Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

2026-07-15T01:24:08Zb0a063ec00394af4c858cba39e695e8630ad5770b49d851d3498572182bff493
AI-assisted attacksCVE-2026-44747CVE-2026-48939CrashStealerForg365Grok BuildJoomla KEVLabubaRATMicrosoftModHeaderOAuthRATRabbitMQSAPSecureBootUEFIbrowser-extensiondata-exfiltrationjscramblermemghostnpm compromisepatchingphishing-as-a-servicesupply-chainzero-day

What happened

This collection summarizes a large set of July 2026 security incidents and updates: Microsoft released a record Patch Tuesday covering 622 CVEs including two zero-days under active exploitation; SAP fixed a critical NetWeaver ABAP out-of-bounds write (CVE-2026-44747, CVSS 9.9); CISA added two Joomla extension zero-days (including CVE-2026-48939) to its KEV catalog. Other notable items: a new Rust-based LabubaRAT masquerading as NVIDIA software, RabbitMQ access-control flaws that can leak OAuth secrets and cross-tenant metadata, 11 Microsoft-signed UEFI shims that can bypass Secure Boot, and a恶

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b0a063ec00394af4c858cba39e695e8630ad5770b49d851d3498572182bff493
Enrichment time
2026-07-15T01:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.