Microsoft SharePoint Server · Google Chrome · SUSE Rancher
DAILY THREAT INTELLIGENCE BRIEFING Date: 2026-07-02 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
EXECUTIVE SUMMARY
CISA added CVE-2026-45659 (Microsoft SharePoint Server deserialization RCE) to the KEV catalog with a three-day remediation deadline of 2026-07-04 — immediate patching is required. Google Chrome received a major security update (150.0.7871.46) patching nearly 400 flaws, including multiple critical sandbox escapes. Progress Kemp LoadMaster (CVE-2026-8037) is now confirmed under active exploitation attempts. The FortiBleed credential-theft campaign has been formally linked to INC and Lynx ransomware operations. A large-scale Azure CLI password-spray campaign has compromised at least 78 Microsoft accounts across 81 million attempts.
CRITICAL VULNERABILITIES
NEW
CVE-2026-45659 (Microsoft SharePoint Server)
- Affected products: Microsoft SharePoint Server (versions subject to CISA KEV)
- Severity: Not yet assigned public CVSS; CWE-502 (Deserialization of Untrusted Data)
- EPSS: Not yet scored
- Technical detail: An authorized but low-privileged attacker can send crafted serialized data over the network to trigger arbitrary code execution on the SharePoint server. Deserialization flaws in SharePoint have historically been weaponized for webshell deployment and lateral movement. The network-exploitable attack vector and SharePoint’s ubiquity in enterprise environments make this a high-priority target. CISA added this to the KEV catalog on 2026-07-01, confirming active exploitation.
- Exploitation status: Actively exploited in the wild; CISA KEV confirmed.
- Remediation: Apply Microsoft’s patch immediately. CISA BOD 26-04 deadline is 2026-07-04. Restrict SharePoint access to authorized users and networks; review SharePoint server logs for anomalous deserialization activity or webshell indicators.
Google Chrome 150.0.7871.46 (Multiple CVEs — consolidated)
- Affected products: Google Chrome prior to 150.0.7871.46 (Windows, macOS, Linux, Android)
- Severity: CVSS 9.6 across multiple CVEs; several rated Critical by Chromium
- EPSS: Not yet scored
- Technical detail: Google released a major Chrome update patching approximately 400 vulnerabilities. The most severe are sandbox escape flaws in ANGLE (use-after-free: CVE-2026-14390, CVE-2026-14398, CVE-2026-14425; out-of-bounds write: CVE-2026-14397; type confusion: CVE-2026-14423), Dawn (use-after-free: CVE-2026-14417, CVE-2026-14424; out-of-bounds read/write: CVE-2026-14420), Skia (use-after-free: CVE-2026-14419; integer overflow: CVE-2026-14387), Tint (out-of-bounds write: CVE-2026-14392; type confusion: CVE-2026-14423), and V8 (uninitialized use: CVE-2026-14405; inappropriate implementation: CVE-2026-14407; use-after-free: CVE-2026-14432). Multiple flaws are rated Critical by Chromium and allow a remote attacker to escape the browser sandbox via a crafted HTML page. No exploitation confirmed at this time.
- Exploitation status: No confirmed in-the-wild exploitation; attack surface is broad given Chrome’s deployment scale.
- Remediation: Update Chrome to 150.0.7871.46 or later across all managed endpoints. Enable automatic updates where policy permits. Chromium-based browsers (Edge, Brave, etc.) should be updated as vendor patches become available.
CVE-2026-44939 (SUSE Rancher — command injection)
- Affected products: SUSE Rancher 2.10.0–2.10.11, 2.11.0–2.11.13, 2.12.0–2.12.9, 2.13.0–2.13.5, 2.14.0–2.14.1
- Severity: CVSS 9.4
- EPSS: 1.11 (note: value exceeds 1.0, likely a data artifact; treat as very high exploitation probability)
- Technical detail: Rancher fails to sanitize a YAML parameter before passing it to a shell command, enabling an authenticated attacker with project-level access to inject arbitrary OS commands on the Rancher management server. In Kubernetes environments, this can lead to full cluster compromise. The flaw affects all actively supported Rancher branches. Patched versions are 2.10.12, 2.11.14, 2.12.10, 2.13.6, and 2.14.2.
- Exploitation status: No confirmed exploitation; high EPSS and low authentication bar warrant urgent treatment.
- Remediation: Upgrade Rancher to the patched release for your branch. Restrict Rancher management access to trusted administrators and internal networks.
STATUS CHANGE
CVE-2026-8037 (Progress Kemp LoadMaster)
- Active exploitation attempts now confirmed by eSentire TRU. Full entry in yesterday’s report. Treat as actively exploited; patch or isolate management interface immediately.
ONGOING
- CVE-2026-48558 (SimpleHelp): CISA KEV deadline was 2026-07-02 — organizations not yet patched are in breach; hunt for Djinn Stealer indicators.
- CVE-2026-46817 (Oracle E-Business Suite): actively exploited by ShinyHunters; over 900 exposed instances identified; patch immediately.
- CVE-2026-10109 (IBM Db2): pre-auth DRDA RCE; patch and restrict port 50000.
- Adobe ColdFusion CVE-2026-48283 et al.: CVSS 10.0 unauthenticated RCE cluster; apply patches if not yet done.
- BlueHammer (Windows Defender privilege escalation): actively exploited by ransomware gangs; ensure patch applied.
- CVE-2026-41052 (SUSE Rancher privilege escalation): patch to fixed release.
- CVE-2026-42208 (LiteLLM), CVE-2026-55200 (libssh2), CVE-2026-56290 (Joomla Page Builder CK): patch actions remain open.
EUROPEAN ADVISORIES
BSI published a large batch of updated advisories on 2026-07-01. The majority are updates to existing Linux Kernel advisories (WID-SEC-2025-0844, -1114, -1522, -1653, -1665, -1898, -2040, -2099, -2579, -2868, -2920, -2929, WID-SEC-2026-0086, -0215, -0774, -0861) covering DoS, memory corruption, privilege escalation, and unspecified impacts across multiple kernel versions. Apply current distribution-provided kernel updates. Additional updated advisories cover NGINX and NGINX Plus (WID-SEC-2026-0860, -1661: DoS, potential code execution), Red Hat OpenShift Container Platform / gRPC-Go (WID-SEC-2026-1136: security bypass), IBM WebSphere Application Server (WID-SEC-2026-1762: security bypass and code execution), GNU libc (WID-SEC-2026-1190: file manipulation, DoS — critical), and vm2 (WID-SEC-2026-1583: RCE, security bypass, data manipulation — critical). Apply vendor patches for all affected components.
WID-SEC-2026-2162 (UltraVNC) — NEW: BSI rates this advisory high. Multiple vulnerabilities allow a remote unauthenticated attacker to execute arbitrary code, disclose sensitive information, manipulate data, and cause DoS. UltraVNC is used for remote desktop access in enterprise and support environments. Apply available patches and restrict VNC access to trusted networks.
WID-SEC-2026-2161 (LiteLLM) — NEW: Multiple vulnerabilities allow security bypass, arbitrary code execution, and file manipulation. LiteLLM is increasingly deployed as an AI gateway in enterprise environments. Apply available patches; cross-reference with CVE-2026-42208 (CISA KEV, previously reported).
Heise Security reported that Citrix NetScaler ADC and NetScaler Gateway received patches for six vulnerabilities enabling DoS. OpenWRT received patches for multiple critical root-level vulnerabilities. HCL BigFix patched six flaws including man-in-the-middle attack vectors. Apply vendor updates for all three products.
ACTIVE THREATS AND CAMPAIGNS
NEW — FortiBleed Campaign Linked to INC and Lynx Ransomware The FortiBleed credential-theft campaign, which harvested Fortinet device credentials at scale, has been formally attributed to the INC and Lynx ransomware operations. Stolen credentials are being used to establish initial access for ransomware deployment. Organizations that use Fortinet products should immediately audit for credential exposure, rotate all Fortinet management and VPN credentials, review VPN and firewall access logs for unauthorized sessions, and verify no persistent access has been established.
NEW — SEO-Poisoned Software Sites Deploying AsyncRAT via ScreenConnect Kaspersky identified a large-scale, multi-domain, multi-language campaign distributing malicious installer archives via SEO-poisoned websites spoofing popular software (OBS Studio, DNS Jumper, DS4Windows, Bandicam). Installers deploy ScreenConnect as a legitimate-looking remote access tool, then use it to execute AsyncRAT. The campaign’s multi-language scope suggests broad geographic targeting including European users. Block unauthorized ScreenConnect deployments via application control; alert on ScreenConnect installations not provisioned by IT.
NEW — VEIL#DROP: PureLogs Stealer via Blogger-Hosted Delivery Chain Securonix identified a multi-stage campaign (VEIL#DROP) using Blogger pages as a staging platform to deliver PureLogs information stealer. Initial access is via spear-phishing or drive-by compromise. The use of a legitimate Google-hosted platform for payload staging complicates URL-based blocking. Hunt for PureLogs indicators; review proxy logs for unusual Blogger content downloads.
NEW — Ousaban Banking Trojan Targeting Spanish and Portuguese Bank Users Fortinet FortiGuard Labs identified an active campaign distributing the Ousaban banking trojan against Windows users in Spain and Portugal. The campaign uses phishing PDFs disguised as corrupted files, performs geolocation checks to confirm the target is in the Iberian region, and steganographically hides the payload inside an image. European financial institutions and their customers in Spain and Portugal should be alerted. Block suspicious PDF lures and monitor for steganographic payload delivery patterns.
NEW — Azure CLI Password-Spray Campaign (81M+ Attempts) Huntress identified an ongoing automated password-spray campaign targeting Microsoft Azure CLI environments, originating from IPv6 range 2a0a:d683::/32 (LSHIY LLC, AS32167). Between June 12 and June 26, over 81 million login attempts were made, compromising at least 78 accounts. Enable MFA on all Azure accounts, enforce Conditional Access policies, and block or monitor the identified IPv6 range. Review Azure sign-in logs for spray patterns.
ONGOING — RustDuck Botnet: expanding via routers and servers; ensure firmware is current and default credentials are changed. ONGOING — Phantom Squatting (AI-hallucinated domains): enforce package integrity verification in development pipelines. ONGOING — ClickFix API-driven malware delivery: API-served polymorphic payloads active; user awareness and script execution controls recommended. ONGOING — ShinyHunters Oracle EBS campaign: multiple confirmed victims; patch and monitor.
SECURITY NEWS AND CONTEXT
Argo CD repo-server unpatched RCE: Synacktiv disclosed an unauthenticated RCE flaw in Argo CD’s repo-server component (no CVE assigned yet) reachable from internal networks that can lead to full Kubernetes cluster takeover. No fix is available; restrict repo-server network exposure as an interim measure.
Scattered Spider extradition: A 19-year-old suspect (Peter Stokes) was extradited from Finland to the U.S. to face charges of conspiracy, computer intrusion, and fraud linked to the Scattered Spider group. No direct operational impact, but the group remains active.
DHS HSIN breach confirmed: The Department of Homeland Security confirmed a breach of the Homeland Security Information Network (HSIN), a sensitive federal and private-sector information-sharing platform. Scope and attribution are under investigation.
Adobe ColdFusion and Campaign Classic: Seven CVSS 10.0 flaws patched; covered in Critical Vulnerabilities (yesterday’s report). Apply patches if not yet done.
RECOMMENDED ACTIONS
- Patch Microsoft SharePoint Server immediately (CVE-2026-45659) — CISA KEV deadline 2026-07-04; actively exploited deserialization RCE.
- Update Google Chrome to 150.0.7871.46 across all endpoints — multiple critical sandbox escape vulnerabilities patched.
- Upgrade SUSE Rancher to patched release (CVE-2026-44939) — command injection with very high exploitation probability; restrict management access.
- Rotate all Fortinet credentials immediately — FortiBleed campaign confirmed feeding INC and Lynx ransomware operations; audit for unauthorized access.
- Block unauthorized ScreenConnect deployments and alert on new installations — SEO-poisoned campaign delivering AsyncRAT via ScreenConnect.
- Enable MFA and Conditional Access on all Azure accounts; monitor for spray patterns from 2a0a:d683::/32 (CVE-independent credential attack).
- Restrict Argo CD repo-server network exposure — unpatched unauthenticated RCE with no fix available; limit to trusted internal segments only.
- Apply UltraVNC patches (WID-SEC-2026-2162) and restrict VNC to trusted networks.
- Alert Spanish and Portuguese user populations to Ousaban banking trojan phishing PDFs; update email security rules accordingly.
- Continue remediation of previously reported items: CVE-2026-48558 (SimpleHelp — deadline passed), CVE-2026-46817 (Oracle EBS), CVE-2026-8037 (Kemp LoadMaster — now actively exploited), Adobe ColdFusion, BlueHammer (Windows Defender), IBM Db2, LiteLLM, libssh2, Joomla Page Builder CK.