IT News Roundup: GPT-5.6 Release, Siemens OT Zero-Days, SharePoint RCE - July 19, 2026
This week's top IT stories: OpenAI releases GPT-5.6 Sol after government review, critical zero-day chain discovered in Siemens OT switches, CISA adds exploited SharePoint RCE to KEV catalog, Meta launches cloud business, and Adobe ColdFusion faces 11 critical vulnerabilities.
The past week in IT has been dominated by major AI model releases, critical infrastructure vulnerabilities, and shifts in the cloud computing landscape. OpenAI and SpaceXAI both launched flagship models, while security researchers uncovered dangerous flaws in industrial control systems and enterprise platforms.
OpenAI Releases GPT-5.6 Sol After U.S. Government Review
OpenAI publicly released GPT-5.6 on July 9, 2026, marking a significant milestone in the AI development cycle. Rather than a single model, GPT-5.6 ships as a family of three variants ranked by capability: Luna, Terra, and Sol. The flagship Sol variant sets new benchmarks across coding, knowledge work, cybersecurity, and scientific research while reportedly using fewer tokens and lower estimated cost than competing frontier models.
The release came only after a U.S. government review cleared it for broad deployment, signaling a new era of regulatory oversight for frontier AI systems. OpenAI also paired the release with its most advanced safety stack to date. The launch was accompanied by a new tool designed to assist with everyday office productivity tasks, expanding the practical applications of the model beyond research and development.
Source: OpenAI, Tech Journal
SpaceXAI Launches Grok 4.5 as Opus-Class Contender
On the same day, xAI — which has officially rebranded to SpaceXAI — launched Grok 4.5, its most capable model to date. Built on a 1.5 trillion parameter V9 foundation, Grok 4.5 was trained on datasets spanning coding, science, engineering, and mathematics. Musk claims the model matches Anthropic's Claude Opus 4.8 in capability while being faster, cheaper, and more token-efficient.
Grok 4.5 ships with a 500,000-token context window and aggressive pricing at per million input tokens and per million output tokens (with cached input at bash.50). Independent testing by Artificial Analysis ranks it fourth among frontier models. The launch positions SpaceXAI as a direct competitor in the enterprise AI market, particularly for advanced coding and knowledge work where Claude Opus has been widely adopted.
Critical Zero-Day Chain Discovered in Siemens ROX II OT Switches
Palo Alto Networks Unit 42, in partnership with Siemens, published a detailed analysis of three chained zero-day vulnerabilities (CVE-2025-40947, CVE-2025-40948, CVE-2025-40949) affecting Siemens ROX II operational technology switches. The exploit chain allows an attacker to progress from arbitrary file disclosure to full, persistent root-level access on these industrial networking devices.
Siemens ROX II switches are deployed in critical infrastructure environments including manufacturing plants, energy facilities, and transportation systems. The chained nature of the exploit means that even partial patching may leave systems vulnerable if all three vulnerabilities are not addressed simultaneously. The research underscores the growing threat to OT environments, where air-gapped assumptions are increasingly being challenged by sophisticated threat actors.
Source: Palo Alto Networks Unit 42
CISA Adds Exploited SharePoint RCE Zero-Day to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-58644 to its Known Exploited Vulnerabilities catalog on July 17, 2026. The critical deserialization flaw in Microsoft SharePoint Server carries a CVSS score of 9.8 and enables remote code execution. Federal Civilian Executive Branch agencies were directed to apply patches by July 19.
The vulnerability has been confirmed under active exploitation in the wild, making immediate remediation essential for all organizations running SharePoint Server. The KEV listing means that federal agencies face compliance requirements to patch within the mandated deadline. IT administrators should verify their SharePoint deployments are updated and monitor for exploitation attempts through security monitoring tools.
Source: The Hacker News
Meta Launches Meta Compute Cloud Business to Monetize AI Infrastructure
Meta announced plans for a cloud infrastructure business internally called Meta Compute, offering external customers access to its massive AI computing capacity and models including the recently launched closed-weight model Muse Spark. The initiative would transform Meta's approximately 30 billion AI infrastructure investment from a cost center into a potential revenue stream.
The announcement caused Meta stock to surge as much as 10% on July 1. The move positions Meta alongside Amazon Web Services, Microsoft Azure, and Google Cloud in the enterprise AI infrastructure market — a space previously considered beyond the social media company's core competencies. This follows a similar playbook from companies like CoreWeave and Nebius that have built cloud businesses around excess AI compute capacity.
Source: Tech Startups
Adobe ColdFusion Faces 11 Critical Vulnerabilities Including Six CVSS 10.0 Flaws
A vulnerability intelligence report for early July revealed 11 critical vulnerabilities in Adobe ColdFusion 2025 and 2023, with six scoring a maximum CVSS of 10.0 and including unauthenticated remote code execution flaws. ColdFusion is widely deployed in government, financial services, and enterprise environments for web application development.
The severity and breadth of the vulnerabilities make this a high-priority patching event for any organization running ColdFusion. Unauthenticated RCE flaws in particular pose immediate risk since they require no credentials for exploitation. Administrators should verify their ColdFusion installations are updated to the latest patched version and implement compensating controls such as web application firewalls until patches are fully deployed.
Source: Threat Modeling
Google Report: 80% of Organizations Need Tech Stack Upgrades for AI Agents
Google's 2026 State of AI Infrastructure report, released in mid-July, found that more than four in five organizations need to upgrade their technology stacks to support AI agents at scale. The report highlights a growing infrastructure gap between AI ambitions and current IT capabilities across enterprises.
The findings underscore the practical challenges facing organizations looking to deploy AI agents in production environments. Legacy systems, insufficient compute resources, and outdated orchestration platforms are cited as key barriers. The report recommends incremental modernization strategies rather than wholesale infrastructure replacement.
Source: CIO Dive
← Back to Blog