Daily briefing · July 2, 2026

Triple CVSS 10.0 and Seven More Criticals Flood July 2: Build Services, UniFi, WordPress, and Microsoft Cloud All Hit

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 2, 2026 delivered a heavy batch of critical vulnerabilities — 31 in a single day — with three scoring a perfect CVSS 10.0 spanning open-source build infrastructure, Ubiquiti's UniFi ecosystem, and a WordPress plugin. While no active exploitation (KEV) has been confirmed yet, the breadth of affected surfaces — from CI/CD pipelines to cloud identity services and network management platforms — demands immediate attention from defenders.

Today’s brief
  • Three CVSS 10.0 vulnerabilities published today: shellcode injection in OBS tar_scm, command injection in UniFi Connect, and unauthenticated RCE in a WordPress plugin.
  • Microsoft Azure OpenAI and Entra Provisioning Service carry SSRF flaws allowing privilege escalation by authorized attackers — a serious lateral movement risk in cloud environments.
  • Ubiquiti's UniFi portfolio is broadly affected: Connect, Protect, Talk, Access, and Cloud Gateways all have critical command injection or SQL injection issues exploitable from the network with low privileges.
  • SUSE Rancher Fleet's missing validation in Helm Deployer enables cross-tenant credential theft — a severe risk in multi-tenant Kubernetes environments.
31
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56004CVSS 10affects buildservice
A shellcode injection flaw in the Mercurial handler of OBS tar_scm (before 0.12.4) allows any attacker who can supply a malicious _service file to execute arbitrary code as the source service or as the local user — a direct threat to CI/CD pipeline integrity and developer workstations.
2
CVE-2026-50746CVSS 10affects UniFi Connect Application
An improper access control vulnerability in UniFi Connect Application enables a network-adjacent attacker to achieve command injection on the host device with no credential barrier reported, earning a perfect 10.0 and requiring urgent patching of all UniFi Connect deployments.
3
CVE-2026-57624CVSS 10affects Blocksy Companion Pro
Unauthenticated remote code execution in Blocksy Companion Pro (versions up to 2.1.46) means any unauthenticated internet user can fully compromise a WordPress site running the affected plugin — a straightforward mass-exploitation scenario for web hosting environments.
4
CVE-2026-45499CVSS 9.9affects Azure Open AI
An SSRF vulnerability in Azure OpenAI allows an authorized attacker to escalate privileges over the network, potentially pivoting to internal Microsoft cloud infrastructure or exfiltrating sensitive data accessible only from within Azure's trust boundary.
5
CVE-2026-57100CVSS 9.9affects Microsoft Entra Provisioning Service
Microsoft Entra Provisioning Service (SyncFabric) is affected by an SSRF that lets an authorized attacker elevate privileges — a particularly dangerous position given that Entra sits at the heart of identity and provisioning workflows for many enterprise tenants.
6
CVE-2026-44935CVSS 9.9affects Rancher
Missing validation of 'valuesFrom' references in SUSE Rancher Fleet's Helm Deployer (multiple branches affected) allows a tenant owner to read fleet credentials belonging to other tenants, breaking multi-tenancy isolation in Kubernetes cluster management at the infrastructure level.
7
CVE-2026-55115CVSS 9.9affects UniFi Protect Application
A low-privilege SSRF in UniFi Protect Application allows a network-accessible attacker to escalate privileges on the host device, threatening physical security infrastructure — cameras, access control — managed through the Protect platform.
8
CVE-2026-54402CVSS 9.9affects Cloud Gateways
Improper input validation in UniFi OS on Cloud Gateways enables command injection from the network with only low privileges, meaning a compromised or insider network account can achieve full host control over the gateway device.
9
CVE-2026-50747CVSS 9.9affects UniFi Talk Application
Authenticated SQL injection vulnerabilities in UniFi Talk Application allow a low-privileged network attacker to escalate privileges on the host, potentially exposing call records, credentials, and administrative access to the communications platform.
10
CVE-2026-50748CVSS 9.9affects UniFi Access Application
An improper input validation flaw in UniFi Access Application enables command injection from the network with low privileges, putting physical access control systems — door locks, entry logs — at risk of full compromise.
Today’s recommendation: Prioritize immediate patching of OBS tar_scm to 0.12.4+, all affected UniFi applications and Cloud Gateways, Blocksy Companion Pro to 2.1.46+, and all supported Rancher Fleet branches; apply Microsoft's mitigations for Azure OpenAI and Entra Provisioning as soon as they are available. Segment network access to management platforms and CI/CD services to limit exposure while patches are deployed.
With critical flaws spanning CI/CD pipelines, cloud identity, Kubernetes multi-tenancy, and network management all disclosed on the same day, now is the moment to map your own asset inventory against these affected products and validate whether your controls would detect or block exploitation attempts.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →