Wednesday, July 15, 2026
Daily digest
July 2026 Patch Tuesday is the dominant story: Microsoft released a record-breaking 570–622 CVEs (counts vary by source methodology) including three zero-days, two actively exploited. Prioritize triage now.
Microsoft July 2026 Patch Tuesday Fixes Record 570+ Flaws, 3 Zero-Days
Microsoft's July 2026 Patch Tuesday addressed between 570 and 622 CVEs depending on counting methodology — roughly triple last month's record — including two zero-days under active exploitation and one publicly disclosed. More than 60 vulnerabilities are rated Critical. Microsoft attributed the surge in vulnerability discovery partly to AI-assisted research. The two actively exploited zero-days were identified through incident response.
Why it matters: Your Intune-managed Windows 11 fleet needs immediate attention on the two actively exploited zero-days before the rest of the 60+ criticals are triaged. Validate that Intune update rings are pushing KB5101650/KB5099414 — but see the Dell shutdown issue below before deploying broadly.
Microsoft Blocking July Windows Updates on Some Dell PCs Due to Shutdown Issues
Microsoft has applied a compatibility hold to block July 2026 Patch Tuesday updates from deploying on certain Dell devices after reports that the updates cause unexpected shutdowns and performance degradation. Affected Dell machines will not receive the updates automatically until the issue is resolved.
Why it matters: If any Dell hardware is in your Intune-managed fleet, check your update compliance reports for safeguard holds before assuming July patches are deployed. You may need to manually verify coverage on non-Dell endpoints to ensure the actively exploited zero-days are closed there while Dell units remain pending.
Two SonicWall SMA 1000 Zero-Days Actively Exploited, One CVSS 10.0
SonicWall disclosed two zero-day vulnerabilities in its SMA 1000 series appliances being actively exploited in the wild. CVE-2026-15409 (CVSS 10.0) is an unauthenticated SSRF flaw that can enable arbitrary command execution; a second flaw (CVE-2026-15410) is also being exploited. SonicWall has released patches and urges immediate installation.
Why it matters: SMA 1000 appliances are remote-access gateway devices — a CVSS 10.0 unauthenticated RCE on a perimeter device is a critical exposure. If SonicWall SMA 1000 is in your environment or a partner's, treat this as emergency patching; exploitation is confirmed active.
CISA Warns of Active Exploitation of Three On-Premises SharePoint Server Flaws
CISA issued an advisory warning that attackers are actively exploiting three vulnerabilities in internet-exposed on-premises SharePoint Server instances. Federal agencies and administrators are urged to apply available patches immediately or take vulnerable systems offline.
Why it matters: If your environment runs any on-premises SharePoint (common alongside M365 GCC High in hybrid configurations), patch or isolate immediately — CISA advisories for actively exploited flaws carry implicit BOD 22-01 urgency for federal and DIB contractors operating under CMMC frameworks.
OAuth Client ID Spoofing Lets Attackers Silently Validate Stolen Microsoft Entra Credentials
Researchers identified a novel evasion technique in which at least two threat actor groups spoof OAuth client IDs to enumerate accounts and validate stolen credentials against Microsoft Entra ID without generating sign-in events visible in standard telemetry. The technique allows credential stuffing and account validation while bypassing typical detection controls that rely on sign-in logs.
Why it matters: Your M365 GCC High tenant's Entra ID is directly in scope. If your identity monitoring relies solely on successful or failed sign-in logs, this technique is invisible to it — review whether your SIEM or Sentinel instance captures OAuth token request telemetry at the application layer, not just authentication events.
11 Microsoft-Signed UEFI Shims Could Let Attackers Bypass Secure Boot
Researchers discovered 11 older UEFI shim applications that carry valid Microsoft signatures but contain exploitable flaws allowing attackers to execute untrusted code at boot time, enabling deployment of UEFI bootkits. The vulnerable shims remain valid because they are legitimately signed, requiring revocation via DBX updates to block them.
Why it matters: Nutanix AHV nodes boot Linux-based hypervisors and may use UEFI shims in your cluster firmware chain. Verify whether July's Patch Tuesday includes DBX revocation list updates covering these shims, and check whether your AHV and bare-metal servers will receive the updated revocation list through their firmware/OS update processes.
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
Four packages in the @asyncapi namespace on npm were found to have been compromised and are delivering a multi-stage botnet loader. The affected packages include @asyncapi/generator, @asyncapi/specs, and related components used in API tooling pipelines. Multiple security firms — OX Security, SafeDep, Socket, and StepSecurity — independently confirmed the compromise.
Why it matters: If any Ansible playbooks, CI/CD pipelines, or developer tooling in your environment pulls @asyncapi packages, audit your npm dependency trees and build logs now for the affected versions. Supply-chain compromises in API tooling are a recurring vector for lateral movement into infrastructure automation environments.
Cursor IDE Silently Executes Malicious Code from Cloned Repositories on Windows
A flaw in the Cursor AI code editor on Windows causes it to automatically execute any file named git.exe found in a project's root directory when the project is opened, without any user prompt or warning. The execution runs with the user's full privileges and continues as long as the project is open, exposing SSH keys, cloud tokens, and source code to any malicious repository containing such a file.
Why it matters: If developers in your organization use Cursor on Windows workstations — especially those with access to AWS GovCloud credentials, SSH keys, or CUI repositories — this is an immediate risk. A poisoned repository cloned from an untrusted source is all that is required to exfiltrate credentials silently.
White House Announces 'Gold Eagle' AI Clearinghouse for Cyber Vulnerabilities
The White House announced the 'Gold Eagle' initiative, an AI-powered clearinghouse for cyber vulnerability intelligence stemming from a June 2 executive order requiring advanced AI developers to grant the government early access to their capabilities for vulnerability identification. The program aims to centralize AI-assisted vulnerability discovery and disclosure coordination at the federal level.
Why it matters: This initiative may shape how vulnerability disclosure requirements evolve for DIB contractors under CMMC — particularly around timeliness of reporting CUI-relevant vulnerabilities. Watch for downstream policy updates to CMMC L2 assessment guidance or DFARS 252.204-7012 reporting obligations.
Air Force Network Lockouts Hit Troops and Civilians Amid Cybersecurity Quarantines
Air Force personnel across bases and at the Pentagon are being locked out of their computers due to cybersecurity quarantine measures triggered by software updates. The lockouts are disrupting operations for both military and civilian employees.
Why it matters: This is a real-world example of aggressive endpoint quarantine policy causing operational disruption — a tradeoff directly relevant to CMMC L2 environments balancing NIST 800-171 SI/CM controls with mission availability. If your Intune compliance policies enforce quarantine on non-compliant devices, this event illustrates the operational risk of not staging updates carefully.
Google Cloud VMware Service Loses Resilience After Faulty Update; VMware Warns of Critical Load Balancer Flaw
A bad update to Google Cloud's VMware-based hosted service degraded its resilience capabilities for affected customers. Separately, VMware issued an advisory for a critical vulnerability in its load balancer product. The two events occurred concurrently, raising concerns about update risk management in virtualized cloud infrastructure.
Why it matters: While your primary hypervisor is Nutanix AHV rather than VMware, the VMware load balancer CVE may affect shared or partner infrastructure. More broadly, the GCP incident is a reminder to review change management controls on your AHV cluster updates — a failed hypervisor update without rollback planning directly threatens CMMC availability requirements.
AWS Security Hub Adds AI Workload Protection and Microsoft Azure Multicloud Support
AWS Security Hub has been updated with purpose-built protection controls for AI workloads and new multicloud support extending visibility to Microsoft Azure environments. The additions allow centralized security posture management across AWS and Azure from a single Security Hub console.
Why it matters: If your AWS GovCloud deployment uses Security Hub, the AI workload protection controls are directly relevant to any self-hosted AI stack running there. The Azure multicloud connector could also consolidate visibility between AWS GovCloud and any Azure-side resources without adding a separate CSPM tool — worth evaluating against your current monitoring architecture.