Reports
AI-generated structured vendor updates
Microsoft July Patch Tuesday Hits Record 622 CVEs, AI Infrastructure Vulnerabilities Emerge as New Attack Surface
Microsoft's July 2026 Patch Tuesday addresses a record 622 CVEs, including three critical AI vulnerabilities: Copilot RCE (CVSS 9.6), Azure OpenAI EoP (CVSS 9.9), and M365 Copilot EoP (CVSS 9.3). The attack surface expands from OS to AI service infrastructure, signaling an era of AI-driven vulnerability inflation.
libssh2 CVE-2026-55200: Pre-auth RCE via Malicious Server, Attack Surface Shifts to Clients
A critical heap out-of-bounds write vulnerability (CVE-2026-55200, CVSS 9.2) in libssh2 allows a malicious SSH server to achieve pre-auth RCE on connecting clients. The flaw affects curl, Git, PHP, and many other projects statically linking the library, expanding the attack surface from servers to virtually any client application, including CI/CD, backup, and embedded systems.
AMD Critical RCE Vulnerability Disclosed After 124 Days, Sparks AI Infrastructure Security Crisis
Security researcher mr.bruh publicly disclosed a critical remote code execution (RCE) vulnerability in AMD processors after 124 days without a fix, with AMD refusing a $10,000 bounty. The flaw affects AI servers running AMD EPYC and Instinct, likened to a Log4j moment for AI infrastructure, forcing enterprises to reassess chip-level security response and supply chain risk.
Cisco ISE Critical: Multiple CVSS 9.9 Vulnerabilities Patched
Cisco issued urgent security advisory for multiple critical vulnerabilities in ISE and ISE-PIC. CVE-2026-20147 (CVSS 9.9) allows authenticated remote attackers to execute arbitrary commands and escalate to root. CVE-2026-20148 (CVSS 4.9) is a path traversal vulnerability. CVE-2026-20180/20186 also CVSS 9.9 RCE requiring only read-only admin credentials. No workarounds available - immediate patching required.