress sites, and any given site is on it because WordPress runs more than 40% of the web and the same small set of mistakes shows up on most of them. You can read exactly what that bot reads. It takes about ten minutes, the tools are already on your machine, and none of it is hacking.

CVE-2026-46817: Oracle EBS Payments Vulnerability Under Active Exploitation

Oracle E-Business Suite (EBS) sits at the center of finance, procurement, and payment operations for many large enterprises. When a critical vulnerability surfaces in a module like Oracle Payments, the impact reaches well past IT. It touches financial data, transaction integrity, and regulatory exposure. CVE-2026-46817 is exactly that kind of vulnerability, and it is now being actively exploited.

CVE-2026-33017: Langflow RCE Deploys Monero Miners on AI Servers

Enterprises are standing up AI application frameworks like Langflow faster than security teams can review them. These platforms let teams build and automate generative AI workflows in days instead of months, but that speed comes with a cost: many instances go live with default settings, get exposed to the internet, and never make it onto a security team’s radar. CVE-2026-33017 shows exactly what happens next.