Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack
2026-07-15T01:24:08Z•b0a063ec00394af4c858cba39e695e8630ad5770b49d851d3498572182bff493
AI-assisted attacksCVE-2026-44747CVE-2026-48939CrashStealerForg365Grok BuildJoomla KEVLabubaRATMicrosoftModHeaderOAuthRATRabbitMQSAPSecureBootUEFIbrowser-extensiondata-exfiltrationjscramblermemghostnpm compromisepatchingphishing-as-a-servicesupply-chainzero-day
What happened
This collection summarizes a large set of July 2026 security incidents and updates: Microsoft released a record Patch Tuesday covering 622 CVEs including two zero-days under active exploitation; SAP fixed a critical NetWeaver ABAP out-of-bounds write (CVE-2026-44747, CVSS 9.9); CISA added two Joomla extension zero-days (including CVE-2026-48939) to its KEV catalog. Other notable items: a new Rust-based LabubaRAT masquerading as NVIDIA software, RabbitMQ access-control flaws that can leak OAuth secrets and cross-tenant metadata, 11 Microsoft-signed UEFI shims that can bypass Secure Boot, and a恶
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b0a063ec00394af4c858cba39e695e8630ad5770b49d851d3498572182bff493
- Enrichment time
- 2026-07-15T01:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.