Microsoft's Record 570 Patches, SAP's 9.9 Flaw & a Secure Boot Bypass (07/14/2026)
- › Microsoft's July Patch Tuesday fixed a record 570 security flaws, almost triple a typical month, so prioritization matters more than ever.
- › SAP patched a CVSS 9.9 flaw in NetWeaver Application Server ABAP that could let an attacker expose or modify business data.
- › Researchers found 11 old Microsoft-signed Linux UEFI shims that can be abused to bypass Secure Boot on most systems.
- › A Claude for Chrome flaw lets any other browser extension trigger tasks that read your Gmail, Docs, and Calendar.
- › Iran exploited well-known mobile network flaws to locate and strike US military personnel in the Middle East.
Patch Tuesday came in like a flood this month, and it is the smallest of today’s problems in some ways. Microsoft shipped a record 570 fixes, SAP closed a near-perfect-score flaw in the software that runs the enterprise, and researchers showed that Secure Boot, the thing meant to guarantee a clean start, can be walked around with certificates Microsoft signed years ago. The theme is trust that was issued once and never revoked. Prioritize accordingly.
Top 5 Critical Security Alerts
1. Microsoft Patches a Record 570 Security Flaws
Microsoft’s July update plugged at least 570 security holes across Windows and its other software, almost triple a normal Patch Tuesday (Krebs on Security). A number that large is not a victory lap, it is a triage problem, because no team patches 570 things at once and the ones under active exploitation are the only deadline that matters.
Operator Note: Do not treat 570 as a to-do list. Pull the actively-exploited and internet-facing items to the front today and let the rest follow your normal cycle.
2. SAP Patches a CVSS 9.9 NetWeaver Flaw
SAP’s July updates include a critical CVSS 9.9 vulnerability in NetWeaver Application Server ABAP that could let an attacker expose or modify data (The Hacker News). NetWeaver runs the financial and operational core of a huge share of large enterprises, so a 9.9 here reaches straight into the records the business runs on, and SAP flaws have a long history of slow patching.
3. 11 Signed UEFI Shims Can Bypass Secure Boot
Researchers found 11 old, Microsoft-signed UEFI applications that can be abused to bypass Secure Boot on most systems (The Hacker News). Secure Boot exists to guarantee the machine starts with trusted code, and a signed shim that defeats it lets an attacker load a bootkit that survives reinstalls, which is about as deep as persistence gets.
4. Claude for Chrome Flaw Exposes Gmail and Docs
Researchers reported that any browser extension able to run a script on claude.ai can trigger Claude for Chrome tasks aimed at your Gmail, your latest Google Doc, and your Calendar (The Hacker News). An AI browser agent with reach into your mail and documents is a high-value identity, and letting a neighboring extension drive it is exactly the confused-deputy problem that keeps following AI agents around.
5. Iran Located US Troops Through Mobile Network Flaws
A report says the Iranian government exploited well-known cellphone network vulnerabilities to locate and then strike US military personnel in the Middle East (TechCrunch). The SS7-class flaws that make this possible have been known for a decade, and this is the reminder that an unpatched protocol is not an abstract risk when a nation-state turns location data into targeting.
Additional Security Alerts
Threat Intelligence
- Nearly 300 Fake GitHub Repos Push Infostealers: A threat actor published hundreds of GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware, so vet the source before you clone. BleepingComputer
- ClickFix Grows Into a Rentable Ecosystem: The ClickFix technique that tricks users into pasting malicious commands is now available for rent at scale and evades AV and EDR. We cover why capable people fall for it, and how to design it out, in our behavioral breakdown of ClickFix. Dark Reading
Security Breaches & Incidents
- US Indicts Operators of Russian Bulletproof Host: The US unsealed an indictment against alleged operators of the St. Petersburg-based bulletproof hosting service Media Land, which provided infrastructure and support to cybercriminals. The Record
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.