Unpatched Cursor Vulnerability Exposes Users to Code Execution
2026-07-15T19:24:05Z•7adabacf825171b8b0d68e0ffee250b7094d8bdd6c958ca08b845a17af7d6e69
ai-policybind-linkchromecisacode-executioncursoredr-evasionexploitfirefoxgit-executableicspatch-managementprogressremote-code-executionrockwellschneiderservice-nowservicenowsharefilesharepointsiemenssoftware-updatesvulnerability-disclosurewindowszero-day
What happened
Multiple active and high-impact security issues reported: an unpatched Cursor flaw can auto-execute a malicious git.exe placed in a repo root, enabling code execution; CISA warns of three actively exploited SharePoint vulnerabilities (including two zero-days) and urges immediate patching; Bitdefender details Windows bind-link techniques that can hide malware from EDR by creating conflicting filesystem views; vendors (Fortinet, Ivanti, ServiceNow) issued patches — ServiceNow’s AI platform had a critical RCE defect; Progress confirmed a zero-day caused ShareFile disruptions and released a fix; a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 7adabacf825171b8b0d68e0ffee250b7094d8bdd6c958ca08b845a17af7d6e69
- Enrichment time
- 2026-07-15T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.