A path traversal flaw with a maximum CVSS score of 10.0 lets unauthenticated attackers achieve arbitrary code execution on ColdFusion servers. Adobe patched it June 30 believing it wasn't yet exploited — attackers proved otherwise within 2 days. CISA added it to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by July 10.
State of Threats: July 2026
This month's threat landscape was defined by three patterns: critical CVEs moving from disclosure to active exploitation in days rather than weeks, the first confirmed ransomware attack automated end-to-end by an AI agent, and several major breaches whose root cause was identity/access failure rather than a novel exploit. Below are the 10 most significant items, ranked by severity and impact, each with a synthesis and a link to the full write-up.
Top 10 threats this month
A CVSS 9.3 authentication bypass in deprecated IKEv1 VPN configurations lets unauthenticated attackers establish a session without credentials. Exploitation began as early as May 7 and has been tied to at least one confirmed Qilin ransomware intrusion.
A deserialization-of-untrusted-data bug lets authenticated attackers run arbitrary code on SharePoint Server, potentially handing over full server control. CISA added it to its KEV catalog on July 2 after confirming active exploitation.
A privilege escalation flaw in Defender's Malware Protection Engine could let attackers gain SYSTEM privileges on Windows 10/11. Microsoft rushed an emergency patch on July 9 after a researcher publicly disclosed the bug and a proof-of-concept, reportedly amid a bug-bounty dispute.
Researchers at Sysdig identified the first documented ransomware operation run entirely by an LLM agent — from initial access to encryption — via a previously-patched Langflow RCE flaw. It's a preview of how agentic AI can automate the full attack chain, not just individual steps.
A hacker known as "888" claimed to have exfiltrated 35GB from the consulting giant, including source code, RSA/SSH keys, Azure Personal Access Tokens, and Azure Storage access keys. Accenture confirmed an intrusion shortly after the claims surfaced with proof screenshots on a cybercrime forum.
The medical device maker confirmed a breach affecting roughly 3.8 million individuals, attributed to the ShinyHunters group. Unauthorized access to corporate IT systems occurred April 13-19, but customer notifications didn't begin until late June — over two months later.
South Korea's PIPC fined Coupang a record 624.9 billion won (~$409M) — not for a sophisticated hack, but because a former IT employee retained system access after leaving and quietly exfiltrated 33.7 million accounts' data over 7 months. Deleting access logs after a preservation order made the penalty worse.
Huntress observed a campaign generating over 81 million login attempts against Microsoft 365 in two weeks, using Azure CLI to bypass MFA with previously-exposed credentials. It compromised 78 accounts across 64 organizations — a reminder that MFA implementation details matter as much as having MFA at all.
CSA Singapore's June bulletin flagged three remote code execution flaws in Outlook and Word (CVE-2026-47635, CVE-2026-45458, CVE-2026-45456), each CVSS 8.4. No specific vulnerable builds were listed, so every unpatched installation should be treated as exposed until updated.
Explore by category
For the full, continuously-updated feed behind this synthesis, see Latest Threats and Security News.
CYBERSHIELDZONE