21 July 2026
1. What is being reported?
Researchers have discovered new vulnerabilities, including some that allow remote code execution (RCE), meaning attackers could run harmful software on affected systems without permission. These issues affect widely used platforms such as WordPress websites, SharePoint collaboration tools, SonicWall network devices, and certain AI services.
2. What this means in plain English
If your organisation uses any of these technologies, attackers might exploit these weaknesses to access sensitive information, disrupt your services, or take control of your systems. This could lead to data breaches, downtime, or loss of trust from your customers or members.
3. Could this affect a small business?
Small businesses, charities, and clubs using WordPress websites, SharePoint for document sharing, SonicWall firewalls or VPNs, or AI tools could be at risk. If you do not use these technologies, you are less likely to be affected. Always check with your IT provider to confirm.
4. What to do now
- Check if your WordPress site and plugins are up to date and apply any security patches immediately.
- Ask your IT provider if your SharePoint environment has been updated to fix known vulnerabilities.
- Ensure your SonicWall devices have the latest firmware installed from official sources.
- Review your use of AI services and follow any security guidance provided by the service supplier.
5. Ask your IT provider
Can you confirm whether our WordPress, SharePoint, SonicWall devices, and AI services are protected against the latest reported vulnerabilities from July 2026?
6. Bottom line
Stay proactive by updating your software and checking with your IT support to reduce the risk from these new security flaws.
Information based on reputable security reporting and CISA Known Exploited Vulnerabilities list.