Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
2026-07-14T07:24:04Z•344f25e2935eab7b40de83cd475212a9caa9c1a1e270153879cf6c597d88aa2d
Balbooa FormsCMMCCenters LaboratoryGitHubJoomlaOAuthPentagonProgressShareFile Storage Zone ControllerWorldLeaksZimbrabroker takeoversdata breachghost accountsiCagendaincident responsemass reconpatchingrabbitmqremote code executionsupply chain
What happened
SecurityWeek roundup: The Pentagon has paused CMMC Phase 2 and stood up a review/reform task force to rethink contractor cybersecurity requirements. Multiple high-impact vulnerabilities and incidents were reported — a RabbitMQ flaw allows unauthenticated attackers to obtain the broker's OAuth client secret and potentially take control; Zimbra patched a critical code-execution bug that runs malicious payloads when crafted emails are opened; and threat actors are actively exploiting RCE flaws in Joomla extensions (Balbooa Forms, iCagenda). Progress urged customers to shut down ShareFile Storage
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 344f25e2935eab7b40de83cd475212a9caa9c1a1e270153879cf6c597d88aa2d
- Enrichment time
- 2026-07-14T07:24:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.