decrypted · 7 july 2026 · vulnerabilities and patching
Patching Is Necessary. It Isn't Sufficient.
Three stories this week share an uncomfortable thread: patching a vulnerability does not undo what already happened while it was open. Microsoft shipped a fix for a critical SharePoint flaw in May and judged the odds of attack "less likely". CISA has since confirmed active exploitation and ordered US federal agencies to remediate. Separately, Fortinet's older VPN credential problems have resurfaced at industrial scale on criminal forums, months after the underlying bugs were patched. And a small Yorkshire property developer has become the latest reminder that ransomware crews do not care how big you are, only how easy you are. Read together, they say the same thing: fixing the hole in the fence is the beginning of the job, not the end of it.
SharePoint's mispriced bet
CVE-2026-45659 is a flaw in how on-premises SharePoint Server handles "serialised" data: information packaged up for storage or transit and later unpacked back into a live object. Think of it as SharePoint's mailroom agreeing to unwrap any parcel handed in by a signed-in colleague and carry out whatever instructions are folded inside, rather than just filing the contents. Anyone with the standard "Site Member" contributor role, nothing more, can craft a malicious parcel and get code running on the server.
Microsoft patched it in May and rated real-world exploitation "less likely". CISA has now added it to the Known Exploited Vulnerabilities catalogue, confirming active attacks and giving US federal agencies until 4 July to patch or disconnect. On-premises SharePoint remains common across UK local government, universities and law firms, often chosen precisely for the control it gives an organisation over where its data sits. That control only pays off if the patching that comes with it is treated as non-negotiable. The Secure by Design lesson here is about the severity call, not the patch itself: a design that lets routine, low-privilege authentication unlock full code execution has already blurred the line between "authenticated" and "trusted", and no amount of optimistic scoring changes that afterwards.
FortiBleed: the credentials outlived the patch
Researchers have identified a dataset of VPN and administrator credentials for roughly 74,000 internet-facing Fortinet FortiGate firewalls, harvested using a dedicated GPU cracking cluster and now circulating on criminal forums. CISA has urged every FortiGate owner to terminate active SSL VPN and administrative sessions and reset credentials outright, rather than wait to confirm they are affected. The precise route to the data is disputed, but the pattern is familiar: Fortinet devices have a long history of credential-exposing flaws, some dating back years, and organisations that patched the software often never rotated the secrets that had already sat in exported configuration files.
That is the real lesson. A patch fixes the code; it has no idea which passwords, session tokens or API keys passed through the vulnerable component while it was broken. Any remediation process that ends at "patched" and never asks "what needs rotating" is only half finished. For UK organisations running FortiGate or similar edge appliances, the practical move is to treat every credential that has ever touched an internet-facing device as potentially burned, and rotate on a schedule rather than only on suspicion.
A Yorkshire property firm and the SME reality
The extortion group SpaceBears has listed Blenheim, a property and architecture firm operating around Sheffield and the Peak District, on its leak site, claiming over 500GB of CRM records, financial data, building plans and buyer details. Blenheim has not confirmed the claim publicly, and for now it should be read as one, but the profile fits a familiar pattern: a firm holding rich, saleable data about wealthy clients, without the security budget of a bank.
The government's own Cyber Security Breaches Survey this year found smaller organisations backsliding on the basics: fewer risk assessments, fewer written policies, weaker continuity planning. None of the advice has changed in a decade: patch promptly, put multi-factor authentication on anything remote, keep backups genuinely offline and out of reach of a compromised network. The Secure by Design point for SMEs is not technical novelty, it is that these controls remain the highest-leverage spend precisely because attackers know most smaller firms still skip them.
Sources
- CISA Adds One Known Exploited Vulnerability to Catalog
- Microsoft said exploitation was 'less likely'... but CISA just added SharePoint RCE to KEV list
- CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
- Critical FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
- Ransom! Blenheim (JUL-2026)
- Cyber security breaches survey 2025/2026
If any of this touches systems you run or data you hold, get in touch and we'll help you work through it.
More like this
- The npm maintainer account North Korea phished, and the four packages it unlocked 31 july 2026
- The Department for Education's helpdesk, and the 607,000 records it was never built to hold 31 july 2026
- The SD-WAN orchestrator that needed no login, and the one before it 29 july 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.