By Nemuel Cruz, Incognito CyberSecurity™
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to small businesses across Southern Arizona. Here is what happened in cybersecurity over the weekend of July 17-19, 2026, and what each story actually means for a business owner who does not have a full-time security team on payroll.
1. Public exploits released for WordPress "wp2shell" remote code execution flaws
On Saturday, July 18, working exploit code went public for a pair of WordPress Core vulnerabilities. CVE-2026-63030 is a REST API batch-route confusion bug, and CVE-2026-60137 is a SQL injection flaw. Chained together, they give an attacker pre-authentication remote code execution. In plain English: someone who has never logged into your website can take it over. Searchlight Cyber, which discovered the flaws, says the attack works against a stock WordPress install with no plugins and no preconditions. Security firm watchTowr reported the first signs of real-world exploitation within hours of the exploits appearing. The full chain affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, and is fixed in 6.9.5 and 7.0.2.
What to do: Log into your website admin today and confirm you are running WordPress 6.9.5 or 7.0.2. WordPress has force-enabled automatic updates for affected versions, but do not assume it worked — check the version number yourself. If you cannot patch immediately, get the site behind a web application firewall; Cloudflare deployed rules for both flaws across all plans, including free accounts. A simple brochure website feels low-risk right up until it is quietly serving malware to your customers and Google flags it. Ongoing patching like this is exactly what our managed cybersecurity services handle so owners never have to think about it.
2. CISA orders emergency patching of actively exploited Fortinet FortiSandbox flaws
CISA confirmed that two critical Fortinet FortiSandbox vulnerabilities, CVE-2026-39808 and CVE-2026-25089, are being exploited in the wild and added them to its Known Exploited Vulnerabilities catalog. Both are low-complexity command injection flaws that let an unauthenticated attacker run code remotely with no user interaction required. Federal agencies were given until Sunday, July 19 to patch under Binding Operational Directive 26-04. Notably, Fortinet had already released fixes back on April 14 and June 9 — the machines being compromised are the ones that were never updated.
What to do: If you run any Fortinet equipment, confirm your firmware is current this week. The broader lesson matters more than the specific product: your firewall and security appliances sit directly on the internet, which makes them a favorite target rather than a safe zone. CISA now tracks 28 exploited Fortinet vulnerabilities, 13 of which have been used in ransomware attacks. If nobody at your company can tell you the firmware version on your firewall right now, that is the actual finding. Keeping edge hardware patched and monitored is core to our network solutions work.
3. Microsoft warns of a surge in ACR Stealer attacks harvesting browser passwords
Microsoft reported a sharp increase in attacks using ACR Stealer against its enterprise customers. The malware goes after passwords, cookies, session data, and authentication tokens saved in Chrome and Edge, decrypts them using Windows’ own data protection API, then sweeps up PDFs, Microsoft 365 documents, files from the Desktop and Downloads folders, and anything in synced OneDrive and SharePoint directories. The main delivery method is "ClickFix" — a fake error message or fake "verify you are human" prompt that instructs the visitor to copy and paste a command into Windows. The victim infects their own machine by following the instructions.
What to do: Tell every employee this week, in one sentence: no legitimate website will ever ask you to copy and paste a command to fix an error or prove you are human. That single rule defeats the entire ClickFix category. Then stop letting staff save business passwords in the browser — use a password manager instead — and turn on multi-factor authentication everywhere, because stolen session tokens can bypass passwords entirely. Detecting this kind of in-memory malware is what endpoint protection exists for; free antivirus generally will not catch it.
4. Unpatched Windows "LegacyHive" zero-day hands attackers admin privileges
A researcher operating as "Nightmare Eclipse" published a proof-of-concept exploit called LegacyHive on Friday, July 17, just hours after Microsoft shipped its July Patch Tuesday updates. It abuses a flaw in the Windows User Profile Service that still has no CVE assigned and no patch. Vulnerability analyst Will Dormann and researcher Kevin Beaumont both independently confirmed the exploit works on fully updated Windows systems, and Beaumont has published detection queries for Microsoft Defender for Endpoint. Microsoft told BleepingComputer it is "actively investigating" the claims. This is a privilege escalation bug, not a remote break-in — an attacker needs a foothold first, then uses this to become an administrator.
What to do: There is no patch yet, so reduce what an attacker gains if they land on a machine. Stop having staff run day-to-day work from accounts with administrator rights — this is the single highest-value change most small businesses can make, and it costs nothing. Keep separate admin accounts used only for installing software. Privilege escalation bugs are only valuable to an attacker who already got in, so the everyday-account discipline is what blunts them. Standardizing user rights across machines is part of our server and workstation management.
5. 7-Zip patches a code execution flaw — and it will not update itself
7-Zip version 26.02 fixes a heap-based buffer overflow in how the program handles XZ-compressed data, disclosed by researcher Landon Peng and documented by the Zero Day Initiative. An attacker who convinces someone to open a booby-trapped archive can run code as that user. There are no reports of active exploitation yet, but the important detail is operational, not technical: 7-Zip has no automatic update feature. Nobody gets this fix unless a human installs it. Archive tools have a track record here — Russian state hackers exploited a 7-Zip flaw as a zero-day in 2025, and another group weaponized a WinRAR bug the same year to deliver malware through phishing.
What to do: Find out which computers in your office have 7-Zip installed and update them to 26.02 manually from 7-zip.org, or push it through a package manager. If you cannot answer "what software is installed on my machines," that inventory gap is a bigger problem than this one bug — it is how organizations end up running vulnerable software for years without knowing. Software inventory and patch management for tools that do not self-update is a standard part of our small business cyber security solutions.
6. Ernst & Young breached through a third-party support ticket system
Ernst & Young began notifying customers on July 17 of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. Support tickets submitted through the platform may have contained documents holding client tax information. Nobody broke into EY directly. They got in through a vendor, and the exposed data was the material customers had handed over in the course of ordinary support requests.
What to do: Make a list of every outside company that touches your data — your bookkeeper, payroll provider, CRM, IT helpdesk, file-sharing service — and ask each one what they store and how they protect it. Then look at your own habits: sensitive documents attached to support tickets and emails tend to sit in those systems forever. Stop sending tax documents, banking details, and customer records as plain attachments. And make sure you hold your own secure data backups rather than assuming a vendor has a copy you can recover from.
The bottom line
Look at what actually drove this weekend’s news. Fortinet had patches out in April and June; the victims were the ones who never applied them. WordPress shipped a fix before the exploits went public. 7-Zip has a patch nobody will install automatically. The ACR Stealer campaign works because people paste commands they are told to paste. None of this required an attacker to do anything clever. It required someone on the defending side to not do the boring, routine work of patching, inventory, and basic user training. That is good news for small businesses, because the boring work is affordable and it is the part you control.
Incognito CyberSecurity™ is a local Tucson, Arizona MSP company offering 24/7 services to businesses across Southern Arizona.
If you are not certain whether your website, firewall, and workstations are patched against the issues above, that uncertainty is the problem worth fixing. Contact Incognito Cyber Security and we will tell you where you stand.
Lea este artículo en español: Eventos de Ciberseguridad del fin de semana: 20 de julio de 2026


