cyber exposure alerts
414 TopicsMicrosoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
On September 8, Microsoft released its September 2026 Patch Tuesday release which patched 964 CVEs with 104 rated critical and 860 rated as important. This update includes patches for two zero-days that were exploited in the wild. To date, this is the largest Patch Tuesday release ever, crushing the previous record from July’s 569 CVEs. CVE-2026-81963 is an elevation of privilege vulnerability affecting Windows Update Stack elevation of privilege vulnerability. It received a CVSSv3 score of 7.8 and was rated as important. According to Microsoft, this vulnerability was exploited in the wild as a zero-day. CVE-2026-85880 is a elevation of privilege vulnerability affecting Windows Advanced Local Procedure Call (ALPC). It received a CVSSv3 score of 7.8 and is rated as important. According to Microsoft, this vulnerability was exploited in the wild, making it the one of two zero-days addressed in the September Patch Tuesday release. Successful exploitation would allow an attacker to gain SYSTEM level privileges. This month’s update includes patches for: .NET .NET and Visual Studio ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Audio Video Control Transport Protocol Azure Arc Azure CycleCloud Azure HDInsights BranchCache Connected Devices Platform Service (Cdpsvc) Data Sharing Service Client GitHub Copilot and Visual Studio Code Graphic Fonts HID class driver IP Helper Internet Storage Name Service Kernel Streaming WOW Thunk Service Driver Microsoft Account Microsoft Authenticator Microsoft Azure Attestation service and Device Health Attestation Service Microsoft Azure CLI Microsoft COM for Windows Microsoft Dynamics 365 Microsoft Exchange Server Microsoft Graphics Component Microsoft Install Service Microsoft JScript Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office Publisher Microsoft Office SharePoint Microsoft Office Word Microsoft Standard XPS Microsoft Teams for Android Microsoft Trace Data Helper Microsoft UxTheme Library (uxtheme.dll) Microsoft WDAC OLE DB provider for SQL Microsoft WebP Image Extension Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows PDF Microsoft Windows SCSI Class System File Microsoft Windows Search Component Microsoft Windows Speech OpenSSH for Windows Power Automate Push Message Routing Service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Remote Desktop Gateway Service Role: DNS Server Role: Windows Fax Service SQL Server Skype for Business Spring Cloud Azure Storage Port Driver Telnet Client Virtual Hard Disk (VHD) Miniport Driver Visual Studio Visual Studio Code Volume Manager Driver Windows AF_UNIX Socket Provider Windows ALPC Windows Accounts Control Windows Ancillary Function Driver for WinSock Windows Audio Service Windows Authentication Methods Windows Autopilot Windows Bind Filter Driver Windows Biometric Service Windows BitLocker Windows Bluetooth Port Driver Windows Bluetooth Service Windows Boot Manager Windows Broadcast DVR User Service Windows Broker Infrastructure Service Windows CD-ROM Driver Windows Camera Frame Server Monitor Windows Cloud Files Mini Filter Driver Windows Compressed Folder Windows Connected User Experiences and Telemetry Windows Container Manager Service Windows Core Messaging Windows Credential Guard Windows Credential Providers Windows DCOM Server Windows DHCP Client Windows DHCP Server Windows DNS Windows DWM Core Library Windows Defender Firewall Service Windows Deployment Services Windows Device Association Broker service Windows Device Association Service Windows Devices Human Interface Windows Direct Show Windows Display Enhancement Service Windows Distributed File System (DFS) Windows Embedded Mode Service Windows Encrypting File System (EFS) Windows Enterprise App Management Windows Error Reporting Windows Event Logging Service Windows Failover Cluster Windows Fast FAT Driver Windows File History Service Windows GDI Windows GDI+ Windows Graphics Kernel Windows Group Policy Windows HTTP Print Provider Windows HTTP.sys Windows Hello Windows Host Guardian Service Windows Hyper-V Windows IKE Extension Windows IP Address Management (IPAM) Service Windows Image Acquisition Windows Imaging Component Windows Installer Windows Internet Connection Sharing (ICS) Windows Kerberos Windows Kernel Windows Kernel Mode Driver Windows Key Distribution Center Windows LDAP - Lightweight Directory Access Protocol Windows License Manager Windows Link Layer Topology Discovery Protocol Windows MIDI Service Module Windows Management Instrumentation Windows Management Services Windows Media Windows Media Player Windows Message Queuing Windows Message Queuing Queue Manager Windows Microsoft DirectMusic Windows Mobile Broadband Windows Modern Device Management (MDM) Windows Modern Execution Server Windows NDIS Windows NFS Portmapper Windows NTFS Windows Netlogon Windows Network Connection Broker Windows Network File System Windows Notification Windows OLE DB Windows Online Certificate Status Protocol (OCSP) Windows Overlay Filter Windows Paint Windows Partition Management Driver Windows Performance Monitor Windows Power Dependency Coordinator Windows PowerShell Windows Print Spooler Components Windows PrintWorkflowUserSvc Windows Program Compatibility Assistant Service Windows Push Notifications Windows RDP Client Windows RNDIS Windows Raw Image Extension Windows Registry Windows Remote Access Connection Manager Windows Remote Desktop Windows Remote Desktop Licensing Service Windows Remote Desktop Protocol Windows Remote Desktop Services Windows Resilient File System (ReFS) Windows Resilient File System (ReFS) Deduplication Service Windows Routing and Remote Access Service (RRAS) Windows SMB Client Windows SMB Server Windows SMB Server Network Transport Driver (srvnet.sys) Windows Schannel Windows Secure Boot Windows Secure Kernel Mode Windows Secure Socket Tunneling Protocol (SSTP) Windows Security Center Windows Security Health Service Windows Server Windows Services for NFS ONCRPC XDR Driver Windows Setup Files Cleanup Windows Shell Windows Smart Card Windows Spaceport.sys Windows Storage Windows Storage Management Provider Windows Storage Port Driver Windows Storage Spaces Controller Windows TCP/IP Windows Task Scheduler Windows Text Shaping Windows URL Moniker Windows USB Audio Class driver (usbaudio.sys) Windows USB Driver Windows USB Hub Driver Windows USB Mass Storage Class Driver Windows USB Video Driver Windows Universal Disk Format File System Driver (UDFS) Windows Universal Plug and Play (UPnP) Device Host Windows Update Stack Windows VHD miniport driver Windows VOLSNAP.SYS Windows Virtual Trusted Platform Module Windows Volume Manager Extension Driver Windows Volume Shadow Copy Windows Web Platform Storage Windows WebClient Service Windows Win32 Kernel Subsystem Windows Win32K Windows Wireless Networking Windows Wireless Wide Area Network Service Windows Work Folder Service Windows Work Folders Windows exFAT File System Windows iSCSI Windows iSCSI Target Service Winsock XBox Gaming Services Xbox For more information, please visit our blog.210Views0likes0CommentsStyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler. StyleSmuggler, also known as CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself. CVE Description CVSSv3 CVE-2026-75650 Adobe Commerce and Magento Open Source Remote Code Execution 10.0 On September 7, 2026, Adobe released Hotfix VULN-39341 to address CVE-2026-75650. Additional details can be found in Adobe's security bulletin APSB26-146. Adobe also recommends rotating the encryption key and all credentials it protects following a compromise, including admin passwords, REST, SOAP, and GraphQL integration tokens, OAuth client secrets, payment gateway API credentials, database credentials, SSH and deploy keys, and extension API keys. For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.46Views0likes0CommentsFrequently asked questions about the active threat to Siemens S7 Series PLCs
On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well. According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together a frequently asked questions (FAQ) blog to help security and OT teams understand the threats, the techniques involved and the mitigations offered by the authoring agencies. The advisory itself notes that ongoing PLC targeting is broader than Siemens alone and that all PLC owners and operators, regardless of vendor, should apply all relevant mitigations. For more information, please visit our blog.140Views1like0CommentsMicrosoft's August 2026 Patch Tuesday Addresses 398 CVEs (CVE-2026-68820)
On August 11, Microsoft released its August 2026 Patch Tuesday release which patched 398 CVEs with 42 rated critical, 355 rated as important and one rated as moderate. This update includes patches for three zero-days, including one that was exploited in the wild. CVE-2026-68820 is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day. CVE-2026-62832 is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.” CVE-2026-72971 is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.” This month’s update includes patches for: .NET .NET Core .NET Framework AMD Zen Active Directory Certificate Services (AD CS) Application Information Services Azure Active Directory Azure CycleCloud Azure Monitor Agent Azure Storage Explorer Capability Access Management Service (camsvc) Desktop Window Manager Dynamics Business Central GitHub Copilot and Visual Studio Code Microsoft Azure Attestation service and Device Health Attestation Service Microsoft COM for Windows Microsoft Defender for Endpoint Microsoft Digest Authentication Microsoft Dynamics 365 (on-premises) Microsoft Entra Connect Sync Microsoft Exchange Server Microsoft High Performance Computing (HPC) Pack Microsoft Identity Services Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Graphics Component Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office SharePoint Microsoft Office Word Microsoft OneDrive Microsoft PowerShell Microsoft PowerShell Core Microsoft QUIC Microsoft Remote Registry Service Microsoft Teams Mobile Microsoft Teams for Android Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows Search Component Power BI RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client User-Mode Power Service (UMPS) Virtual Hard Disk (VHD) Miniport Driver Visual Studio Code Visual Studio Code - Python extension Visual Studio Code CoPilot Chat Extension Windows Accessibility Infrastructure (ATBroker.exe) Windows Active Directory Windows Ancillary Function Driver for WinSock Windows Autopilot Windows Backup Engine Windows Bind Filter Driver Windows Cloud Files Mini Filter Driver Windows Common Log File System Driver Windows Container Isolation FS Filter Driver (unionfs.sys) Windows Cross Device Service Windows DHCP Client Windows DHCP Server Windows DNS Windows DWM Core Library Windows Defender Firewall Service Windows Deployment Services Windows Device Association Service Windows Display Enhancement Service Windows Encrypting File System (EFS) Windows Event Logging Service Windows GDI Windows GDI+ Windows Graphics Kernel Windows HTTP Protocol Stack Windows HTTP.sys Windows Hello Windows Hyper-V Windows Imaging Component Windows Installer Windows Kerberos Windows Kernel Windows Key Guard Windows LDAP - Lightweight Directory Access Protocol Windows LUAFV Windows License Manager Windows MIDI Service Module Windows Management Instrumentation Windows Management Services Windows Message Queuing Windows Modern Device Management (MDM) Windows NTFS Windows Narrator Braille Windows Network Address Translation (NAT) Windows Network Connection Broker Windows Network File System Windows Package Manager Windows Program Compatibility Assistant Service Windows Projected File System Windows Push Notifications Windows RPC API Windows Remote Access API Windows Remote Access Connection Manager Windows Remote Desktop Services Windows Remote Help Windows Remote Help Defense Windows Routing and Remote Access Service (RRAS) Windows SMB Client Windows SMB Server Windows Schannel Windows Secure Socket Tunneling Protocol (SSTP) Windows Sensor Data Service Windows Shell Windows Storage Windows Storage Port Driver Windows TCP/IP Windows Telephony Service Windows USB Driver Windows Universal Disk Format File System Driver (UDFS) Windows User Profile Service Windows Win32K Windows Wired AutoConfig Service Windows Work Folder Service Windows iSCSI Target Service Winlogon For more information, please visit our blog.323Views0likes0Commentswp2shell (CVE-2026-63030, CVE-2026-60137): FAQs about exploit chain in WordPress Core
On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com, a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain. wp2shell is a two-vulnerability exploit chain affecting WordPress Core. CVE Description CVSSv3 CVE-2026-63030 WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability 9.8 CVE-2026-60137 WordPress Core WP_Query author__not_in SQL Injection Vulnerability 5.9 Hexastrike began observing exploitation attempts in honeypots over the weekend following the July 17 disclosure and has since assisted with incident response in several confirmed attacks. Patchstack has also confirmed in-the-wild exploitation. Other researchers have reported seeing active exploitation in the wild. For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.167Views0likes0CommentsFrequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
On July 14, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an alert confirming active exploitation of three on-premises SharePoint Server vulnerabilities: CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164. The alert noted that these flaws had been used to gain unauthorized access to SharePoint deployments across all supported on-premises versions and flagged two additional high-risk vulnerabilities, CVE-2026-55040 and CVE-2026-58644, as not yet exploited but warranting immediate patching. However in an update to the security advisory on July 15, Microsoft confirmed CVE-2026-58644 has been exploited in the wild. Five Microsoft SharePoint Server vulnerabilities are covered in CISA’s alert: Four with confirmed active exploitation and one newly disclosed high-severity flaw that Microsoft assesses as “Exploitation More Likely” according to Microsoft's Exploitability Index. All five affect all supported on-premises SharePoint Server versions: Subscription Edition, 2019, and 2016. CVE Description CVSSv3 VPR CVE-2026-32201 Microsoft SharePoint Server Spoofing Vulnerability 6.5 7.2 CVE-2026-45659 Microsoft SharePoint Remote Code Execution Vulnerability 8.8 9.4 CVE-2026-56164 Microsoft SharePoint Server Elevation of Privilege Vulnerability 9.8 - NVD 5.3 - Microsoft 9.5 CVE-2026-55040 Microsoft SharePoint Server Security Feature Bypass Vulnerability 9.1 7.3 CVE-2026-58644 Microsoft SharePoint Server Remote Code Execution Vulnerability 9.8 7.9 *Please note: Tenable’s Vulnerability Priority Rating (VPR) scores are calculated nightly. This blog post was published on July 16 and reflects VPR at that time. For more information about these vulnerabilities, including the availability of patches and Tenable product coverage, please visit our FAQ blog.95Views0likes0CommentsCVE-2026-15409, CVE-2026-15410: SonicWall SMA 1000 zero-day vulnerabilities exploited in the wild
On July 14, SonicWall disclosed two vulnerabilities that are being exploited together in the wild: CVE Description CVSSv3 CVE-2026-15409 SonicWall SMA 1000 server-side request forgery (SSRF) vulnerability 10 CVE-2026-15410 SonicWall SMA 1000 remote code execution vulnerability (RCE) 7.2 While the advisory does not specify if they were exploited in tandem, together they form a fully remote, unauthenticated path to arbitrary OS command execution on affected appliances. CVE-2026-15409 is a SSRF vulnerability affecting the SMA 1000 Workplace interface. This flaw allows a remote, unauthenticated attacker to make network requests to locations of the attacker's choosing. In practice, SSRF on an internet-facing appliance can serve as a pivot, allowing an attacker to probe internal services, relay authentication material, or reach the AMC in a way that bypasses normal access controls. CVE-2026-15410 is a code injection vulnerability in the Appliance Management Console (AMC). The AMC is the administrative interface used to configure the appliance, manage users, set access policies, and monitor sessions. While this flaw does require the user to be authenticated, the potential chaining of these vulnerabilities makes the exploitation path possible without authentication These flaws have been exploited in the wild as zero-days. While SonicWall has not provided any details on attribution of which threat actors may be behind the attacks, several SonicWall vulnerabilities have been targeted in the past, including the exploitation of zero-days. For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.39Views0likes0CommentsMicrosoft’s July 2026 Patch Tuesday Addresses 569 CVEs
On July 7, Microsoft released its July 2026 Patch Tuesday release, the largest Patch Tuesday release to date. This update patched 569 CVEs with 56 rated critical, 510 rated as important and 3 rated as moderate. This month's update included fixes for three zero-days, two of which were exploited in the wild. CVE-2026-56155 is an elevation of privilege vulnerability affecting Active Directory Federation Services. It received a CVSSv3 score of 7.8 and is rated important. Microsoft notes that this flaw was exploited in the wild as a zero-day and is credited to researchers with the Microsoft Detection and Response Team (DART). Successful exploitation would allow an attacker to gain administrator privileges. CVE-2026-56164 is an elevation of privilege vulnerability in Microsoft SharePoint Server. It received a CVSSv3 score of 5.3 and is rated moderate. According to Microsoft, it was exploited in the wild as a zero-day. CVE-2026-50661 is a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.1 and is rated as important. It was publicly disclosed prior to a patch being available and assessed as “Exploitation Less Likely” according to Microsoft's Exploitability Index. While an exploit is public, the advisory notes that exploitation requires physical access to the target device. This month’s update includes patches for: .NET .NET Core .NET Framework ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Azure Active Directory Azure CycleCloud Azure Monitor Agent Azure Spring Apps Code Integrity DLL (ci.dll) Composite Image File System Driver Content Delivery Manager Desktop Window Manager Extensible Storage Engine (ESENT) GitHub Copilot and Visual Studio GitHub Copilot and Visual Studio Code Github Copilot HTTP/2 Microsoft 365 Copilot for iOS Microsoft Bing App for IOS Microsoft Copilot Microsoft Defender Microsoft Defender for Endpoint Microsoft Dynamics NAV Microsoft Edge for Android Microsoft Exchange Server Microsoft Fabric Data Warehouse Microsoft Graphics Component Microsoft Input Method Editor (IME) Microsoft Install Service Microsoft NAT Helper Components (ipnathlp.dll) Microsoft Office Microsoft Office Excel Microsoft Office OneNote Microsoft Office PowerPoint Microsoft Office SharePoint Microsoft Office Word Microsoft Printer Drivers Microsoft Surface Microsoft Windows Microsoft Windows App Store Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows Search Component Microsoft Windows Speech Microsoft XML Microsoft XML Core Services Minecraft Bedrock Dedicated Server Outlook Copilot Power BI Quality Windows Audio/Video Experience (QWAVE) service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Role: DNS Server SQL Server SQL Server ODBC driver Universal Plug and Play (upnp.dll) Virtual Hard Disk (VHD) Miniport Driver Visual Studio Visual Studio Code Window PC Manager Windows Active Directory Windows Admin Center Windows Ancillary Function Driver for WinSock Windows App Installer Windows AppX Deployment Service Windows Application Model Windows Audio Compression Manager (ACM) Windows Audio Service Windows Backup Engine Windows BitLocker Windows Bluetooth Port Driver Windows Bluetooth Service Windows Boot Loader Windows Brokering File System Windows Client-Side Caching (CSC) Service Windows Clip Service Windows Clipboard Server Windows Clipboard User Service Windows Cloud Files Mini Filter Driver Windows Common Log File System Driver Windows Connected User Experiences and Telemetry Windows Container Isolation FS Filter Driver (unionfs.sys) Windows CryptoAPI Windows Cryptographic Services Windows DHCP Client Windows DHCP Server Windows DNS Windows DWM Windows DWM Core Library Windows Data.dll Windows Devices Human Interface Windows DirectX Windows Domain Controller Windows Event Logging Service Windows FTP Service Windows File Explorer Windows File History Service Windows Filtering Platform (WFP) Windows GDI Windows GDI+ Windows Graphics Kernel Windows Group Policy Windows HTTP.sys Windows Hyper-V Windows Image Acquisition Windows Installer Windows Internal System User Profile Windows Internal Task Bar Windows Internet Key Exchange (IKE) Protocol Windows Kernel Windows Kernel Mode Driver Windows Kernel-Mode Drivers Windows Key Guard Windows LUAFV Windows Local Security Authority Subsystem Service (LSASS) Windows MIDI Service Module Windows Management Services Windows Media Windows Message Queuing Windows Message Queuing Queue Manager Windows NTFS Windows Narrator Braille Windows Netlogon Windows Network Address Translation (NAT) Windows Network File System Windows Network Policy Server SNMP Windows Notification Windows OLE Windows Operating Systems Windows Overlay Filter Windows PowerShell Windows Presentation Foundation (WPF) Windows Print Spooler Components Windows Projected File System Windows Push Notifications Windows Quality of Service (QoS) Packet Scheduler Windows RDP Windows RPC API Windows Redirected Drive Buffering Windows Remote Access Connection Manager Windows Remote Access Service Infrastructure Windows Remote Desktop Protocol Windows Remote Desktop Services Windows Remote Help Defense Windows Resilient File System (ReFS) Windows Routing and Remote Access Service (RRAS) Windows Runtime Windows SMB Windows SMB Server Windows SMB Server Network Transport Driver (srvnet.sys) Windows Schannel Windows Secure Boot Windows Secure Kernel Mode Windows Secure Socket Tunneling Protocol (SSTP) Windows Sensor Data Service Windows Server Windows Server Backup Windows Server Network driver Windows Server Update Service Windows Spaceport.sys Windows StateRepository API Windows Storage Windows Storage Spaces Direct Windows Subsystem for Linux Windows System Windows TCP/IP Windows Telephony Service Windows Terminal Windows Trusted Runtime Interface Driver Windows USB Audio Class driver (usbaudio.sys) Windows USB Driver Windows USB Hub Driver Windows USB Print Driver Windows USB Video Driver Windows Unified Consent System Windows Universal Disk Format File System Driver (UDFS) Windows User Interface Core Windows VMSwitch Windows Virtual Filtering Platform (VFP) Windows WalletService Windows Web Proxy Auto-Discovery Protocol (WPAD) Windows WebView Windows Win32K Windows Win32K - GRFX Windows Wireless Networking Windows Wireless Wide Area Network Service For more information, please visit our blog.200Views0likes0CommentsMicrosoft’s June 2026 Patch Tuesday Addresses 198 CVEs
On June 9, Microsoft released its June 2026 Patch Tuesday release which patched 198 CVEs with 32 rated as critical and 166 rated as important. This month's updates included three zero-days that were publicly disclosed prior to patches being made available. This Patch Tuesday release is the largest release since the Patch Tuesday program began, smashing the previous record of 167 CVEs in the October 2025 Patch Tuesday release. One of the zero-days is CVE-2026-50507, a security feature bypass vulnerability affecting Windows BitLocker. It received a CVSSv3 score of 6.8 and is rated as important. According to Microsoft, an attacker with physical access to the system could bypass the BitLocker Device Encryption feature in order to gain access to the device's encrypted data. This vulnerability appears to be the flaw known as Bitskrieg and a collaboration between Chaotic Eclipse (Nightmare Eclipse) and Jonas L. Chaotic Eclipse or Nightmare Eclipse has published several additional zero-days recently, including BlueHammer (CVE-2026-33825), GreenPlasma, MiniPlasma and YellowKey (CVE-2026-45585). This month’s update includes patches for: .NET ASP.NET Core Active Directory Domain Services Azure HorizonDB Azure Stack Edge Copilot Chat (Microsoft Edge) Function Discovery Service (fdwsd.dll) GitHub Copilot and Visual Studio Code HTTP/2 Linux MANA Driver M365 Copilot Microsoft Azure Attestation service and Device Health Attestation Service Microsoft Azure Kubernetes Service Microsoft Bing Microsoft Copilot Microsoft Defender for Endpoint Microsoft Dynamics 365 (on-premises) Microsoft Exchange Online Microsoft Exchange Server Microsoft Graph Microsoft Graphics Component Microsoft Kinect Microsoft Live Share Canvas SDK Microsoft Office Microsoft Office Click-To-Run Microsoft Office Excel Microsoft Office Project Microsoft Office SharePoint Microsoft Office Word Microsoft PC Manager Microsoft PowerToys Microsoft Teams for Android Microsoft UxTheme Library (uxtheme.dll) Microsoft Windows DNS Nuance PowerScribe Office for Android Remote Desktop Client Role: Windows Hyper-V UI Automation Manager (uiamanager.dll) Universal Plug and Play (upnp.dll) Visual Studio Code Windows Administrator Protection Windows Ancillary Function Driver for WinSock Windows Application Identity (AppID) Subsystem Windows BitLocker Windows Bluetooth Port Driver Windows Bluetooth Service Windows Boot Manager Windows Collaborative Translation Framework Windows Common Log File System Driver Windows Cryptographic Services Windows DHCP Client Windows DHCP Server Windows DWM Core Library Windows Deployment Services Windows HTTP.sys Windows Hotpatch Monitoring Service Windows Hyper-V Windows Internet (wininet.dll) Windows Kerberos Windows Kernel Windows Kernel-Mode Drivers Windows Mark of the Web (MOTW) Windows Media Windows NT OS Kernel Windows NTFS Windows Narrator Braille Windows Network Controller (NC) Host Agent Windows Performance Monitor Windows Program Compatibility Assistant Service Windows Projected File System Filter Driver Windows Push Notifications Windows RDP Windows SDK Windows Secure Boot Windows Shell Windows Storage Windows TCP/IP Windows Telephony Service Windows UEFI Windows Universal Disk Format File System Driver (UDFS) Windows Win32K - GRFX Winlogon For more information, please visit our blog.1.5KViews0likes1CommentMini Shai-Hulud: Frequently asked questions about the TeamPCP supply chain campaign
Between September 2025 and May 2026, a threat group tracked as TeamPCP has conducted a series of coordinated supply chain attacks across the npm and PyPI package ecosystems. The campaign, which the group calls Shai-Hulud, uses a self-propagating worm that steals developer and cloud credentials, then leverages those credentials to publish poisoned versions of additional packages. Each compromised continuous integration and continuous deployment (CI/CD) pipeline becomes a new distribution vector, enabling exponential spread. The current iteration is known as Mini Shai-Hulud. Tenable’s Research Special Operations Team (RSO) has compiled an FAQ blog to discuss what Mini Shai-Hulud is, how the campaign operates, who has been affected and what organizations should do to protect their software supply chains. For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.355Views0likes0Comments