Short, tactical, daily. The weekly Issues are the verdict — these are the notes scrawled in between.
-
ServiceNow CVE-2026-6875 and WordPress WP2Shell flaws are under active exploitation, while a critical unauthenticated NGINX RCE (CVE-2026-42533) sits one crafted request away from your edge.
-
Public exploits are live for WordPress Core 'wp2shell' RCE, and 7-Zip patched a malicious-archive RCE in 26.02.
-
WordPress core wp2shell RCE has a public PoC and Inc ransomware is chaining SonicWall SMA zero-days for root, both under active or imminent exploitation.
-
A critical SharePoint RCE (CVE-2026-58644) is under active exploitation with a CISA July 19 deadline, while CISA also flags two exploited Fortinet FortiSandbox flaws.
-
CISA sets a Saturday deadline for the actively exploited Oracle E-Business Suite flaw while Zoom patches a 9.8 account-takeover bug for Windows.
-
Two SonicWall SMA1000 zero-days (CVE-2026-15409/15410) and three actively exploited SharePoint flaws are under attack right now, while Microsoft ships a record 570-plus patch load.
-
CISA flags active exploitation of Joomla iCagenda and Balbooa Forms RCE flaws, while a Jscrambler npm supply chain compromise and ShinyHunters OAuth abuse of Salesforce show trusted code and connections remain the soft entry.
-
CISA adds two max-severity Joomla extension flaws (CVE-2026-48939 and iCagenda) to KEV after zero-day exploitation, while Progress tells ShareFile customers to shut down servers over a credible threat.
-
A compromised jscrambler 8.14.0 npm release runs a Rust infostealer on install across Windows, macOS, and Linux.
-
Progress tells ShareFile admins to power off Storage Zone Controllers over a credible threat, Gitea's Docker auth bypass is under active exploitation, and a compromised Injective Labs npm package is stealing wallet keys.
-
Okta and Bleeping Computer detail active vishing-driven Entra passkey enrollment attacks (O-UNC-066, Helix) hitting Microsoft 365, while attackers actively exploit the 'Ill Bloom' wallet flaw and a poisoned Injective npm package to drain crypto.
-
A China-linked cluster is actively exploiting Roundcube to hijack university mail, Tenda ships an unpatched firmware backdoor (CVE-2026-11405), and Microsoft finally patched the RoguePlanet Defender zero-day (CVE-2026-50656).
-
Active exploitation of max-severity ColdFusion (CVE-2026-48282), Langflow, and Gitea (CVE-2026-20896) flaws, plus GhostLock (CVE-2026-43499), a 15-year-old Linux root escape hitting every mainstream distro.
-
NetScaler is under active exploitation again with a public PoC, while BeyondTrust ships critical pre-auth bypass fixes and a 16-year-old KVM escape (Januscape) drops with a working proof-of-concept.
-
Opera GX patched a zero-click flaw that let malicious sites auto-install mods and exfiltrate page data, while Google and the FBI disrupted the NetNut residential proxy botnet.
-
A local-root Linux kernel flaw (CVE-2026-46242) now has a fix and hits Android, while North Korea's npm typosquats keep bleeding developer secrets.
-
Anubis affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) for ransomware access while FortiBleed actors monetize thousands of compromised Fortinet firewalls with a Nextcloud zero-day.
-
Three active-exploitation items lead today: SharePoint RCE CVE-2026-45659 hits CISA KEV, Cisco confirms Unified CM exploitation, and an unpatched Argo CD flaw threatens full Kubernetes cluster takeover.
-
Active exploitation of Langflow RCE (CVE-2026-33017) and an ongoing Azure CLI password spray dominate today, alongside a batch of max-severity Adobe ColdFusion patches.
-
Three actively exploited critical flaws hit at once: SimpleHexlp CVE-2026-48558, Oracle EBS CVE-2026-46817, and Windows Defender 'BlueHammer,' all with confirmed in-the-wild abuse.
-
Active exploitation hits SimpleHelp (CVE-2026-48558) and Oracle EBS (CVE-2026-46817), while a public PoC drops for the libssh2 client flaw CVE-2026-55200.