Daily briefing · July 2, 2026

Triple CVSS 10.0 and Seven More Criticals Flood July 2: Build Services, UniFi, WordPress, and Microsoft Cloud All Hit

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

July 2, 2026 delivered a heavy batch of critical vulnerabilities — 31 in a single day — with three scoring a perfect CVSS 10.0 spanning open-source build infrastructure, Ubiquiti's UniFi ecosystem, and a WordPress plugin. While no active exploitation (KEV) has been confirmed yet, the breadth of affected surfaces — from CI/CD pipelines to cloud identity services and network management platforms — demands immediate attention from defenders.

Today’s brief
  • Three CVSS 10.0 vulnerabilities published today: shellcode injection in OBS tar_scm, command injection in UniFi Connect, and unauthenticated RCE in a WordPress plugin.
  • Microsoft Azure OpenAI and Entra Provisioning Service carry SSRF flaws allowing privilege escalation by authorized attackers — a serious lateral movement risk in cloud environments.
  • Ubiquiti's UniFi portfolio is broadly affected: Connect, Protect, Talk, Access, and Cloud Gateways all have critical command injection or SQL injection issues exploitable from the network with low privileges.
  • SUSE Rancher Fleet's missing validation in Helm Deployer enables cross-tenant credential theft — a severe risk in multi-tenant Kubernetes environments.
31
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-56004CVSS 10affects buildservice
A shellcode injection flaw in the Mercurial handler of OBS tar_scm (before 0.12.4) allows any attacker who can supply a malicious _service file to execute arbitrary code as the source service or as the local user — a direct threat to CI/CD pipeline integrity and developer workstations.
2
CVE-2026-50746CVSS 10affects UniFi Connect Application
An improper access control vulnerability in UniFi Connect Application enables a network-adjacent attacker to achieve command injection on the host device with no credential barrier reported, earning a perfect 10.0 and requiring urgent patching of all UniFi Connect deployments.
3
CVE-2026-57624CVSS 10affects Blocksy Companion Pro
Unauthenticated remote code execution in Blocksy Companion Pro (versions up to 2.1.46) means any unauthenticated internet user can fully compromise a WordPress site running the affected plugin — a straightforward mass-exploitation scenario for web hosting environments.
4
CVE-2026-45499CVSS 9.9affects Azure Open AI
An SSRF vulnerability in Azure OpenAI allows an authorized attacker to escalate privileges over the network, potentially pivoting to internal Microsoft cloud infrastructure or exfiltrating sensitive data accessible only from within Azure's trust boundary.
5
CVE-2026-57100CVSS 9.9affects Microsoft Entra Provisioning Service
Microsoft Entra Provisioning Service (SyncFabric) is affected by an SSRF that lets an authorized attacker elevate privileges — a particularly dangerous position given that Entra sits at the heart of identity and provisioning workflows for many enterprise tenants.
6
CVE-2026-44935CVSS 9.9affects Rancher
Missing validation of 'valuesFrom' references in SUSE Rancher Fleet's Helm Deployer (multiple branches affected) allows a tenant owner to read fleet credentials belonging to other tenants, breaking multi-tenancy isolation in Kubernetes cluster management at the infrastructure level.
7
CVE-2026-55115CVSS 9.9affects UniFi Protect Application
A low-privilege SSRF in UniFi Protect Application allows a network-accessible attacker to escalate privileges on the host device, threatening physical security infrastructure — cameras, access control — managed through the Protect platform.
8
CVE-2026-54402CVSS 9.9affects Cloud Gateways
Improper input validation in UniFi OS on Cloud Gateways enables command injection from the network with only low privileges, meaning a compromised or insider network account can achieve full host control over the gateway device.
9
CVE-2026-50747CVSS 9.9affects UniFi Talk Application
Authenticated SQL injection vulnerabilities in UniFi Talk Application allow a low-privileged network attacker to escalate privileges on the host, potentially exposing call records, credentials, and administrative access to the communications platform.
10
CVE-2026-50748CVSS 9.9affects UniFi Access Application
An improper input validation flaw in UniFi Access Application enables command injection from the network with low privileges, putting physical access control systems — door locks, entry logs — at risk of full compromise.
Today’s recommendation: Prioritize immediate patching of OBS tar_scm to 0.12.4+, all affected UniFi applications and Cloud Gateways, Blocksy Companion Pro to 2.1.46+, and all supported Rancher Fleet branches; apply Microsoft's mitigations for Azure OpenAI and Entra Provisioning as soon as they are available. Segment network access to management platforms and CI/CD services to limit exposure while patches are deployed.
With critical flaws spanning CI/CD pipelines, cloud identity, Kubernetes multi-tenancy, and network management all disclosed on the same day, now is the moment to map your own asset inventory against these affected products and validate whether your controls would detect or block exploitation attempts.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share