July 2026 (30)
Google Security Updates — July 2026
5 CVEs 41 IOCsRoundup of Google security advisories published in July 2026.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Redis Authenticated Remote Code Execution Vulnerability
1 TTPA vulnerability in Redis allows a remote, authenticated attacker to achieve arbitrary code execution on the target server.
Multiple Vulnerabilities in Progress MOVEit Transfer
1 TTP 4 CVEsMultiple vulnerabilities, including remote XSS and security policy bypass, have been identified in Progress MOVEit Transfer versions prior to 2026.0.3, enabling potential unauthorized access and session-based script execution.
Apple Security Updates — July 2026
4 CVEs 10 IOCsRoundup of Apple security advisories published in July 2026.
Detection of Malicious AMQP Multi-Queue Message Purging
1 TTPAdversaries may perform rapid multi-queue purges in AMQP-based messaging systems, such as RabbitMQ, to facilitate data destruction or cause widespread application disruption following credential compromise.
Denial of Service in gnome-remote-desktop via Connection Throttling Bypass
1 TTP 1 CVEA vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.
Unauthenticated Remote Code Injection in Logsign SIEM
1 CVELogsign SIEM versions prior to 6.4.108 are vulnerable to a critical code injection flaw (CVE-2026-17561) that enables unauthenticated remote attackers to achieve arbitrary code execution.
Citrix NetScaler ADC and Gateway CVE-2026-3055 Exploitation
2 rules 3 TTPs 5 CVEs 1 IOCThreat actors are actively exploiting CVE-2026-3055, a critical memory overread vulnerability in Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML identity provider (IDP), to extract sensitive information, including authenticated administrative session IDs, potentially leading to full system takeover.
Red Hat Advanced Cluster Security Policy Bypass via Deployment Label Manipulation
1 TTP 1 CVEA vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows an authenticated user to bypass security policy enforcement by setting the 'openshift.io/encoded-deployment-config' label to 'null'.
SolarWinds Web Help Desk Security Bypass Vulnerability
1 CVEA vulnerability in SolarWinds Web Help Desk, identified as CVE-2024-28986, allows remote unauthenticated attackers to bypass security measures, potentially leading to unauthorized access.
Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT
1 TTPMultiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.
AWS SageMaker Execution Role Privilege Escalation via PassRole
1 TTPAn adversary with SageMaker resource-creation rights and broad iam:PassRole permissions can escalate privileges by passing highly privileged IAM roles to SageMaker notebook instances, training, processing, or pipeline jobs.
Detection of Unusual AWS IAM Guardrail Policy Deletion
1 rule 2 TTPsThis threat brief identifies a detection strategy for attackers attempting defense evasion or persistence by deleting sensitive AWS IAM managed policies using previously unseen identities.
Unusual AWS Batch Job Container Command Override Detection
1 rule 1 TTPThis detection targets the abuse of AWS Batch 'containerOverrides.command' parameters by infrequent users to inject malicious commands or data exfiltration logic into production compute environments.
Arbitrary File Upload Vulnerability in Realtyna Organic IDX Plugin
2 TTPs 1 CVEThe Realtyna Organic IDX plugin for WordPress contains an arbitrary file upload vulnerability (CVE-2026-16236) due to improper validation and authentication, allowing remote attackers to achieve remote code execution.
Critical Hard-coded Credential Vulnerability in Rich Source DMS+ (Non-Mobile)
1 TTP 1 CVERich Source DMS+ (Non-Mobile) versions 5.63 and earlier contain a hard-coded API key allowing unauthenticated remote attackers to gain full administrative control over affected devices.
Argument Injection Vulnerability in yggdrasil-worker-package-manager
1 TTP 1 CVEAn argument injection vulnerability in the APT backend of yggdrasil-worker-package-manager allows local attackers to manipulate apt-get command-line arguments to achieve root-level code execution.
MeshCentral WebSocket Hijacking Vulnerability
1 CVECVE-2026-66420 is a high-severity vulnerability in MeshCentral 1.1.21 allowing unauthenticated attackers to hijack administrator sessions via a cross-site WebSocket hijacking protection bypass.
Stored XSS Vulnerability in OpenClaw Dashboard
1 TTP 1 CVEAn unauthenticated stored XSS vulnerability in the OpenClaw Dashboard allows remote attackers to execute arbitrary JavaScript in administrative sessions via the sessions API.
Siemens Security Updates — July 2026
5 CVEs 2 IOCsRoundup of Siemens security advisories published in July 2026.
Authenticated Remote Code Execution in Wolf CMS
1 rule 3 TTPsWolf CMS versions up to 0.8.3.1 contain a remote code execution vulnerability in the FileManagerController allowing authenticated users with specific permissions to upload and execute arbitrary PHP files.
Authentication Bypass Vulnerability in IBM WebSphere Application Server
2 CVEsA critical authentication bypass vulnerability (CVE-2026-10842) allows remote, unauthenticated attackers to circumvent security constraints in IBM WebSphere Application Server and Liberty versions.
Critical Authentication Bypass in Spikster API
1 CVEA missing authentication vulnerability in Spikster allows unauthenticated remote attackers to access approximately 50 API endpoints, leading to full system compromise.
Remote Code Execution via Exposed H2 Database in Juggle Through
2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability in Juggle Through 1.6.0 allows attackers to leverage default credentials on the H2 database console to execute system-level commands.
SSRF Protection Bypass in dssrf Library via URL Normalization
1 TTP 1 CVEThe dssrf library version 1.0.3 contains an SSRF bypass vulnerability in the is_url_safe function caused by improper character removal before URL parsing, allowing attackers to access restricted internal resources.
Arbitrary Code Execution in AWS Amplify Studio via Input Validation Flaw
1 TTP 1 CVEThe amplify-codegen-ui package is vulnerable to arbitrary code execution due to insufficient input validation during the component expression-binding process, allowing authenticated users to inject malicious JavaScript.
Leantime Authenticated LFI and SSRF via Blueprints
1 TTP 1 CVELeantime 3.6.2 contains a vulnerability in the Blueprints::import method allowing authenticated attackers to perform SSRF and LFI via the JSON-RPC API.
Path Traversal Vulnerability in IBM Langflow OSS
1 rule 1 CVEIBM Langflow OSS versions 1.0.0 through 1.10.1 are vulnerable to a path traversal flaw (CVE-2026-12942) that allows unauthenticated remote attackers to read arbitrary files from the hosting system.
Stack-based Buffer Overflow in IBM Db2 setgid Helper
1 rule 1 TTP 1 CVEIBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 contain a buffer overflow vulnerability in the db2flacc setgid helper that allows local attackers to escalate privileges.