Product
critical
threat
Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday
8 TTPs 4 CVEs 8 IOCsMicrosoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.
exploited
PoC
Active Directory Federation Services +23
patch-tuesday
zero-day
vulnerability
microsoft
windows
sharepoint
active-directory-federation-services
bitlocker
+2
8t
4c
8i
updated
critical
threat
CVE-2026-63030: Critical Remote Code Execution Vulnerability in WordPress Core
2 TTPs 15 CVEs 8 IOCsCVE-2026-63030 is a critical unauthenticated remote code execution vulnerability affecting WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allowing an unauthenticated attacker to execute arbitrary code via the WordPress REST API batch endpoint, potentially leading to complete website compromise.
exploited
PoC
WordPress Core 6.9.0 +51
wordpress
rce
web-vulnerability
cve
2t
15c
8i
updated
high
advisory
Microsoft Security Updates — July 2026
10 CVEs 227 IOCsRoundup of Microsoft security advisories published in July 2026.
PoC
PowerShell +516
roundup
10c
227i
updated