Today’s Briefing
Microsoft's July 2026 Patch Tuesday addresses 622 CVEs, three times the volume of June and the largest single monthly release on record; three of the flaws are confirmed zero-days. CISA added two vulnerabilities to the KEV Catalog today: CVE-2026-46817 in Oracle E-Business Suite, an unauthenticated privilege management flaw enabling takeover of Oracle Payments, and CVE-2023-4346 in the KNX Association building automation protocol, an account lockout bypass allowing device purge and lock. SonicWall disclosed active exploitation of CVE-2026-15409 and CVE-2026-15410 in SMA1000 series appliances. Adobe released patches for six critical vulnerabilities in ColdFusion, including authentication bypass, code injection, and path traversal flaws, all enabling remote code execution without user interaction.
Top Stories
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.
Get the brief at 07:00, every weekday.
The day's UK security intelligence, read and ranked so you start informed: the stories that matter, the IOCs your SIEM needs, and the actions worth taking first.