Monthly Vuln Summary 2026-07 (26)
In-the-Wild CVE Review · 2026-07
26 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2026-20316 —
0.0— Cisco Secure Firewall Management Center (FMC) — Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated,… [KEV] [RANSOMWARE] - CVE-2025-68686 —
0.0— Fortinet FortiOS — Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch develope… [KEV] - CVE-2026-16812 —
0.0— Arista VeloCloud Orchestrator — Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO… [KEV] - CVE-2026-16232 —
0.0— Check Point SmartConsole — Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to a… [KEV] - CVE-2026-50522 —
0.0— Microsoft SharePoint — Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. [KEV] - CVE-2026-60137 —
0.0— WordPress Core — WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow… [KEV] - CVE-2026-63030 —
0.0— WordPress Core — WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be … [KEV] - CVE-2026-0770 —
0.0— Langflow Langflow — Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. [KEV] - CVE-2021-27137 —
0.0— DD-WRT DD-WRT — DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vu… [KEV] - CVE-2026-58644 —
0.0— Microsoft SharePoint — Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. [KEV] - CVE-2026-25089 —
0.0— Fortinet FortiSandbox — Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized comma… [KEV] - CVE-2026-39808 —
0.0— Fortinet FortiSandbox — Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests… [KEV] - CVE-2026-46817 —
0.0— Oracle E-Business Suite — Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. … [KEV] - CVE-2023-4346 —
0.0— KNX Association KNX Protocol Connection Authorization Option 1 — KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devi… [KEV] - CVE-2026-56155 —
0.0— Microsoft Active Directory Federation Services — Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally… [KEV] - CVE-2026-56164 —
0.0— Microsoft SharePoint Server — Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. [KEV] - CVE-2026-15409 —
0.0— SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make reque… [KEV] [RANSOMWARE] - CVE-2026-15410 —
0.0— SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execut… [KEV] [RANSOMWARE] - CVE-2008-4128 —
0.0— Cisco IOS — Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /le… [KEV] - CVE-2026-56291 —
0.0— Balbooa Forms — Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executab… [KEV] - CVE-2026-48939 —
0.0— iCagenda iCagenda — iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in… [KEV] - CVE-2026-48908 —
0.0— JoomShaper SP Page Builder — JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulti… [KEV] - CVE-2026-55255 —
0.0— Langflow Langflow — Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifyi… [KEV] - CVE-2026-56290 —
0.0— Joomlack Page Builder — Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload. [KEV] - CVE-2026-48282 —
0.0— Adobe ColdFusion — Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. [KEV] - CVE-2026-45659 —
0.0— Microsoft SharePoint Server — Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. [KEV] [RANSOMWARE]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.