News Jul 4, 2026 ๐Ÿ‘ 22

IT News Roundup: CitrixBleed Returns, SharePoint RCE, Meta AI Cloud, and More - July 4, 2026

This week's IT news covers the return of CitrixBleed-class vulnerabilities in NetScaler with active exploitation within hours, a critical SharePoint RCE added to CISA's KEV catalog, Meta's entry into the AI cloud infrastructure market, the US lifting export controls on Anthropic's Fable 5 and Mythos 5, and AI-assisted vulnerability discovery driving a record surge in CVE disclosures.

The past few days have been dominated by a perfect storm of infrastructure vulnerabilities hitting widely deployed enterprise products, major shifts in the AI compute market, and surprising data on how AI is accelerating vulnerability discovery across the entire software ecosystem. From Citrix NetScaler to Microsoft SharePoint to Cisco Unified CM, organizations running these platforms need to act quickly.

CitrixBleed Returns: Six Critical NetScaler Vulnerabilities Exploited Within Hours

Citrix has released emergency patches for six vulnerabilities in NetScaler ADC and NetScaler Gateway, including a critical memory disclosure flaw (CVE-2026-8451, CVSS 8.8) that belongs to the recurring CitrixBleed class of memory management failures. The vulnerabilities โ€” tracked as CVE-2026-8451, CVE-2026-8452, CVE-2026-8655, CVE-2026-10816, CVE-2026-10817, and CVE-2026-13474 โ€” affect multiple supported versions of the appliances and can be exploited to read arbitrary files, trigger denial-of-service conditions, and disclose sensitive memory contents.

Attackers moved fast: decoy infrastructure operator Lupovis confirmed that CVE-2026-8451 was actively exploited within 24 hours of public disclosure, consistent with the pattern seen in previous CitrixBleed incidents dating back to CVE-2023-4966. Organizations with internet-facing NetScaler deployments should patch immediately and apply the specific Citrix workaround for CVE-2026-13474 if upgrading is not immediately possible.

Source: The Hacker News, CSA Singapore

CISA Adds SharePoint Remote Code Execution to Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-45659 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. The flaw is a deserialization of untrusted data vulnerability in Microsoft SharePoint Server that allows remote code execution โ€” and requires only Site Member-level permissions to exploit, making it accessible to a broad range of authenticated users.

The vulnerability was patched in Microsoft's May 2026 updates, though Microsoft initially assessed exploitation as "less likely" โ€” an assessment that proved wrong. The Register noted that CISA's KEV listing triggers a 3-day remediation mandate (BOD 26-04) for federal agencies, with a deadline of July 4. Private sector organizations running on-premises SharePoint should treat this with equal urgency given the confirmed active exploitation and the low privilege threshold required.

Source: CISA, The Register

Cisco Unified CM SSRF Vulnerability Actively Exploited to Deploy Webshells

CISA has also added CVE-2026-20230 (CVSS 8.6) to its KEV catalog โ€” a server-side request forgery vulnerability in Cisco Unified Communications Manager that allows unauthenticated remote attackers to conduct SSRF attacks, write arbitrary files, and potentially achieve root-level access. Threat intelligence firm Defused has observed automated attacks originating from the Tor network leveraging the WebDialer SSRF component to deploy webshells.

Cisco confirmed active exploitation as of early July, with public proof-of-concept exploit code available since at least June. The vulnerability stems from improper input validation for specific HTTP requests in the WebDialer feature. Organizations running Cisco Unified CM or Unified CM SME should verify they are on patched versions immediately, especially if the system is exposed to the internet or accessible from untrusted networks.

Source: F5 Labs, The Hacker News

Meta Launches Cloud Business to Sell Excess AI Compute Capacity

Meta Platforms is building a cloud infrastructure business internally dubbed Meta Compute that will sell access to excess AI computing capacity and hosted access to Meta's own AI models, including its Muse Spark lineup. The move directly challenges Amazon Web Services, Google Cloud, and Microsoft Azure, following a similar model to neocloud providers like CoreWeave.

The initiative is led by infrastructure chief Santosh Janardhan and Meta's Superintelligence Labs team. Bloomberg reports the two-track approach would combine raw GPU compute rental with a hosted model platform similar to AWS Bedrock. Meta's 2026 capex guidance of $115โ€“135 billion signals massive ongoing AI infrastructure investment, and monetizing excess capacity could improve returns on that spending. The news sent Meta shares up approximately 9% on the announcement.

Source: TechCrunch, CNBC

US Lifts Export Controls on Anthropic's Fable 5 and Mythos 5

The U.S. Department of Commerce has lifted export restrictions on Anthropic's most advanced AI models, Claude Fable 5 and Mythos 5, which had been abruptly disabled on June 12 after the administration cited national security concerns. Commerce Secretary Howard Lutnick approved the rollback on June 30, and Anthropic began restoring global access on July 1.

Fable 5 is now available worldwide on the Claude Platform, Claude.ai, Claude Code, and Claude Cowork. Mythos 5 access has been restored for trusted U.S. organizations, with Anthropic confirming that over 100 companies can now use the model. Anthropic agreed to deploy new classifiers and "proactively detect and address security risks" as part of the resolution. During the first week, Fable 5 usage will be capped at 50% of normal levels to manage demand.

Source: Anthropic, New York Times

AI-Assisted Vulnerability Discovery Drives Record 3.5x Spike in CVE Disclosures

Epoch AI has published data showing that 21 major organizations disclosed approximately 1,500 high- and critical-severity CVEs in June 2026 โ€” roughly 3.5 times the pre-Mythos monthly record. The total monthly CVE count has climbed from around 2,200 in mid-2023 to over 6,100 in June 2026, representing what researchers are calling a "step-function change" rather than gradual drift.

The surge is directly attributed to AI-assisted vulnerability discovery tools, with Microsoft even crediting OpenAI's Codex with reporting one of June Patch Tuesday's three publicly disclosed zero-days. The FIRST forecasting team has revised its 2026 CVE projection upward to approximately 68,000 total disclosures, with cumulative drift 46.3% above the original forecast. The open question remains whether defenders can leverage the same AI capabilities for patching as quickly as attackers use them for finding flaws.

Source: Epoch AI, FIRST.org

Cloudflare Introduces AI Traffic Controls for Website Owners

Cloudflare has rolled out new traffic classification tools that let site owners distinguish between search engine bots, AI agent scrapers, and training data harvesters, giving customers granular control over which automated traffic reaches their content. The feature is particularly relevant for ad-monetized sites that need to protect revenue from non-human traffic while still allowing legitimate search indexing.

The controls allow administrators to set per-category policies โ€” for example, allowing search crawlers while blocking training bots โ€” and apply them to specific pages or entire zones. This addresses a growing concern among publishers and content creators about AI companies scraping websites at scale without compensation or consent, and gives site operators a practical tool to manage this exposure without blanket blocking that could harm SEO.

Source: The Neuron


โ† Back to Blog