Saturday, July 25, 2026 Archive

Archived Security Snapshot

Critical vulnerabilities, curated daily for security professionals

Archived Security Brief

Microsoft cloud infrastructure dominates Saturday's disclosures, with maximum-severity flaws in Azure Kubernetes Service (CVE-2026-56163), Azure Key Vault (CVE-2026-62825), and Azure App Service for Linux (CVE-2026-58630) all rated CVSS 10. The day brought 42 critical CVEs, up 11% from the prior day's 38, and 124 high-priority CVEs, a 55% increase from 80. Additional CVSS 10 issues affect Azure DNS (CVE-2026-58275), Microsoft Purview Data Governance (CVE-2026-57106), and Exchange Online (CVE-2026-56191), while Microsoft 365 Copilot (CVE-2026-50517) reaches CVSS 9.9. Beyond the Microsoft cluster, industrial control systems from Loytec (CVE-2026-12503, CVSS 9.2) and a Linux kernel flaw (CVE-2026-64046, CVSS 9.8) broaden the exposure across enterprise and operational technology. Six vulnerabilities carry confirmed active exploitation, including WordPress Core, Check Point SmartConsole, and Microsoft SharePoint; vendor patch details were not yet consolidated at disclosure, so teams should track advisories and apply cloud-side and vendor fixes as they publish.

  • Microsoft cloud services account for eight of the top critical CVEs, including CVSS 10 flaws in Azure Kubernetes Service, Azure Key Vault, Azure DNS, and Exchange Online
  • 42 critical CVEs disclosed, an 11% increase over the prior day's 38
  • 124 high-priority CVEs disclosed, a 55% increase over the prior day's 80
  • Microsoft 365 Copilot (CVE-2026-50517, CVSS 9.9) and Microsoft Purview Data Governance (CVE-2026-57106, CVSS 10) extend risk into data governance and AI assistant tooling
  • Industrial and infrastructure exposure includes Loytec building-automation controllers (CVE-2026-12503, CVSS 9.2) and a Linux kernel flaw (CVE-2026-64046, CVSS 9.8)
  • Six CVEs show confirmed active exploitation, spanning WordPress Core, Check Point SmartConsole, and Microsoft SharePoint

Immediate action: Prioritize Microsoft Azure and Microsoft 365 environments, where multiple CVSS 10 flaws affect Kubernetes Service, Key Vault, App Service, DNS, and Exchange Online; many of these are service-side and may be mitigated by Microsoft, so verify tenant configuration and monitor the Microsoft Security Response Center for update status. Separately, patch actively exploited systems including WordPress Core, Check Point SmartConsole, and Microsoft SharePoint as vendor fixes become available, and review Loytec controllers and Linux kernel exposure in operational environments.

How to read this brief

CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).

Exploitability — how hard the flaw is to attack, read from the CVSS vector:

  • Network / Adjacent / Local / Physical — how close an attacker must get. Network means reachable over the internet.
  • No / Low / High privileges — the access they need first. No privileges means no login required.
  • No interaction / User interaction — whether a victim has to do something (open a file, click a link). No interaction means fully automatable.

The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.

Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.

EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.

💡 Tip: Swipe CVE cards left to ⭐ star, right to ❌ remove

Section Navigation