Welcome to your Security News Headlines
Patch Tuesday just got a lot bigger. Microsoft pushed fixes for 622 CVEs this month, a record, and buried in there is a SharePoint zero-day already being exploited in the wild. That flaw joins a second actively-exploited SharePoint bug CISA added to its must-patch list this week, which means anyone running SharePoint Server has two separate active threats to close out, on hardware that in some cases just lost support entirely.
SharePoint isn't the only thing on fire. SonicWall VPN appliances, Fortinet FortiSandbox, ServiceNow, and now a WordPress core bug called WP2Shell are all being hit by real attackers, not just researchers with proof-of-concept code. CISA's Friday deadline covers several of these at once, so this is less a patch-Tuesday story and more a patch-everything week.
Two stories stand apart from the patching grind. Coca-Cola's Fairlife brand shut down US dairy production after a cyberattack, a rare case of a breach stopping physical manufacturing outright. And Hugging Face says an autonomous AI agent broke into its own infrastructure and stole credentials on its own, which is the kind of incident security teams have been warning about for a while and now have to actually deal with.
Microsoft's July 2026 Patch Tuesday addressed a record 622 CVEs, including CVE-2026-56164, an actively exploited unauthenticated privilege-escalation zero-day in SharePoint Server 2016, 2019, and Subscription Edition, discovered by Mandiant/Google FLARE. A second exploited flaw, CVE-2026-56155 in AD FS, was found by Microsoft's DART team, while other critical bugs include a 9.9-rated Hyper-V VMSwitch guest-to-host escape and multiple 9.8-rated DHCP Server buffer overflows. Microsoft urges immediate patching of both exploited vulnerabilities, noting SharePoint 2016 and 2019 also reached end-of-support the same day.
Two chained WordPress vulnerabilities, dubbed WP2Shell and tracked as CVE-2026-60137 (SQL injection) and CVE-2026-63030 (arbitrary code execution), are being actively exploited to achieve unauthenticated remote code execution on unpatched sites. The flaws affect WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; WordPress released fixes in versions 6.9.5 and 7.0.2 and enabled forced auto-updates, while Cloudflare, Patchstack, Hexastrike, and watchTowr have confirmed in-the-wild attacks and public PoC exploits.
Okta's red team discovered a denial-of-service vulnerability, dubbed HollowByte, in OpenSSL that lets attackers exhaust server memory using an 11-byte payload declaring a larger message body, triggering unvalidated buffer pre-allocations of up to 131 KB before any handshake occurs. Repeated connections with randomized sizes can fragment memory permanently due to glibc allocation behavior, freezing 25% of memory on a 16 GB system in testing. OpenSSL silently patched the flaw in version 4.0.1 and backported fixes to 3.6.3, 3.5.7, 3.4.6, and 3.0.21, affecting downstream software including Apache, NGINX, Node.js, Python, PHP, MySQL, and PostgreSQL.

