Friday, July 3, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Friday's disclosures center on Microsoft cloud services and WordPress/WooCommerce commerce plugins, with several near-maximum-severity flaws affecting Azure OpenAI, Microsoft Entra, and Microsoft 365 Copilot. The brief covers 34 critical CVEs (up 21% from 28) and 78 high-priority CVEs (unchanged from the prior day). Notable entries include CVE-2026-45499 (CVSS 9.9) in Microsoft Azure OpenAI, CVE-2026-57100 (CVSS 9.9) in Microsoft Entra Provisioning Service, and CVE-2026-5524 (CVSS 9.8) in Divi Form Builder. The disclosures skew toward remote code execution and authentication weaknesses across cloud identity services and e-commerce plugins, exposing both enterprise SaaS deployments and self-hosted WooCommerce storefronts. No patches were available at disclosure time (0%), so teams should prioritize monitoring and compensating controls; two CVEs, in SimpleHelp and Microsoft Office SharePoint, have confirmed active exploitation.

  • Microsoft cloud services dominate today's critical set, with Azure OpenAI (CVE-2026-45499, CVSS 9.9) and Entra Provisioning Service (CVE-2026-57100, CVSS 9.9) leading by severity
  • 34 critical CVEs disclosed, a 21% increase from the prior day's 28
  • 78 high-priority CVEs, flat versus the prior day
  • Remote code execution and authentication flaws span cloud identity platforms and WooCommerce plugins, including Divi Form Builder (CVE-2026-5524, CVSS 9.8) and Novalnet Payment Gateway (CVE-2026-57677, CVSS 9.8)
  • Patch availability sits at 0% at disclosure, affecting Microsoft cloud services, Red Hat Enterprise Linux 10 (CVE-2026-14544), and multiple WordPress commerce plugins
  • 2 CVEs are under active exploitation, in SimpleHelp and Microsoft Office SharePoint

Immediate action: Prioritize Microsoft cloud identity and AI services (Azure OpenAI, Entra, 365 Copilot) and self-hosted WooCommerce storefronts running the affected Divi, Novalnet, and Printcart plugins for immediate review. With no vendor patches available at disclosure, apply vendor mitigations, restrict exposure, and increase monitoring on the actively exploited SimpleHelp and SharePoint issues until fixes ship.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation