0dayNews — Vulnerability & Exploit News
Known Exploited Vulnerabilities
Microsoft SharePoint Server deserialization remote code execution
A high-severity deserialization-of-untrusted-data flaw in on-premises Microsoft SharePoint Server that leads to remote code execution. Patched by Microsoft in the May 2026 security update; added to the CISA Known Exploited Vulnerabilities catalog on July 2, 2026 after confirmed exploitation in the wild.
Microsoft Defender Antimalware Platform Local Privilege Escalation (BlueHammer)
A local privilege escalation flaw in Microsoft Defender Antimalware Platform caused by insufficient access-control granularity. An authorized local attacker can elevate privileges. Patched in April 2026 Patch Tuesday, added to the CISA KEV catalog on 2026-04-22, and confirmed by CISA in July 2026 as weaponized in ransomware attacks. Disclosed as a zero-day by researcher "Chaotic Eclipse" (aka Nightmare-Eclipse) alongside two sibling flaws — RedSun and UnDefend — as a protest of Microsoft's disclosure coordination.
Palo Alto Networks PAN-OS GlobalProtect Command Injection Zero-Day
A command-injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS allows an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Exploited in the wild as a zero-day before a patch was available.
Ivanti Connect Secure / Policy Secure Authentication Bypass
An authentication-bypass vulnerability in the web component of Ivanti Connect Secure and Policy Secure gateways allows a remote attacker to access restricted resources without credentials. Chained with CVE-2024-21887 for full remote code execution in real-world attacks.
Ivanti Connect Secure / Policy Secure Command Injection
A command-injection vulnerability in the web components of Ivanti Connect Secure and Policy Secure lets an authenticated administrator send specially crafted requests to execute arbitrary commands. Chained with CVE-2023-46805's auth bypass for unauthenticated RCE in the wild.
Cisco IOS XE Web UI Privilege Escalation Zero-Day
A privilege-escalation vulnerability in the Web UI feature of Cisco IOS XE Software allows a remote, unauthenticated attacker to create an account with privilege level 15 (full admin) access, enabling full device takeover. Exploited at mass scale against tens of thousands of devices.
From the desk

Metasploit's July 3 drop: SMB-to-Meterpreter and Peyara RCE — the detection tune
Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

vCenter's Unrestricted-Upload Bug: A Reminder That Management Planes Shouldn't Face the Internet
CVE-2021-21972 let unauthenticated attackers execute code with root privileges on VMware vCenter Server — and internet scans found tens of thousands of instances exposed anyway, against VMware's own guidance.
CISA confirms BlueHammer Defender LPE is being used in ransomware attacks
CVE-2026-33825, the Microsoft Defender local privilege escalation disclosed as a zero-day by 'Chaotic Eclipse' in April, is confirmed weaponized in ransomware. Patched. Ransomware family unnamed.

PolinRider: North Korean actors seed 108 malicious packages across four ecosystems
The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

Spring4Shell: Why This One Needed Careful Triage, Not Panic
CVE-2022-22965 leaked publicly before VMware's patch was ready — but unlike Log4Shell, exploitation required a specific combination of conditions that made blanket panic the wrong response.

IGA was built around employment records. Agents don't have those.
A contributed piece to The Hacker News from Orchid Security lays out where the joiner-mover-leaver model quietly fails for AI agents. Vendor-adjacent, but the gap analysis holds.
This week's SITREP
Week in Review: DPRK Broke Supply Chains, an LLM Ran Ransomware
Three DPRK supply-chain campaigns in parallel, JadePuffer's LLM-agent ransomware milestone, and yet another week of unpatched edge RCEs across Kemp, FatFs, and Cisco Unified CM — Kilobaud on what this collection of stories has in common.




