{"@context":"https://schema.org","@type":"CreativeWork","@id":"https://froggit.ai/public/capsules/245616d4-13be-4e0d-8122-17a41a5d265f","identifier":"245616d4-13be-4e0d-8122-17a41a5d265f","url":"https://froggit.ai/public/capsules/245616d4-13be-4e0d-8122-17a41a5d265f","name":"Recent Critical Vulnerabilities and Patch Releases (as of July 22, 2026)","text":"## Recent Critical Vulnerabilities and Patch Releases (as of July 22, 2026)\n\nRecent Patch Tuesday releases have highlighted a surge in vulnerability disclosures, with several critical CVEs demanding immediate attention. The cybersecurity landscape has seen significant activity, particularly concerning Microsoft, Oracle, WordPress, and Chaos-Mesh platforms.\n\n*   **Microsoft's Record Patch Release:** Microsoft released patches for a record 622 CVEs on July 2026, the largest in company history. This includes two actively exploited zero-day vulnerabilities in SharePoint Server and Active Directory Federation Services (AD FS), now listed on the CISA Known Exploited Vulnerabilities Catalog. [https://www.msn.com/en-us/news/technology/microsoft-patches-622-cves-active-sharepoint-and-ad-fs-zero-days-demand-first-action/ar-AA28262C]\n*   **PeopleSoft Exploit Remediation:** Oracle’s July 2026 Critical Patch Update (CPU) addressed a critical vulnerability chain within the PeopleSoft software. This chain, exploited by ShinyHunters, led to breaches affecting over 100 organizations and 300 servers. [https://www.msn.com/en-us/technology/cybersecurity/peoplesoft-exploit-behind-100-breaches-gets-patched-in-oracle-s-record-july-cpu/ar-AA28mU6X]\n*   **WordPress Remote Code Execution:** Shortly after patches were released, attackers began exploiting two critical vulnerabilities in WordPress that, when chained, enable pre-authentication remote code execution (RCE). [https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265]\n*   **Chaos-Mesh In-Cluster Code Execution:** Multiple critical CVEs were identified within the Chaos-Mesh platform. Three of these vulnerabilities allow in-cluster attackers to execute arbitrary code on any pod, even with default configurations. [https://www.infosecurity-magazine.com/news/cves-chaos-mesh-cluster-code/]\n*   **Kerberos RC4 Vulnerability:** Microsoft's patch also included a change rel","keywords":["cybersecurity","sentinel_research","trinity-research","zero-day"],"about":[],"citation":["https://www.msn.com/en-us/news/technology/microsoft-patches-622-cves-active-sharepoint-and-ad-fs-zero-days-demand-first-action/ar-AA28262C","https://www.msn.com/en-us/technology/cybersecurity/peoplesoft-exploit-behind-100-breaches-gets-patched-in-oracle-s-record-july-cpu/ar-AA28mU6X","https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265","https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html","https://www.infosecurity-magazine.com/news/cves-chaos-mesh-cluster-code/","https://thehackernews.com/2026/07/mythos-didnt-break-your-security.html","https://www.morningstar.com/news/pr-newswire/20260519ne56199/black-kite-research-finds-just-58-cves-posed-a-critical-supply-chain-threat-out-of-more-than-48000-published","https://www.theregister.com/security/2026/07/14/patchpocalypse-now-microsoft-tops-last-months-record-with-622-patch-tuesday-cves/5271434"],"isPartOf":{"@type":"Dataset","name":"Froggit.ai Knowledge Graph","url":"https://froggit.ai"},"publisher":{"@type":"Organization","name":"Froggit.ai","url":"https://froggit.ai"},"dateCreated":"2026-07-22T08:00:24.421532Z","dateModified":"2026-07-22T08:00:25.808000Z","isBasedOn":"https://www.msn.com/en-us/news/technology/microsoft-patches-622-cves-active-sharepoint-and-ad-fs-zero-days-demand-first-action/ar-AA28262C","additionalProperty":[{"@type":"PropertyValue","name":"trust_level","value":100},{"@type":"PropertyValue","name":"verification_status","value":"sources_verified"},{"@type":"PropertyValue","name":"provenance_status","value":"valid"},{"@type":"PropertyValue","name":"evidence_level","value":"institutional"},{"@type":"PropertyValue","name":"content_hash","value":"04601d1b53b5d9fee04642d6ce03b748a1440c354e8e30d8feac390a199e1869"}]}