MilikMilik

Microsoft, SAP, and Adobe Patch Record Vulnerabilities

Microsoft, SAP, and Adobe Patch Record Vulnerabilities
Interest|High-Quality Software

This Patch Cycle Is Different: Treat Identity and Core Apps as Tier‑0

Enterprise security teams are facing an unusually dense patch cycle in which Microsoft, SAP, Adobe ecosystem components, and collaboration platforms have shipped fixes for actively exploited and near‑critical vulnerabilities, making disciplined prioritization across identity, document management, and business applications more important than the raw number of CVEs.

The headline is not that Microsoft released 622 security patches; it is that many of the flaws directly touch the systems that decide who is trusted in your environment. Identity platforms, content platforms, and ERP back ends are now the attacker’s shortest path to business data, and this cycle is a stress test of your enterprise patch management strategy. If you are still sorting by CVSS alone, you are making the wrong call. The only rational approach is to rank by exploitation, then by business impact: identity first, data stores second, everything else after.

Microsoft, SAP, and Adobe Patch Record Vulnerabilities

Microsoft Security Patches: Zero‑Days in SharePoint, AD FS, and a Kerberos Trap

Microsoft’s largest Patch Tuesday to date delivers 622 CVE fixes, and two of them are already under active attack: CVE‑2026‑56164 in on‑premises SharePoint Server and CVE‑2026‑56155 in Active Directory Federation Services. Both are elevation‑of‑privilege flaws in infrastructure that effectively guard your document estate and your authentication tokens. If your enterprise runs self‑hosted SharePoint or AD FS, these are not optional maintenance windows; they are emergency changes. The SharePoint bug even allows an unauthenticated attacker to escalate privileges remotely over the network, with no credentials or user interaction.

This patch set also completes Microsoft’s long Kerberos RC4 lock‑down, removing the RC4DefaultDisablementPhase rollback switch that admins have used as a safety valve since January. The uncomfortable truth: “If any service account in your environment still requests RC4 Kerberos tickets, it can fail authentication the moment the update lands.” Legacy apps will break silently unless you test now. Smart teams will pre‑scan domain controllers for RC4 use, coordinate with app owners, and only then push domain‑wide updates. Ignoring this change is how you self‑inflict an outage disguised as security hardening.

SAP NetWeaver ABAP Flaw: Business Data Is the Real Target

SAP’s July release underlines how fragile core business systems remain when memory‑safety bugs surface in central components. The standout issue is CVE‑2026‑44747, a CVSS 9.9 out‑of‑bounds write flaw in SAP NetWeaver Application Server ABAP. An authenticated attacker can exploit logical errors in memory management to corrupt memory, which can lead to unauthorized data access, modification, or even full system unavailability. In plain language: your financials, HR, and supply‑chain data could be exposed or altered by someone who already has a foothold in your SAP environment.

A suggested workaround disables ICF nodes with a specific property in transaction SICF, but doing so blocks opening transactions in SAP GUI for HTML and is therefore “not an option for all customers.” The only sensible choice for most enterprises is to prioritize deployment of the patched ABAP kernel. Alongside this, SAP has also fixed a request smuggling flaw in Approuter deployments and a default‑credential issue in SAP Commerce Cloud; customers are advised to update and audit for lingering sample OAuth 2.0 clients, removing any they find. If your business runs on SAP, this patch wave is about data integrity, not compliance box‑ticking.

Microsoft, SAP, and Adobe Patch Record Vulnerabilities

Actively Exploited Web and Collaboration Flaws: CISA KEV, Zimbra, and Account Takeovers

While platforms patch, attackers move even faster. CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities catalog, covering Adobe ColdFusion, two Joomla page builders, and the Langflow workflow tool. The Adobe ColdFusion path traversal bug, CVE‑2026‑48282, carries a CVSS score of 10.0 and can lead to arbitrary code execution under the current user context. Another flaw, CVE‑2026‑55255 in Langflow, lets an authenticated attacker execute any flow belonging to another user simply by specifying the victim’s flow ID. These are the kinds of web‑facing holes that turn edge servers into launchpads for deeper compromises. CISA is clear: Federal agencies must apply fixes by early July, and enterprises would be wise to follow the same urgency curve.

On the collaboration front, Zimbra’s “Daffodil” 10.1.19 release fixes a stored cross‑site scripting vulnerability in the Classic Web Client that could be used to compromise users’ machines by sending them crafted emails. The malicious code runs when the message is opened, threatening session data, mailbox contents, and account settings—even though the vendor labels deployment risk as low. Given Zimbra’s history of XSS‑based attacks, including previous persistent bugs exploited against sensitive users, any organization still on the Classic Web Client should treat this as an account‑hijacking risk and install the update immediately. Leaving mail platforms unpatched is handing attackers a pre‑texted phishing channel with built‑in code execution.

Microsoft, SAP, and Adobe Patch Record Vulnerabilities

Stop Drowning in CVEs: A Practical Enterprise Patch Management Order

With hundreds of Microsoft security patches, high‑impact SAP fixes, CISA KEV additions, and collaboration bugs all demanding attention at once, the worst mistake is to treat them as equal. Microsoft itself advises sorting by what is actively exploited—using KEV, EPSS, and Microsoft’s exploited flags—rather than by severity score. The right move is to design an opinionated patch order rooted in your business architecture, not vendor labels.

  1. Patch exploited identity and document platforms first: Microsoft SharePoint CVE‑2026‑56164 and AD FS CVE‑2026‑56155, alongside the Kerberos RC4 change on domain controllers.
  2. Patch SAP NetWeaver ABAP CVE‑2026‑44747 with the new kernel rather than long‑term reliance on disruptive SICF workarounds, then address Approuter and Commerce Cloud fixes and remove any sample OAuth 2.0 clients you find.
  3. Apply fixes for KEV‑listed web flaws in Adobe ColdFusion, JoomShaper SP Page Builder (update to version 6.6.2 or later), Page Builder CK, and Langflow on exposed sites.
  4. Update collaboration platforms, especially Zimbra Daffodil to 10.1.19 for Classic Web Client users, and validate that XSS filters and custom mitigations still work as expected.

Patch everything eventually, but be unapologetically biased: identity, auth, and business data come first. If your patch management playbook does not encode that bias, this cycle is your warning to rewrite it.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!