> ## Content Index
> Fetch the complete content index at: https://www.clinicalcyber.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# ShinyHunters uses healthcare help desks to break into cloud accounts
- URL: https://www.clinicalcyber.com/issue-012-2026-07-27/
- Published: 2026-07-27T19:43:45.000Z
- Updated: 2026-07-27T19:43:45.000Z
- Description: The group is using phone calls to persuade help desks to reset multifactor authentication, then taking over cloud accounts and stealing data from connected services—often without deploying traditional ransomware.
- Author: Clinical Cyber Dispatch
- Tags: #ccd-edition:ccd-issue-012-d5f0bf0f6e661abd, #ccd-candidate:b236c5c92a793db7cbf21208fcf7ba802f66bb4253764fa3e9e11c1c5df3370c

## CISO Quick Read

1. 01  
### Craneware contains an intrusion while assessing stolen data  
Craneware disclosed unauthorized access and data exfiltration but reported no disruption to customer services or company operations.  
The unresolved scope includes some employee data and a subset of customer and partner records tied to a healthcare financial-technology supplier.  
Craneware still has to determine the precise scope of the exfiltrated customer, partner and employee data and identify the affected parties.

**Timing**20 July 2026  
[Open the supporting record](#incident-craneware-2026-07-20)
2. 02  
### Oracle WebCenter Content flaw allows unauthenticated takeover  
An unauthenticated attacker with HTTP network access can exploit affected WebCenter Content versions to take over the platform and potentially affect connected products.  
Where WebCenter Content or a dependent service is deployed, a takeover could expose or alter content and disrupt access to the platform.  
Applicable deployments are self-managed Oracle WebCenter Content releases 12.2.1.4.0 and 14.1.2.0.0 that untrusted parties can reach over HTTP.

**Timing**Oracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.  
[Open the supporting record](#cve-cve-2026-60644)
3. 03  
### Oracle PeopleSoft flaw exposes critical application data  
An unauthenticated attacker with HTTP network access can exploit PeopleSoft Enterprise CC Common Application Objects 9.2 to read, create, delete or modify critical application data.  
Where the affected PeopleSoft component is deployed, unauthorized data access and modification could undermine records and the business processes that depend on them.  
This applies to Oracle PeopleSoft Enterprise CC Common Application Objects release 9.2 when untrusted parties can reach it over HTTP.

**Timing**Oracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.  
[Open the supporting record](#cve-cve-2026-60606)
4. 04  
### FDA says affected ENROUTE catheters should not be used  
FDA issued a potentially high-risk Early Alert for Boston Scientific ENROUTE NPS and NPS Plus products and directed affected product to be removed from use and distribution.  
The instruction immediately removes affected transcarotid neuroprotection catheters from procedural inventory.  
Affected ENROUTE inventory should remain segregated and out of use while FDA reviews the potentially high-risk issue and determines its recall classification.

**Timing**21 July 2026  
[Open the supporting record](#clinical-fda-boston-enroute-2026-07-21)
5. 05  
### OpenAI reports an incident in a Hugging Face evaluation dependency  
OpenAI disclosed a security incident involving model-evaluation work conducted through Hugging Face infrastructure.  
Healthcare AI programs using comparable external evaluation platforms inherit a dependency path involving credentials, model access and third-party infrastructure.  
External evaluation platforms extend an AI program’s trust boundary to the credentials and model access they handle.

**Timing**21 July 2026  
[Open the supporting record](#ai-openai-huggingface-eval-incident-2026-07-21)

## Healthcare Incident Watch

Healthcare Incident Watch

### Craneware reports data theft but no service disruption

Craneware disclosed unauthorized access to a subset of its data environment and said the incident had been contained. The company reported no disruption to customer services or its operations.

A significant volume of file names was viewed and exfiltrated, together with some employee data and a subset of customer and partner records. The investigation has not resolved the precise nature or scope, including the final population affected; the disclosure neither identifies an attacker nor links the incident to patient harm.

[Read Craneware’s incident notice](https://www.investegate.co.uk/announcement/rns/craneware--crw/notice-of-cyber-security-incident/9675808?ref=clinicalcyber.com)

Healthcare Incident Watch

### ShinyHunters uses identity resets to reach health-sector SaaS

Health-ISAC flagged an increase in successful ShinyHunters attacks affecting the health sector and documented the attack pattern: phone-based social engineering persuades help desks to reset multifactor authentication or re-enroll a device, enabling takeover of Microsoft Entra, Okta or Google SSO accounts and access to connected SaaS platforms for data theft and extortion.

The warning is sector-level rather than a comprehensive victim inventory. Its defensive focus is the identity control plane: stronger identity proofing, phishing-resistant MFA, tighter SaaS logging and containment playbooks prepared for rapid account takeover.

[Read the Health-ISAC advisory](https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/?ref=clinicalcyber.com)

Healthcare Incident Watch

### Malware disruption closes AnMed offices and imaging

AnMed said malware was impacting its network, creating a cybersecurity disruption whose scope beyond the immediate service plan was still developing. The notice did not attribute an attacker or establish ransomware or data exposure.

Medical Group offices and Imaging Services were scheduled to close Monday, July 27, while Urgent Care, Kids Care, Integrated Therapy and Laboratory Services were scheduled to open. Procedure, transfer, diversion and operational decisions were being guided by patient safety, with AnMed coordinating care access with EMS and regional hospitals.

[Read AnMed’s systems disruption notice](https://anmed.org/about/news-media/news/anmed-systems-disruption?ref=clinicalcyber.com)

## Regulatory & Privacy

Regulatory & Privacy

### Operation Vital Signs tests response across critical health functions

HSCC’s Operation Vital Signs invited all regulated entities to a national virtual exercise on July 21–22 testing enterprise and cross-sector response and recovery, including effects on critical functions and patient safety.

Pairing recovery mechanics with patient safety makes the exercise a test of sector coordination around care-critical functions. After-action results remain the next milestone.

[View Operation Vital Signs information](https://healthsectorcouncil.org/?ref=clinicalcyber.com)

Regulatory & Privacy

### Health-ISAC’s first CISO benchmark spans five industry segments

Health-ISAC released its first CISO benchmarking report, drawing on survey input from 76 security leaders across providers, payers, pharmaceutical companies, medical-device organizations and global operations.

The report covers health-sector risks, emerging threats, governance, staffing, budgets, technology investment and CISO priorities for the next 12 to 24 months. Its 76-participant sample offers a peer benchmark across several industry segments, with broader interpretation dependent on the report’s methodology.

[Read the CISO Benchmarking Report](https://health-isac.org/2026-health-isac-ciso-benchmarking-report/?ref=clinicalcyber.com)

Regulatory & Privacy

### Health-ISAC puts AI exposure, medical IoT and policy on one agenda

Health-ISAC’s July 22 Quarterly Threat Insights briefing placed AI-server and MCP exposure, patient safety, legacy medical IoT and U.S. critical-infrastructure policy on one health-sector readiness agenda.

The grouping connects emerging AI dependencies, aging connected devices and policy developments within clinical technology planning. The page sets a readiness agenda and creates no new legal duty.

[Watch Quarterly Threat Insights](https://health-isac.org/quarterly-threat-insights-q2-2026/?ref=clinicalcyber.com)

Regulatory & Privacy

### FDA and CMS test a real-world evidence route for digital health

Selecting the first TEMPO participant starts practical testing of FDA’s pilot regulatory approach; product approval and real-world outcome evidence remain later milestones.

[Read the FDA TEMPO announcement](https://www.fda.gov/news-events/press-announcements/fda-announces-first-participant-selected-tempo-digital-health-devices-pilot?ref=clinicalcyber.com)

## AI & Clinical Automation Watch

AI & Clinical Automation

### OpenAI incident exposes a third-party model-evaluation dependency

OpenAI disclosed a security incident in model-evaluation work using Hugging Face infrastructure. The compromise exposed a third-party dependency path spanning external evaluation platforms, credentials and model access.

Evaluation infrastructure therefore belongs inside the AI trust boundary, with credentials and model access as the principal control points. OpenAI reported no healthcare involvement.

[Read OpenAI’s disclosure](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=clinicalcyber.com)

AI & Clinical Automation Watch

### Health-ISAC puts AI-server and MCP exposure on the health-sector agenda

AI-server and MCP exposure belongs in clinical technology risk planning because the same readiness agenda connects it to patient safety and legacy medical IoT.

[Watch Quarterly Threat Insights](https://health-isac.org/quarterly-threat-insights-q2-2026/?ref=clinicalcyber.com)

AI & Clinical Automation

### FDA selects Dexcom as the first TEMPO pilot participant

FDA selected Dexcom as the first participant in the TEMPO digital-health devices pilot on July 22, activating the pilot’s first manufacturer participation and FDA’s continuing evaluation of the Dexcom Glucose Health Program.

The selection moves TEMPO into a live test of how digital-health devices can generate real-world evidence for chronic-disease care. Product approval and outcome evidence remain later milestones.

[Read the FDA TEMPO announcement](https://www.fda.gov/news-events/press-announcements/fda-announces-first-participant-selected-tempo-digital-health-devices-pilot?ref=clinicalcyber.com)

## Priority CVEs

[CVE-2026-60644](https://nvd.nist.gov/vuln/detail/CVE-2026-60644?ref=clinicalcyber.com)Oracle WebCenter ContentNewCritical · CVSS 3.1 10.0 (Oracle/CNA)

Rank 1No confirmed exploitation; not in CISA KEV at cutoffExposure assessment · contain accessReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026

What is it?

An unauthenticated attacker can take over an affected Oracle WebCenter Content server with an HTTP request, potentially affecting connected products as well.

Why should healthcare care?

A hospital using WebCenter Content for policy, intranet or administrative documents could have those documents exposed, altered or made unavailable if the server is taken over.

What is the remediation?

Identify self-managed WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 instances reachable over HTTP from untrusted networks, then remove that reachability with network controls.

Affected versions

12.2.1.4.0 and 14.1.2.0.0

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Primary sources

[Oracle Cpu](https://www.oracle.com/security-alerts/cpujul2026.html?ref=clinicalcyber.com)[Cve Cve-2026-60644](https://cveawg.mitre.org/api/cve/CVE-2026-60644?ref=clinicalcyber.com)[Oracle WebCenter Content 12c Marketplace 26.7.1](https://docs.oracle.com/en/cloud/paas/webcenter-content/content-marketplace-new/index.html?ref=clinicalcyber.com)[Oracle WebCenter Content 14c Marketplace 26.7.1](https://docs.oracle.com/en/cloud/paas/webcenter-content/content-marketplace-whatsnew/index.html?ref=clinicalcyber.com)

[CVE-2026-60606](https://nvd.nist.gov/vuln/detail/CVE-2026-60606?ref=clinicalcyber.com)Oracle PeopleSoft Enterprise CC Common Application ObjectsNewCritical · CVSS 3.1 9.1 (Oracle/CNA)

Rank 2No confirmed exploitation; not in CISA KEV at cutoffExposure assessment · contain accessReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026

What is it?

An unauthenticated attacker can use HTTP requests to read, create, alter or delete data available through PeopleSoft Common Application Objects 9.2.

Why should healthcare care?

A hospital using PeopleSoft 9.2 for HR, payroll, finance or supply-chain administration could have records and transactions disclosed or changed through the affected component.

What is the remediation?

Identify PeopleSoft Enterprise CC Common Application Objects 9.2 endpoints reachable over HTTP from untrusted networks, then restrict access to trusted networks until the release-specific PUM/PRP custom change package is deployed.

Affected versions

9.2

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Primary sources

[Oracle Cpu](https://www.oracle.com/security-alerts/cpujul2026.html?ref=clinicalcyber.com)[Cve Cve-2026-60606](https://cveawg.mitre.org/api/cve/CVE-2026-60606?ref=clinicalcyber.com)[Oracle PeopleSoft security-fix process](https://blogs.oracle.com/peoplesoft/stay-alert-stay-current-finding-peoplesoft-security-fixes-faster?ref=clinicalcyber.com)

[CVE-2026-66040](https://nvd.nist.gov/vuln/detail/CVE-2026-66040?ref=clinicalcyber.com)FFmpegNewHigh · CVSS 4.0 8.7 (VulnCheck/CNA)

Rank 3No confirmed exploitation; not in CISA KEV at cutoffInterim containmentReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026

What is it?

A crafted PNG or APNG eXIf chunk can make FFmpeg write past a heap buffer, crashing the process or potentially running attacker-controlled code.

Why should healthcare care?

Healthcare web, imaging-export or communications systems that encode untrusted PNG or APNG files with FFmpeg could suffer a media-processing outage or code execution under the service account.

What is the remediation?

Disable or isolate FFmpeg PNG/APNG encoding for untrusted input carrying eXIf metadata until a supported fixed release or backport is available.

Affected versions

FFmpeg 8.1.2 and earlier

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Alternative authoritative CVSS

High · CVSS 3.1 8.8 (NVD)

Primary sources

[Ffmpeg Patch](https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc?ref=clinicalcyber.com)[Cve Cve-2026-66040](https://cveawg.mitre.org/api/cve/CVE-2026-66040?ref=clinicalcyber.com)[FFmpeg official releases](https://ffmpeg.org/download.html?ref=clinicalcyber.com)[FFmpeg security and backport status](https://www.ffmpeg.org/security.html?ref=clinicalcyber.com)

[CVE-2026-56167](https://nvd.nist.gov/vuln/detail/CVE-2026-56167?ref=clinicalcyber.com)Microsoft Azure AI SearchNewHigh · CVSS 3.1 8.5 (Microsoft/CNA)

Rank 4No confirmed exploitation; not in CISA KEV at cutoffVendor-managed · no customer actionReported 23 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026

What is it?

An authorized attacker could exploit server-side request forgery in Azure AI Search to cross a service boundary and gain additional privileges.

Why should healthcare care?

If Azure AI Search indexes clinical, research or administrative content, an authorized account could reach resources outside its intended search-service boundary.

What is the remediation?

No customer action is required; Microsoft reports Azure AI Search is fully mitigated as a hosted service.

Affected versions

Authoritative record does not specify

First reported

23 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Primary sources

[Msrc Azure](https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-56167?ref=clinicalcyber.com)[Msrc Azure Products](https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?$filter=cveNumber%20eq%20%27CVE-2026-56167%27&ref=clinicalcyber.com)[Cve Cve-2026-56167](https://cveawg.mitre.org/api/cve/CVE-2026-56167?ref=clinicalcyber.com)

[CVE-2026-10818](https://nvd.nist.gov/vuln/detail/CVE-2026-10818?ref=clinicalcyber.com)WPForms ProNewHigh · CVSS 3.1 8.1 (Wordfence/CNA)

Rank 5No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 25 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026

What is it?

WPForms Pro writes uploaded chunks before checking their file type, allowing an unauthenticated attacker to place a potentially executable file on the WordPress host.

Why should healthcare care?

A healthcare website using WPForms Pro for public appointment, referral or contact forms could have its WordPress host compromised through the upload flaw, disrupting the site or exposing data available to that host.

What is the remediation?

Upgrade WPForms Pro to version 1.10.2 or later.

Affected versions

WPForms Pro 1.10.1.1 and earlier

First reported

25 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Primary sources

[Wpforms Changelog](https://wpforms.com/docs/how-to-view-recent-changes-to-the-wpforms-plugin-changelog/?ref=clinicalcyber.com)[Cve Cve-2026-10818](https://cveawg.mitre.org/api/cve/CVE-2026-10818?ref=clinicalcyber.com)

## Clinical Engineering & Medical Device Watch

Immediate stop-use instructionFDA Early Alert — potentially high risk · classification pending

Clinical Engineering

### FDA directs removal of affected ENROUTE neuroprotection catheters

The ENROUTE Transcarotid Neuroprotection System and ENROUTE Transcarotid Neuroprotection System Plus reverse blood flow to carry emboli away from carotid circulation before lesion crossing and during lesion manipulation. Specific lots can experience arterial sheath-tip separation or partial separation during use. A retained tip may require endovascular or surgical retrieval and can lead to embolism, stroke, transient ischemic attack, restenosis or thrombosis. Boston Scientific reported one serious injury and no deaths as of July 9.

FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should stop using and segregate affected product, return it and trace units distributed to downstream facilities. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.

[Read the FDA ENROUTE Early Alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-percutaneous-catheter-issue-boston-scientific?ref=clinicalcyber.com)

Immediate stop-use instructionFDA Early Alert — potentially high risk · classification pending

Clinical Engineering

### FDA flags three lots of Baxter Duo-Vent administration sets

Baxter Duo-Vent solution sets deliver fluid into the vascular system. Affected lots can develop air bubbles in the drip chamber and tubing when a pressure cuff is used or the tubing is flushed in the fully open position. Without an air-in-line detector, air can reach the patient; patients with a patent foramen ovale or another right-to-left shunt face the risk of stroke, myocardial ischemia or death. Baxter reported no serious injuries or deaths as of July 15.

FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should quarantine and stop using affected lots, return them and obtain replacements. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.

[Read the FDA Baxter Early Alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-intravascular-administration-set-issue-baxter?ref=clinicalcyber.com)

## CCD CVE Tracker

New, updated and continuing vulnerabilities under active CCD watch.

**17**Active watch

**5**New this week

**0**Updated this week

**12**Continuing watch

**1** Critical**2** KEV / known exploited

Search the ledger 

All activeNewUpdatedContinuingCriticalKEV / known exploited

Expand allCollapse all

New this week0 additional new CVEs — 5 shown in Priority CVEsUpdated this week0 updated CVEsContinuing watch12 continuing CVEs

[CVE-2026-8655](https://nvd.nist.gov/vuln/detail/CVE-2026-8655?ref=clinicalcyber.com)NetScaler ADCContinuing watchCVSS 9.8

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

Memory-overflow flaws can deny service when NetScaler ADC operates as an Oracle load balancer, DNS proxy or recursive resolver.

Why should healthcare care?

A hospital using an affected NetScaler ADC for Oracle load balancing or DNS could lose application routing or name resolution.

What is the remediation?

Install NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later on affected Oracle load-balancer or DNS appliances, checking the configuration strings listed in CTX696604 to identify applicable systems.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-8655](https://cveawg.mitre.org/api/cve/CVE-2026-8655?ref=clinicalcyber.com)

[CVE-2026-8452](https://nvd.nist.gov/vuln/detail/CVE-2026-8452?ref=clinicalcyber.com)NetScaler ADC and NetScaler GatewayContinuing watchCVSS 9.8

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

A memory-overflow flaw can make an affected NetScaler Gateway or AAA virtual server behave unpredictably or stop serving traffic.

Why should healthcare care?

A hospital using NetScaler for SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA access could lose remote-access or authentication availability during an attack.

What is the remediation?

Upgrade affected Gateway or AAA appliances to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, using add authentication vserver and add vpn vserver entries to identify applicable configurations.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-8452](https://cveawg.mitre.org/api/cve/CVE-2026-8452?ref=clinicalcyber.com)

[CVE-2026-8451](https://nvd.nist.gov/vuln/detail/CVE-2026-8451?ref=clinicalcyber.com)NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

Insufficient input validation can make a NetScaler appliance configured as a SAML identity provider read past a memory boundary.

Why should healthcare care?

A hospital using a customer-managed NetScaler appliance as its SAML identity provider could have appliance memory exposed or sign-on service interrupted.

What is the remediation?

Upgrade affected NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and identify SAML IdP configurations by checking for add authentication samlIdPProfile entries.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-8451](https://cveawg.mitre.org/api/cve/CVE-2026-8451?ref=clinicalcyber.com)

[CVE-2026-58014](https://nvd.nist.gov/vuln/detail/CVE-2026-58014?ref=clinicalcyber.com)GNOME GLib and Red Hat Enterprise Linux glib2Continuing watchHIGH

No confirmed exploitation; not in CISA KEV at cutoffMitigation availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

An empty value in an untrusted .desktop or .ini key file can trigger a one-byte out-of-bounds access in GLib and, in some cases, cause a denial of service.

Why should healthcare care?

General enterprise exposure—not a healthcare-specific finding—this CVE is retained only for organizations whose application inventory contains the affected GLib parser and a path for untrusted .desktop or .ini key files to reach it.

What is the remediation?

Upgrade upstream GLib to 2.88.1 or later; for affected Red Hat packages without an erratum, allow applications to load only trusted key files or reject empty values before calling g\_key\_file\_get\_locale\_string\_list.

Affected versions

Upstream GLib before 2.88.1; vendor-listed RHEL glib2 packages without an available erratum

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Redhat Cve](https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-58014.json?ref=clinicalcyber.com)[Cve Cve-2026-58014](https://cveawg.mitre.org/api/cve/CVE-2026-58014?ref=clinicalcyber.com)

[CVE-2026-48558](https://nvd.nist.gov/vuln/detail/CVE-2026-48558?ref=clinicalcyber.com)SimpleHelpContinuing watchCritical · CVSS 3.1 10.0 (VulnCheck/CNA)

Known exploited; CISA KEVUpgrade availableDue 2 July 2026Reported 29 June 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

A SimpleHelp server can accept an unsigned OIDC identity token and grant an unauthenticated attacker a technician session, potentially bypassing multifactor authentication.

Why should healthcare care?

A hospital using OIDC for SimpleHelp technician login could give an attacker a trusted remote-support session with access to managed endpoints.

What is the remediation?

Upgrade SimpleHelp 5.5 deployments to 5.5.16 or later and 6.0 prereleases to 6.0 RC2 or later; if the update cannot be completed immediately, disconnect or stop the server until the exposure is resolved.

Affected versions

SimpleHelp 5.5.15 and earlier; SimpleHelp 6.0 prereleases before RC2

Remediation due

2 July 2026

First reported

29 June 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Alternative authoritative CVSS

Critical · CVSS 4.0 9.5 (VulnCheck/CNA)

Primary sources

[Simplehelp Notice](https://guides.simple-help.com/kb---security-vulnerabilities-05-2026?ref=clinicalcyber.com)[Simplehelp Release](https://simple-help.com/release-news/5-5-16?ref=clinicalcyber.com)[Cve Cve-2026-48558](https://cveawg.mitre.org/api/cve/CVE-2026-48558?ref=clinicalcyber.com)[Cisa Kev](https://www.cisa.gov/sites/default/files/feeds/known%5Fexploited%5Fvulnerabilities.json?ref=clinicalcyber.com)

[CVE-2026-45659](https://nvd.nist.gov/vuln/detail/CVE-2026-45659?ref=clinicalcyber.com)Microsoft SharePoint ServerContinuing watchHigh · CVSS 3.1 8.8 (Microsoft/CNA)

Known exploited; CISA KEVPatch available — KB5002868 / KB5002870 / KB5002863Due 4 July 2026Reported 1 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

An authenticated SharePoint site member can send untrusted serialized data to an on-premises server and execute code remotely.

Why should healthcare care?

A hospital running on-premises SharePoint for internal documents or collaboration could have the server taken over and its content exposed or altered by an authenticated site member.

What is the remediation?

Install KB5002868 on SharePoint 2016, KB5002870 on SharePoint 2019 or KB5002863 on SharePoint Subscription Edition, reaching builds 16.0.5552.1002, 16.0.10417.20128 or 16.0.19725.20280 respectively.

Affected versions

SharePoint Server 2016 before build 16.0.5552.1002; SharePoint Server 2019 before 16.0.10417.20128; SharePoint Subscription Edition before 16.0.19725.20280

Remediation due

4 July 2026

First reported

1 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Msrc Sharepoint](https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-45659?ref=clinicalcyber.com)[Msrc Sharepoint Products](https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?$filter=cveNumber%20eq%20%27CVE-2026-45659%27&ref=clinicalcyber.com)[Cve Cve-2026-45659](https://cveawg.mitre.org/api/cve/CVE-2026-45659?ref=clinicalcyber.com)

[CVE-2026-13784](https://nvd.nist.gov/vuln/detail/CVE-2026-13784?ref=clinicalcyber.com)Google ChromeContinuing watchHIGH

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

A second use-after-free in Chrome Views can corrupt heap memory when a user performs specific gestures on a crafted HTML page.

Why should healthcare care?

A healthcare endpoint running an older Chrome build could lose browser integrity or availability when its user interacts with a malicious page.

What is the remediation?

Install Chrome 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Chrome Release](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop%5F0175352312.html?ref=clinicalcyber.com)[Cve Cve-2026-13784](https://cveawg.mitre.org/api/cve/CVE-2026-13784?ref=clinicalcyber.com)

[CVE-2026-13783](https://nvd.nist.gov/vuln/detail/CVE-2026-13783?ref=clinicalcyber.com)Google ChromeContinuing watchHIGH

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

A crafted web page and specific user-interface gestures can trigger a use-after-free in Chrome Views and corrupt heap memory.

Why should healthcare care?

A hospital user browsing external content with an outdated Chrome build could have the browser compromised or crashed after interacting with a crafted page.

What is the remediation?

Update Windows and macOS endpoints to Chrome 150.0.7871.47 or later and Linux endpoints to 150.0.7871.46 or later.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Chrome Release](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop%5F0175352312.html?ref=clinicalcyber.com)[Cve Cve-2026-13783](https://cveawg.mitre.org/api/cve/CVE-2026-13783?ref=clinicalcyber.com)

[CVE-2026-13774](https://nvd.nist.gov/vuln/detail/CVE-2026-13774?ref=clinicalcyber.com)Google ChromeContinuing watchHIGH

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026

What is it?

A malicious Chrome extension can trigger a use-after-free in the Extensions component and execute attacker-controlled code.

Why should healthcare care?

On hospital workstations that permit extension installation, a user who installs a malicious Chrome extension could run attacker code in the browser context.

What is the remediation?

Update desktop Chrome to 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux, and enforce the managed-browser extension allowlist.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Primary sources

[Chrome Release](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop%5F0175352312.html?ref=clinicalcyber.com)[Cve Cve-2026-13774](https://cveawg.mitre.org/api/cve/CVE-2026-13774?ref=clinicalcyber.com)

[CVE-2026-13474](https://nvd.nist.gov/vuln/detail/CVE-2026-13474?ref=clinicalcyber.com)NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5

No confirmed exploitation; not in CISA KEV at cutoffConfiguration change availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026

What is it?

Malformed HTTP/2 requests can exhaust resources on an affected NetScaler virtual server and stop it from serving traffic.

Why should healthcare care?

A hospital using an HTTP/2-enabled NetScaler virtual server for load balancing, content switching or VPN access could lose access to applications or remote connectivity during an attack.

What is the remediation?

Upgrade to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later and, on non-HTTP-Strict profiles, run set ns httpProfile <profile\_name> -http2SmallWndTimeout 30.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-13474](https://cveawg.mitre.org/api/cve/CVE-2026-13474?ref=clinicalcyber.com)

[CVE-2026-10817](https://nvd.nist.gov/vuln/detail/CVE-2026-10817?ref=clinicalcyber.com)NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026

What is it?

Malformed traffic can make a NetScaler TCP profile read past its memory boundary when TCP timestamps are enabled, potentially disclosing appliance memory.

Why should healthcare care?

A hospital virtual server or service using a timestamp-enabled NetScaler TCP profile could expose appliance memory through malformed traffic.

What is the remediation?

Upgrade affected NetScaler services to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, then inventory profiles with TimeStamp ENABLED and map them to virtual servers and services.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-10817](https://cveawg.mitre.org/api/cve/CVE-2026-10817?ref=clinicalcyber.com)

[CVE-2026-10816](https://nvd.nist.gov/vuln/detail/CVE-2026-10816?ref=clinicalcyber.com)NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5

No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026

What is it?

An unauthenticated attacker on an adjacent network can read arbitrary appliance files when a NetScaler management address is reachable.

Why should healthcare care?

A hospital with a reachable NetScaler management address could have configuration or other appliance-accessible files disclosed without authentication.

What is the remediation?

Update management-reachable NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and restrict access to NSIP, Cluster Management IP and management-enabled SNIP addresses.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

Primary sources

[Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)[Cve Cve-2026-10816](https://cveawg.mitre.org/api/cve/CVE-2026-10816?ref=clinicalcyber.com)

[**9 records left active watch this week** — view archive](https://clinicalcyber.com/cve-archive/?ref=clinicalcyber.com)

## Sources and Methodology

Evidence window: 20–26 July 2026; cutoff 27 July at 12:00 a.m. America/New\_York.

Open Source IndexIssue-level sources 3
1. [Health-ISAC ShinyHunters advisory](https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/?ref=clinicalcyber.com)
2. [CVE Program CNA record (Wordfence)](https://cveawg.mitre.org/api/cve/CVE-2026-10818?ref=clinicalcyber.com)
3. [WPForms changelog](https://wpforms.com/docs/how-to-view-recent-changes-to-the-wpforms-plugin-changelog/?ref=clinicalcyber.com)
Healthcare Incident Watch 3
1. [Craneware incident notice](https://www.investegate.co.uk/announcement/rns/craneware--crw/notice-of-cyber-security-incident/9675808?ref=clinicalcyber.com)
2. [Health-ISAC ShinyHunters advisory](https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/?ref=clinicalcyber.com)
3. [AnMed systems disruption notice](https://anmed.org/about/news-media/news/anmed-systems-disruption?ref=clinicalcyber.com)
Regulatory & Privacy 4
1. [Health Sector Coordinating Council](https://healthsectorcouncil.org/?ref=clinicalcyber.com)
2. [Health-ISAC CISO Benchmarking Report](https://health-isac.org/2026-health-isac-ciso-benchmarking-report/?ref=clinicalcyber.com)
3. [Health-ISAC Quarterly Threat Insights](https://health-isac.org/quarterly-threat-insights-q2-2026/?ref=clinicalcyber.com)
4. [FDA TEMPO announcement](https://www.fda.gov/news-events/press-announcements/fda-announces-first-participant-selected-tempo-digital-health-devices-pilot?ref=clinicalcyber.com)
AI & Clinical Automation Watch 3
1. [OpenAI security disclosure](https://openai.com/index/hugging-face-model-evaluation-security-incident/?ref=clinicalcyber.com)
2. [Health-ISAC Quarterly Threat Insights](https://health-isac.org/quarterly-threat-insights-q2-2026/?ref=clinicalcyber.com)
3. [FDA TEMPO announcement](https://www.fda.gov/news-events/press-announcements/fda-announces-first-participant-selected-tempo-digital-health-devices-pilot?ref=clinicalcyber.com)
Other supporting sources 2
1. [FDA ENROUTE Early Alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-percutaneous-catheter-issue-boston-scientific?ref=clinicalcyber.com)
2. [FDA Baxter Duo-Vent Early Alert](https://www.fda.gov/medical-devices/medical-device-recalls-and-early-alerts/early-alert-intravascular-administration-set-issue-baxter?ref=clinicalcyber.com)
CVE sources 35
1. [Oracle Cpu](https://www.oracle.com/security-alerts/cpujul2026.html?ref=clinicalcyber.com)
2. [Cve Cve-2026-60644](https://cveawg.mitre.org/api/cve/CVE-2026-60644?ref=clinicalcyber.com)
3. [Oracle WebCenter Content 12c Marketplace 26.7.1](https://docs.oracle.com/en/cloud/paas/webcenter-content/content-marketplace-new/index.html?ref=clinicalcyber.com)
4. [Oracle WebCenter Content 14c Marketplace 26.7.1](https://docs.oracle.com/en/cloud/paas/webcenter-content/content-marketplace-whatsnew/index.html?ref=clinicalcyber.com)
5. [Cve Cve-2026-60606](https://cveawg.mitre.org/api/cve/CVE-2026-60606?ref=clinicalcyber.com)
6. [Oracle PeopleSoft security-fix process](https://blogs.oracle.com/peoplesoft/stay-alert-stay-current-finding-peoplesoft-security-fixes-faster?ref=clinicalcyber.com)
7. [Ffmpeg Patch](https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc?ref=clinicalcyber.com)
8. [Cve Cve-2026-66040](https://cveawg.mitre.org/api/cve/CVE-2026-66040?ref=clinicalcyber.com)
9. [FFmpeg official releases](https://ffmpeg.org/download.html?ref=clinicalcyber.com)
10. [FFmpeg security and backport status](https://www.ffmpeg.org/security.html?ref=clinicalcyber.com)
11. [Wpforms Changelog](https://wpforms.com/docs/how-to-view-recent-changes-to-the-wpforms-plugin-changelog/?ref=clinicalcyber.com)
12. [Cve Cve-2026-10818](https://cveawg.mitre.org/api/cve/CVE-2026-10818?ref=clinicalcyber.com)
13. [Msrc Azure](https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-56167?ref=clinicalcyber.com)
14. [Msrc Azure Products](https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?$filter=cveNumber%20eq%20%27CVE-2026-56167%27&ref=clinicalcyber.com)
15. [Cve Cve-2026-56167](https://cveawg.mitre.org/api/cve/CVE-2026-56167?ref=clinicalcyber.com)
16. [Netscaler Bulletin](https://support.citrix.com/external/article/CTX696604/netscaler-adc-and-netscaler-gateway-secu.html?ref=clinicalcyber.com)
17. [Cve Cve-2026-10816](https://cveawg.mitre.org/api/cve/CVE-2026-10816?ref=clinicalcyber.com)
18. [Cve Cve-2026-10817](https://cveawg.mitre.org/api/cve/CVE-2026-10817?ref=clinicalcyber.com)
19. [Cve Cve-2026-13474](https://cveawg.mitre.org/api/cve/CVE-2026-13474?ref=clinicalcyber.com)
20. [Chrome Release](https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop%5F0175352312.html?ref=clinicalcyber.com)
21. [Cve Cve-2026-13774](https://cveawg.mitre.org/api/cve/CVE-2026-13774?ref=clinicalcyber.com)
22. [Cve Cve-2026-13783](https://cveawg.mitre.org/api/cve/CVE-2026-13783?ref=clinicalcyber.com)
23. [Cve Cve-2026-13784](https://cveawg.mitre.org/api/cve/CVE-2026-13784?ref=clinicalcyber.com)
24. [Msrc Sharepoint](https://api.msrc.microsoft.com/sug/v2.0/en-US/vulnerability/CVE-2026-45659?ref=clinicalcyber.com)
25. [Msrc Sharepoint Products](https://api.msrc.microsoft.com/sug/v2.0/en-US/affectedProduct?$filter=cveNumber%20eq%20%27CVE-2026-45659%27&ref=clinicalcyber.com)
26. [Cve Cve-2026-45659](https://cveawg.mitre.org/api/cve/CVE-2026-45659?ref=clinicalcyber.com)
27. [Simplehelp Notice](https://guides.simple-help.com/kb---security-vulnerabilities-05-2026?ref=clinicalcyber.com)
28. [Simplehelp Release](https://simple-help.com/release-news/5-5-16?ref=clinicalcyber.com)
29. [Cve Cve-2026-48558](https://cveawg.mitre.org/api/cve/CVE-2026-48558?ref=clinicalcyber.com)
30. [CISA Known Exploited Vulnerabilities catalog (linked in applicable CVE records)](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?ref=clinicalcyber.com)
31. [Redhat Cve](https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-58014.json?ref=clinicalcyber.com)
32. [Cve Cve-2026-58014](https://cveawg.mitre.org/api/cve/CVE-2026-58014?ref=clinicalcyber.com)
33. [Cve Cve-2026-8451](https://cveawg.mitre.org/api/cve/CVE-2026-8451?ref=clinicalcyber.com)
34. [Cve Cve-2026-8452](https://cveawg.mitre.org/api/cve/CVE-2026-8452?ref=clinicalcyber.com)
35. [Cve Cve-2026-8655](https://cveawg.mitre.org/api/cve/CVE-2026-8655?ref=clinicalcyber.com)