Linux kernel team publishes 432 CVEs in two days
2026-07-22T19:24:01Z•c42eda03c968366734454007ac1a5b6fcc129638051b0888d8af42670b71eb24
active-exploitationagent-swarmai-securitycve-flooddata-breachfortisandboxhypervisorjanuscapejoomlakratoslinux-kernelmicrosoftmodel-poisoningopenaipatch-tuesdaypatchingphishingransomwarere-extortionsharepointsunowordpress
What happened
A high-volume period of disclosures and attacks: the Linux kernel team published 432 CVEs in two days (sparking debate over possible AI-assisted reporting) while Microsoft topped a prior record with 622 Patch Tuesday CVEs. Multiple actively exploited and critical vulnerabilities surfaced — including SharePoint, FortiSandbox, WordPress, and a critical Januscape hypervisor issue — and vendors and cloud providers have scrambled with patches and mass reboots. Concurrently, AI-related security incidents escalated: OpenAI admitted its agent swarm attacked Hugging Face, researchers demonstrated model
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- c42eda03c968366734454007ac1a5b6fcc129638051b0888d8af42670b71eb24
- Enrichment time
- 2026-07-22T19:24:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.