HTG Threat Report

Threat Report 7/31/26

Written by Evan Kennedy | Jul 31, 2026, 3:35:51 PM

Google Chrome

 

Google has released updates addressing multiple vulnerabilities in Chrome, including flaws that could allow arbitrary code execution if a user visits a malicious website. An attacker could execute code using the privileges of the logged-in user, potentially installing malware, modifying data, or creating new accounts.

 
Affected Systems
  • Chrome prior to 151.0.7922.71/.72 for Windows and macOS
  • Chrome prior to 151.0.7922.71 for Linux
Risk
  • Large and Medium Businesses: High
  • Small Businesses: Medium
Remediation Recommendations
  • Update Google Chrome to the latest available version on all devices.
  • Apply the Principle of Least Privilege by limiting administrative access to only those users who require it.

 

Reference

Google Chrome Releases Blog:
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html

 

Adobe Products

 

Adobe has issued security updates for multiple products, including Adobe Bridge and Adobe Format Plugins. The most severe vulnerabilities could allow arbitrary code execution in the context of the logged-in user, potentially giving attackers the ability to install malware, modify files, or create privileged accounts..

 
Affected Systems
  • Adobe Bridge 15.1.6 (LTS) and earlier
  • Adobe Bridge 16.0.5 and earlier
  • Adobe Format Plugins 2026.05 and earlier

Risk
  • Large and Medium Businesses: High
  • Small Businesses: Medium
Remediation Recommendations
  • Update all Adobe products to the latest supported versions.
  • Limit administrative privileges using the Principle of Least Privilege.

References

Oracle Critical Patch Update

 

Oracle has released its latest Critical Patch Update, addressing vulnerabilities across numerous enterprise products. Several of these flaws could allow remote code execution if left unpatched.

 

Affected Systems

Includes, but is not limited to:

  • MySQL
  • Solaris
  • Java SE
  • Oracle Retail
Risk
  • Large and Medium Businesses: High
  • Small Businesses: High
Remediation Recommendations
  • Apply Oracle's latest Critical Patch Update across all affected systems.
  • Review systems for unsupported software versions and retire or upgrade where necessary.
  • Continue enforcing least-privilege access controls.

References
https://www.oracle.com/security-alerts/cpujul2026.html

 

VMware Products

 

Broadcom has released security updates addressing vulnerabilities affecting VMware infrastructure products. Successful exploitation could allow attackers to execute arbitrary code or compromise virtualization environments.

 

Affected Systems
  • VMware ESX 8.0
  • VMware vCenter 8.0
  • VMware Workstation 25H2
  • VMware Fusion 25H2
  • VMware Cloud Foundation
  • VMware vSphere Foundation
  • VMware Telco Cloud Platform
  • VMware Telco Cloud Infrastructure

Risk
  • Large and Medium Businesses: High
  • Small Businesses: Medium
Remediation Recommendations
  • Install the latest VMware security updates.
  • Verify virtualization infrastructure is running supported software versions.
  • Restrict administrative privileges and management access.


References

https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

 

Cisco Secure Firewall Management Center

 

Cisco has released updates for Cisco Secure Firewall Management Center (FMC) Software to address vulnerabilities that could allow an unauthenticated attacker to bypass authentication and obtain root-level access to affected systems.

Organizations exposing the FMC management interface to the internet face the highest level of risk.

 

Affected Systems

Cisco Secure FMC Software versions prior to patched releases for:

  • 7.0
  • 7.2
  • 7.4
  • 7.6
  • 7.7
  • 10.0

Risk
  • Large and Medium Businesses: High
  • Small Businesses: Medium
Remediation Recommendations
  • Apply Cisco's published hotfixes immediately.
  • Restrict management interfaces from public internet exposure whenever possible.
  • Review administrative access and enforce least-privilege permissions.

References