Skip to main content

Windows Remote Desktop Protocol Server Unauthenticated RCE Patched in July 2026 Patch Tuesday (CVE-2026-56190)

Scope: Windows Server 2019, 2022, 2025 and Windows 10/11 (All Builds with RDP Server Enabled)

Microsoft SharePoint Server Deserialization RCE Exploited as Zero-Day, Now Added to CISA KEV (CVE-2026-58644 / CVE-2026-50522)

Scope: Microsoft SharePoint Server 2016, 2019, and Subscription Edition (All On-Premises Deployments

Microsoft AD FS Zero-Day Actively Exploited to Grant Admin Privileges, Patched in Record July 2026 Patch Tuesday (CVE-2026-56155)

Scope: Microsoft Active Directory Federation Services (Windows Server 2019, 2022, 2025 with AD FS Ro

JetBrains IntelliJ IDEA Critical Path Traversal in Workspace ID Handling Leads to Code Execution (CVE-2026-59792)

Scope: JetBrains IntelliJ IDEA Versions Before 2026.1.4 and Before 2026.2

vLLM OpenAI-Compatible API Server Authentication Bypass Allows Unauthenticated AI Inference Access (CVE-2026-48746)

Scope: vLLM Versions 0.3.0 through 0.21.x (Fixed in 0.22.0)

Ultimate Member WordPress Plugin Unauthenticated Blind SQL Injection Exposes Database Contents (CVE-2026-15290)

Scope: Ultimate Member WordPress Plugin Versions up to and Including 2.10.1

WPFunnels WooCommerce Plugin Unauthenticated Log Injection Leads to Remote Code Execution (CVE-2026-14345)

Scope: WPFunnels Funnel Builder for WooCommerce Plugin Versions up to and Including 3.12.7

Subscribe to Advisories