Daily briefing · July 2, 2026
Triple CVSS 10.0 and Seven More Criticals Flood July 2: Build Services, UniFi, WordPress, and Microsoft Cloud All Hit
July 2, 2026 delivered a heavy batch of critical vulnerabilities — 31 in a single day — with three scoring a perfect CVSS 10.0 spanning open-source build infrastructure, Ubiquiti's UniFi ecosystem, and a WordPress plugin. While no active exploitation (KEV) has been confirmed yet, the breadth of affected surfaces — from CI/CD pipelines to cloud identity services and network management platforms — demands immediate attention from defenders.
Today’s brief
- Three CVSS 10.0 vulnerabilities published today: shellcode injection in OBS tar_scm, command injection in UniFi Connect, and unauthenticated RCE in a WordPress plugin.
- Microsoft Azure OpenAI and Entra Provisioning Service carry SSRF flaws allowing privilege escalation by authorized attackers — a serious lateral movement risk in cloud environments.
- Ubiquiti's UniFi portfolio is broadly affected: Connect, Protect, Talk, Access, and Cloud Gateways all have critical command injection or SQL injection issues exploitable from the network with low privileges.
- SUSE Rancher Fleet's missing validation in Helm Deployer enables cross-tenant credential theft — a severe risk in multi-tenant Kubernetes environments.
31
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A shellcode injection flaw in the Mercurial handler of OBS tar_scm (before 0.12.4) allows any attacker who can supply a malicious _service file to execute arbitrary code as the source service or as the local user — a direct threat to CI/CD pipeline integrity and developer workstations.
2
An improper access control vulnerability in UniFi Connect Application enables a network-adjacent attacker to achieve command injection on the host device with no credential barrier reported, earning a perfect 10.0 and requiring urgent patching of all UniFi Connect deployments.
3
Unauthenticated remote code execution in Blocksy Companion Pro (versions up to 2.1.46) means any unauthenticated internet user can fully compromise a WordPress site running the affected plugin — a straightforward mass-exploitation scenario for web hosting environments.
4
An SSRF vulnerability in Azure OpenAI allows an authorized attacker to escalate privileges over the network, potentially pivoting to internal Microsoft cloud infrastructure or exfiltrating sensitive data accessible only from within Azure's trust boundary.
5
Microsoft Entra Provisioning Service (SyncFabric) is affected by an SSRF that lets an authorized attacker elevate privileges — a particularly dangerous position given that Entra sits at the heart of identity and provisioning workflows for many enterprise tenants.
6
Missing validation of 'valuesFrom' references in SUSE Rancher Fleet's Helm Deployer (multiple branches affected) allows a tenant owner to read fleet credentials belonging to other tenants, breaking multi-tenancy isolation in Kubernetes cluster management at the infrastructure level.
7
A low-privilege SSRF in UniFi Protect Application allows a network-accessible attacker to escalate privileges on the host device, threatening physical security infrastructure — cameras, access control — managed through the Protect platform.
8
Improper input validation in UniFi OS on Cloud Gateways enables command injection from the network with only low privileges, meaning a compromised or insider network account can achieve full host control over the gateway device.
9
Authenticated SQL injection vulnerabilities in UniFi Talk Application allow a low-privileged network attacker to escalate privileges on the host, potentially exposing call records, credentials, and administrative access to the communications platform.
10
An improper input validation flaw in UniFi Access Application enables command injection from the network with low privileges, putting physical access control systems — door locks, entry logs — at risk of full compromise.
Today’s recommendation: Prioritize immediate patching of OBS tar_scm to 0.12.4+, all affected UniFi applications and Cloud Gateways, Blocksy Companion Pro to 2.1.46+, and all supported Rancher Fleet branches; apply Microsoft's mitigations for Azure OpenAI and Entra Provisioning as soon as they are available. Segment network access to management platforms and CI/CD services to limit exposure while patches are deployed.
With critical flaws spanning CI/CD pipelines, cloud identity, Kubernetes multi-tenancy, and network management all disclosed on the same day, now is the moment to map your own asset inventory against these affected products and validate whether your controls would detect or block exploitation attempts.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →