Friday, July 3, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

🎯 SSCV Profile

See how vulnerabilities affect your specific environment

CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework

Risk scores will be adjusted based on your selected environment

Archived Security Brief

Friday's disclosures center on Microsoft cloud services and WordPress/WooCommerce commerce plugins, with several near-maximum-severity flaws affecting Azure OpenAI, Microsoft Entra, and Microsoft 365 Copilot. The brief covers 34 critical CVEs (up 21% from 28) and 78 high-priority CVEs (unchanged from the prior day). Notable entries include CVE-2026-45499 (CVSS 9.9) in Microsoft Azure OpenAI, CVE-2026-57100 (CVSS 9.9) in Microsoft Entra Provisioning Service, and CVE-2026-5524 (CVSS 9.8) in Divi Form Builder. The disclosures skew toward remote code execution and authentication weaknesses across cloud identity services and e-commerce plugins, exposing both enterprise SaaS deployments and self-hosted WooCommerce storefronts. No patches were available at disclosure time (0%), so teams should prioritize monitoring and compensating controls; two CVEs, in SimpleHelp and Microsoft Office SharePoint, have confirmed active exploitation.

  • Microsoft cloud services dominate today's critical set, with Azure OpenAI (CVE-2026-45499, CVSS 9.9) and Entra Provisioning Service (CVE-2026-57100, CVSS 9.9) leading by severity
  • 34 critical CVEs disclosed, a 21% increase from the prior day's 28
  • 78 high-priority CVEs, flat versus the prior day
  • Remote code execution and authentication flaws span cloud identity platforms and WooCommerce plugins, including Divi Form Builder (CVE-2026-5524, CVSS 9.8) and Novalnet Payment Gateway (CVE-2026-57677, CVSS 9.8)
  • Patch availability sits at 0% at disclosure, affecting Microsoft cloud services, Red Hat Enterprise Linux 10 (CVE-2026-14544), and multiple WordPress commerce plugins
  • 2 CVEs are under active exploitation, in SimpleHelp and Microsoft Office SharePoint

Immediate action: Prioritize Microsoft cloud identity and AI services (Azure OpenAI, Entra, 365 Copilot) and self-hosted WooCommerce storefronts running the affected Divi, Novalnet, and Printcart plugins for immediate review. With no vendor patches available at disclosure, apply vendor mitigations, restrict exposure, and increase monitoring on the actively exploited SimpleHelp and SharePoint issues until fixes ship.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation