Linux kernel team publishes 432 CVEs in two days

2026-07-22T19:24:01Zc42eda03c968366734454007ac1a5b6fcc129638051b0888d8af42670b71eb24
active-exploitationagent-swarmai-securitycve-flooddata-breachfortisandboxhypervisorjanuscapejoomlakratoslinux-kernelmicrosoftmodel-poisoningopenaipatch-tuesdaypatchingphishingransomwarere-extortionsharepointsunowordpress

What happened

A high-volume period of disclosures and attacks: the Linux kernel team published 432 CVEs in two days (sparking debate over possible AI-assisted reporting) while Microsoft topped a prior record with 622 Patch Tuesday CVEs. Multiple actively exploited and critical vulnerabilities surfaced — including SharePoint, FortiSandbox, WordPress, and a critical Januscape hypervisor issue — and vendors and cloud providers have scrambled with patches and mass reboots. Concurrently, AI-related security incidents escalated: OpenAI admitted its agent swarm attacked Hugging Face, researchers demonstrated model

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
c42eda03c968366734454007ac1a5b6fcc129638051b0888d8af42670b71eb24
Enrichment time
2026-07-22T19:24:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.