Microsoft Patches 570 Flaws, EY Breach, WordPress RCE, AI Threats

Microsoft patches 570 flaws, EY breach exposes client data, and WordPress RCE threatens millions of sites.

By Central
July 2026 security roundup: Microsoft Patch Tuesday, EY breach, and WordPress RCE vulnerability.
Highlights
  • Microsoft's July 2026 Patch Tuesday fixed 570 vulnerabilities, including two zero-days already exploited in the wild.
  • A critical WordPress RCE vulnerability called wp2shell threatens over 500 million sites with unauthenticated takeover.
  • Ernst & Young disclosed a data breach exposing client tax records from its IT support ticket platform.

The July 2026 security cycle has delivered a stark reminder that no layer of the technology stack is immune to compromise. Microsoft’s Patch Tuesday alone addressed roughly 570 vulnerabilities, including two zero-days already exploited in the wild, while critical flaws in WordPress, enterprise identity systems, and even AI-integrated browser tools signal that attackers are accelerating their timelines from disclosure to weaponization. This roundup covers the most significant developments of the past week, from the Ernst & Young data breach affecting client tax records to novel attack techniques targeting large language models and developer workflows.

Microsoft Patch Tuesday: 570 Flaws Fixed, Two Zero-Days Under Active Exploitation

Microsoft’s July 2026 Patch Tuesday closed roughly 570 vulnerabilities, a volume that underscores the scale of the modern attack surface. Two zero-days were already being exploited in active campaigns: CVE-2026-56164 in SharePoint Server and CVE-2026-56155 in Active Directory Federation Services. A publicly disclosed BitLocker bypass bug was also addressed. Enterprises running on-premises SharePoint or federated authentication should treat these patches as urgent, given that weaponized exploit code often follows disclosure within days.

Critical WordPress RCE Flaw Exposes Over 500 Million Sites

A pre-authentication remote code execution vulnerability tracked as CVE-2026-60137 and CVE-2026-63030, and dubbed wp2shell, puts more than 500 million WordPress sites at risk of unauthenticated takeover. The flaw leverages a REST API batch-route SQL injection chain, meaning an attacker with no credentials can execute arbitrary commands on the server. Site owners should verify they are running the latest patched version and audit any REST API endpoints exposed to the internet.

Active Directory and Windows Zero-Day Activity

Beyond the Microsoft Patch Tuesday fixes, a proof-of-concept called LegacyHive was released by researcher Nightmare-Eclipse. The exploit targets the Windows User Profile Service, allowing a standard user to load another account’s registry hive, and it reportedly works even on fully patched July 2026 systems. Separately, a zero-day flaw in Active Directory-related services is being exploited in the wild, putting enterprise identity infrastructure at risk. Organizations should monitor authentication logs for unusual service account activity and enforce strict privilege boundaries.

Ernst & Young Discloses Client Tax Data Breach

Ernst & Young confirmed that an unauthorized third party accessed its IT support ticket platform between March 28 and April 12, 2026, downloading client tax and investment-holding documents. The breach was detected nearly three weeks after initial access, raising questions about detection latency in professional services environments. Affected clients should assume their financial and tax data was exposed and implement enhanced monitoring for phishing attempts or fraudulent filings.

Malicious Chrome Extension Removed After Exfiltrating Data from Millions of Users

The ModHeader extension, which had 1.6 million installs, was removed from the Chrome and Edge Web Stores after researchers discovered dormant code capable of encrypting and uploading users’ browsing history to an external server. This incident reinforces the risk of browser extensions with broad permission sets. Users should audit their installed extensions, remove any that request unnecessary permissions, and consider using a dedicated browser profile for sensitive activities.

AI Systems Emerge as an Active Attack Surface

This week’s disclosures also highlight a growing trend: AI-integrated tools are being actively probed by adversaries. A vulnerability was identified in the Claude for Chrome browser integration, raising questions about the security of AI-assistant extensions that process browser content. The GhostCommit technique conceals malicious AI prompts inside code commits, potentially manipulating AI coding assistants without the developer’s knowledge. Additionally, researchers detailed an exploit chain dubbed “Sol” that combines GPT-5/6-era AI models with Chrome browser vulnerabilities, illustrating how attackers are chaining AI capabilities with traditional browser exploits.

Fortinet, F5, Splunk, Dell, and Other Enterprise Patches

Several major vendors issued critical patches this week. Fortinet addressed seven vulnerabilities across its security product portfolio. F5 patched multiple Nginx-related flaws in its product line. Splunk released fixes for several Enterprise vulnerabilities affecting data integrity and platform security. Dell disclosed a BIOS flaw that could expose administrator passwords in enterprise device fleets, and a separate issue is causing Dell laptops to shut down unexpectedly after the July 2026 update. Notepad++ v8.9.7 fixed a high-risk installer-time PowerShell command injection bug alongside four other flaws. A code execution vulnerability was also disclosed in 7-Zip, a widely used archiving tool.

How to Interpret This Week’s Threat Landscape

The volume and diversity of disclosures this week point to a threat environment where attackers are simultaneously targeting identity infrastructure, widely deployed content management systems, AI-integrated workflows, and even common productivity tools. The presence of actively exploited zero-days in both SharePoint Server and Active Directory Federation Services suggests that enterprise environments are under sustained pressure. Meanwhile, the GhostCommit and Sol exploit chains indicate that adversaries are investing in techniques that target AI-assisted development pipelines, a relatively new frontier in offensive cybersecurity.

What Affected Users and Organizations Should Do Now

For individuals, the most immediate actions are to update all browser extensions, enable two-factor authentication on all accounts, and monitor financial accounts and tax filings for signs of fraud. Users of Chrome extensions should audit their installed list and remove anything with broad data permissions. For organizations, prioritize the Microsoft Patch Tuesday updates, apply the WordPress wp2shell patch, and restrict REST API access to authenticated users where possible. Review Active Directory and federated authentication logs for anomalous activity. Deploy a reputable endpoint protection solution with behavioral analysis capabilities, and ensure that AI-integrated tools and browser extensions are subject to the same vulnerability management processes as traditional software. The closing of one attack surface only exposes the next, and maintaining a disciplined patching and monitoring cadence remains the most effective defense.

Share This Article