Microsoft SharePoint Zero-Day Exploited — Patch Now
Today's cybersecurity digest — CVEs, headline news, quantum computing, and something weird. July 19, 2026
cybr.cx | Daily Digest — July 19, 2026
Critical Vulnerabilities
⚠️ Actively exploited — CVE-2026-58644 | Microsoft SharePoint | No CVSS published
A deserialization of untrusted data vulnerability in Microsoft SharePoint allows an unauthenticated remote attacker to execute arbitrary code over the network. CISA added this to the KEV catalogue on July 16 with a remediation deadline of today — if your SharePoint deployment isn't patched, treat this as an emergency. Network-accessible SharePoint instances are the priority exposure.
⚠️ Actively exploited — CVE-2026-25089 & CVE-2026-39808 | Fortinet FortiSandbox | No CVSS published
Two separate OS command injection vulnerabilities in FortiSandbox (including FortiSandbox Cloud and PaaS) allow unauthenticated attackers to execute arbitrary commands via crafted HTTP requests. Both were added to the KEV on July 16. The fact that your sandbox environment — the thing meant to detonate suspicious payloads safely — is itself exploitable without credentials is particularly uncomfortable. Patch or isolate immediately.
⚠️ Actively exploited — CVE-2026-56164 | Microsoft SharePoint Server | No CVSS published
A missing authentication for critical function vulnerability allows an unauthenticated network attacker to elevate privileges on SharePoint Server. Paired with CVE-2026-58644 above, organisations running SharePoint are facing a compounded risk from two concurrent actively exploited flaws. Remediation deadline was July 17 — if you haven't acted, you're already overdue.
⚠️ Actively exploited — CVE-2026-46817 | Oracle E-Business Suite (Payments) | No CVSS published
An improper privilege management flaw in Oracle E-Business Suite allows an unauthenticated HTTP attacker to fully compromise Oracle Payments. The remediation deadline passed July 18. Any internet-facing Oracle EBS deployment handling payment data should be treated as potentially compromised if not yet patched.
⚠️ Actively exploited — CVE-2026-15409 & CVE-2026-15410 | SonicWall SMA1000 Appliances | No CVSS published
SonicWall's SMA1000 remote access appliances carry two vulnerabilities under active exploitation: an SSRF flaw (CVE-2026-15409) allowing unauthenticated requests to internal locations, and a code injection flaw (CVE-2026-15410) enabling OS command execution by an authenticated admin. Both had a July 17 remediation deadline. SMA devices sitting on the network perimeter with active exploitation confirmed is a high-priority patching scenario.
⚠️ Actively exploited — CVE-2026-56155 | Microsoft Active Directory Federation Services | No CVSS published
A privilege escalation vulnerability in AD FS allows a locally authenticated attacker to elevate privileges. Given AD FS's role in federated identity and SSO chains, local privilege escalation here can pivot quickly into broader identity compromise. Deadline: July 28 — but don't wait.
⚠️ Actively exploited — CVE-2023-4346 | KNX Protocol (Building Automation) | No CVSS published
A lockout mechanism flaw in KNX Protocol Connection Authorization Option 1 allows an attacker to purge all devices and set a BCU key, effectively bricking or locking connected building automation equipment. Operational technology and building management teams should audit KNX deployments for additional security options and network segmentation.
⚠️ Actively exploited — CVE-2008-4128 | Cisco IOS 12.4 | No CVSS published
Yes, 2008. A CSRF vulnerability in Cisco IOS 12.4 is currently being actively exploited, allowing remote attackers to execute privileged commands via crafted URIs. If you have IOS 12.4 devices anywhere in production in 2026, this is the sign you needed to decommission them.
CVE-2026-16095 / CVE-2026-16096 / CVE-2026-16097 | Shibby Tomato 1.28 | CVSS 8.8
Three separate memory corruption vulnerabilities — an out-of-bounds write in setup_conntrack, a stack-based buffer overflow in the webmon domain handler, and a stack overflow in the Scheduler Name Handler — all remotely exploitable on Shibby Tomato 1.28. This firmware has been superseded by FreshTomato for years; any device still running Shibby Tomato should be considered unpatched and unmaintainable. Migrate or replace.
CVE-2023-54366 & CVE-2024-58362 & CVE-2024-58366 | SurrealDB | CVSS 8.8 / 8.8 / 8.5
A cluster of SurrealDB vulnerabilities worth treating together: an insecure default of FULL table permissions on pre-1.0.1 versions (CVE-2023-54366), a bincode-encoded subquery injection via the RPC signin/signup API on pre-1.5.5 (CVE-2024-58362), and a format string vulnerability in the scripting engine on pre-1.1.1 that can lead to memory read or code execution (CVE-2024-58366). If you're running SurrealDB in any internet-exposed context, verify your version and review table-level permissions.
CVE-2026-11826 | OpenPLC v3 | CVSS 8.8
A heap-based buffer overflow in the getData() function of OpenPLC's Modbus master component can be triggered by an authenticated attacker through the web interface. OpenPLC is widely used in industrial control and research environments; authenticated access is often the only barrier here, making credential hygiene and network isolation critical mitigations.
CVE-2026-13445 | IBM Langflow OSS 1.0.0–1.10.1 | CVSS 8.1
An authenticated attacker can abuse the SaveToFile component to read and exfiltrate another user's uploaded files by specifying absolute paths to victim storage locations. In append mode, victim file contents are copied into the attacker's namespace. Multi-tenant Langflow deployments are directly at risk.
Headline News
Abbott Laboratories investigating dual cyber incidents and extortion claims
Abbott Laboratories has confirmed it is investigating two separate cybersecurity incidents. The first involves unauthorised access to legacy internal systems belonging to Exact Sciences, part of Abbott's Cancer Diagnostics business — a segment that handles highly sensitive patient diagnostic data. The second is a distinct extortion claim by threat actors alleging they have breached Abbott systems, though the company has not yet confirmed the second intrusion's scope. The healthcare sector's persistent attractiveness as a ransomware and extortion target stems from the combination of sensitive data, operational urgency, and historically fragmented IT estates from acquisitions — legacy systems absorbed through M&A are a recurring initial access vector worth scrutinising in any post-merger integration checklist.
TP-Link Kasa cameras silently leaked home GPS coordinates for six years
Researcher-published findings reveal that TP-Link Kasa EC71 cameras exposed precise GPS location data via an unauthenticated UDP service — with no credential required to query the device. The vulnerability persisted for approximately six years, meaning any network-adjacent attacker could silently retrieve the physical location of a home or premises running one of these cameras without the owner's knowledge. The technical specifics are stark: an unauthenticated UDP endpoint returning geolocation data is not an edge case oversight, it's a fundamental access control failure in a consumer device category that security teams often overlook during home-working security reviews. This is a useful reminder that IoT devices in remote-worker environments remain largely outside corporate security visibility, and the attack surface is more literal than most threat models assume.
Schrödinger's Feed
Singapore-based startup pQCee has closed a $3.9M seed round specifically targeting enterprise deployment of post-quantum cryptography — framed explicitly around "crypto-agility," the ability for systems to swap cryptographic algorithms without architectural overhaul. The funding reflects a genuine market inflection: PQC is no longer a standards exercise happening at NIST, it's entering procurement conversations at the enterprise and government level. Crypto-agility matters because the transition away from RSA and ECC won't be a single cutover — it'll be a multi-year coexistence period where hybrid classical/PQC schemes need to run simultaneously. Practitioners responsible for PKI, TLS infrastructure, or long-lived encrypted data archives should be tracking vendor PQC roadmaps now, not when the first "harvest now, decrypt later" attack surfaces publicly.
/dev/random
A data visualisation quietly making the rounds shows Stack Overflow question volume over time — and the cliff edge is not subtle. New question submissions, a reliable proxy for active developer engagement with the platform, begin a steep and sustained decline precisely when large language models became widely accessible in late 2022 and early 2023. It's not that developers stopped having questions; it's that they stopped asking them in public. The practical security implication nobody is talking about: Stack Overflow's historically rich, human-curated answer corpus was a significant training signal for the very models now replacing it, and if that public knowledge commons dries up, future model iterations may have a lot less grounded, peer-reviewed material to learn from. The ouroboros feeds itself, apparently.