Daily briefing · July 2, 2026
Triple CVSS 10.0 and Seven More Criticals Flood July 2: Build Services, UniFi, WordPress, and Microsoft Cloud All Hit
July 2, 2026 delivered a heavy batch of critical vulnerabilities — 31 in a single day — with three scoring a perfect CVSS 10.0 spanning open-source build infrastructure, Ubiquiti's UniFi ecosystem, and a WordPress plugin. While no active exploitation (KEV) has been confirmed yet, the breadth of affected surfaces — from CI/CD pipelines to cloud identity services and network management platforms — demands immediate attention from defenders.
Today’s brief
- Three CVSS 10.0 vulnerabilities published today: shellcode injection in OBS tar_scm, command injection in UniFi Connect, and unauthenticated RCE in a WordPress plugin.
- Microsoft Azure OpenAI and Entra Provisioning Service carry SSRF flaws allowing privilege escalation by authorized attackers — a serious lateral movement risk in cloud environments.
- Ubiquiti's UniFi portfolio is broadly affected: Connect, Protect, Talk, Access, and Cloud Gateways all have critical command injection or SQL injection issues exploitable from the network with low privileges.
- SUSE Rancher Fleet's missing validation in Helm Deployer enables cross-tenant credential theft — a severe risk in multi-tenant Kubernetes environments.
31
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A shellcode injection flaw in the Mercurial handler of OBS tar_scm (before 0.12.4) allows any attacker who can supply a malicious _service file to execute arbitrary code as the source service or as the local user — a direct threat to CI/CD pipeline integrity and developer workstations.
2
An improper access control vulnerability in UniFi Connect Application enables a network-adjacent attacker to achieve command injection on the host device with no credential barrier reported, earning a perfect 10.0 and requiring urgent patching of all UniFi Connect deployments.
3
Unauthenticated remote code execution in Blocksy Companion Pro (versions up to 2.1.46) means any unauthenticated internet user can fully compromise a WordPress site running the affected plugin — a straightforward mass-exploitation scenario for web hosting environments.
4
An SSRF vulnerability in Azure OpenAI allows an authorized attacker to escalate privileges over the network, potentially pivoting to internal Microsoft cloud infrastructure or exfiltrating sensitive data accessible only from within Azure's trust boundary.
5
Microsoft Entra Provisioning Service (SyncFabric) is affected by an SSRF that lets an authorized attacker elevate privileges — a particularly dangerous position given that Entra sits at the heart of identity and provisioning workflows for many enterprise tenants.
6
Missing validation of 'valuesFrom' references in SUSE Rancher Fleet's Helm Deployer (multiple branches affected) allows a tenant owner to read fleet credentials belonging to other tenants, breaking multi-tenancy isolation in Kubernetes cluster management at the infrastructure level.
7
A low-privilege SSRF in UniFi Protect Application allows a network-accessible attacker to escalate privileges on the host device, threatening physical security infrastructure — cameras, access control — managed through the Protect platform.
8
Improper input validation in UniFi OS on Cloud Gateways enables command injection from the network with only low privileges, meaning a compromised or insider network account can achieve full host control over the gateway device.
9
Authenticated SQL injection vulnerabilities in UniFi Talk Application allow a low-privileged network attacker to escalate privileges on the host, potentially exposing call records, credentials, and administrative access to the communications platform.
10
An improper input validation flaw in UniFi Access Application enables command injection from the network with low privileges, putting physical access control systems — door locks, entry logs — at risk of full compromise.
Today’s recommendation: Prioritize immediate patching of OBS tar_scm to 0.12.4+, all affected UniFi applications and Cloud Gateways, Blocksy Companion Pro to 2.1.46+, and all supported Rancher Fleet branches; apply Microsoft's mitigations for Azure OpenAI and Entra Provisioning as soon as they are available. Segment network access to management platforms and CI/CD services to limit exposure while patches are deployed.
With critical flaws spanning CI/CD pipelines, cloud identity, Kubernetes multi-tenancy, and network management all disclosed on the same day, now is the moment to map your own asset inventory against these affected products and validate whether your controls would detect or block exploitation attempts.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →