Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

2026-07-14T07:24:04Z344f25e2935eab7b40de83cd475212a9caa9c1a1e270153879cf6c597d88aa2d
Balbooa FormsCMMCCenters LaboratoryGitHubJoomlaOAuthPentagonProgressShareFile Storage Zone ControllerWorldLeaksZimbrabroker takeoversdata breachghost accountsiCagendaincident responsemass reconpatchingrabbitmqremote code executionsupply chain

What happened

SecurityWeek roundup: The Pentagon has paused CMMC Phase 2 and stood up a review/reform task force to rethink contractor cybersecurity requirements. Multiple high-impact vulnerabilities and incidents were reported — a RabbitMQ flaw allows unauthenticated attackers to obtain the broker's OAuth client secret and potentially take control; Zimbra patched a critical code-execution bug that runs malicious payloads when crafted emails are opened; and threat actors are actively exploiting RCE flaws in Joomla extensions (Balbooa Forms, iCagenda). Progress urged customers to shut down ShareFile Storage

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
344f25e2935eab7b40de83cd475212a9caa9c1a1e270153879cf6c597d88aa2d
Enrichment time
2026-07-14T07:24:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.