Active-Exploitation
CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV
Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data — CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.
Coordinated Attack Hits 30+ Minnesota Water Utilities, Knocks a Treatment Plant Offline
A coordinated attack on internet-exposed PLCs disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, forcing manual control at multiple plants.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
Fastjson 1.x RCE (CVE-2026-16723) Under Active Attack — No Patch Coming
A pre-auth RCE in Fastjson 1.2.68–1.2.83 requires no AutoType and no gadget chain, is already under active attack across US, Singapore, and Canadian targets, and Alibaba has confirmed the 1.x line will not get a fix.
CVE-2026-16232: Check Point SmartConsole Auth Bypass Grants Full Admin — Actively Exploited, Added to CISA KEV
An unauthenticated attacker can steal a SmartConsole application login token and log into Check Point's Security Management Server with full admin rights. CVE-2026-16232 (CVSS 9.3) is under active exploitation and now sits in CISA's KEV catalog with a July 25 remediation deadline.
CVE-2026-50522: SharePoint RCE Under Active Exploitation, Attackers Stealing Machine Keys for Post-Patch Persistence
CVE-2026-50522, a critical 9.8 CVSS SharePoint deserialization RCE, is being actively exploited to steal machine keys that let attackers forge auth tokens and keep access even after the box is patched.
ServiceNow AI Platform Sandbox-Escape RCE (CVE-2026-6875) Under Active Exploitation
A pre-authentication sandbox-escape flaw in ServiceNow's AI Platform is being exploited in the wild against unpatched instances, with attackers reaching the same code-execution primitive through a gadget chain that diverges from the published proof-of-concept.
CVE-2026-50518: Unauthenticated Heap Overflow RCE in Windows DHCP Server, No Exploit Required to Care
CVE-2026-50518 is a CVSS 9.8 heap-based buffer overflow in Windows DHCP Server, exploitable pre-auth over the network with no user interaction. Microsoft rates it Exploitation More Likely.
wp2shell: A Two-CVE Chain Turns WordPress Core Into Pre-Auth RCE
CVE-2026-60137 and CVE-2026-63030 chain a REST API route-confusion bug with a WP_Query SQL injection to give unauthenticated attackers a path to full RCE on default WordPress installs.
AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug
A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.
CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17
Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.
Microsoft's July Patch Tuesday Breaks Its Own Record Again: 570 Flaws, Two Zero-Days Under Active Attack
Microsoft's largest Patch Tuesday ever fixes 570 vulnerabilities, including an exploited AD FS privilege-escalation zero-day, an exploited SharePoint EoP zero-day, and a publicly disclosed BitLocker bypass.
Langflow Hit With Its Second CISA KEV Entry in Four Months: CVE-2026-55255 IDOR Under Active Exploitation
CISA adds Langflow CVE-2026-55255, an IDOR letting authenticated attackers hijack other users' AI workflows, to its KEV catalog after Sysdig caught in-the-wild exploitation chained with secret harvesting.
CVE-2026-11405: Undocumented Admin Backdoor in Tenda Router Firmware, No Patch Available
CERT/CC disclosed a hardcoded backdoor password mechanism in Tenda router firmware that grants full admin access regardless of the real password — Tenda has not responded to coordination attempts since May, and there is no patch.
Gitea CVE-2026-20896: Docker Images Trusted a Spoofable Header for Admin Access, Now Under Active Probing
Gitea's official Docker images shipped with reverse-proxy header trust wide open by default, letting anyone who can reach the port impersonate any user including an admin — Sysdig has now caught the first in-the-wild probing, 13 days after disclosure.
PixelSmash: A 50KB Video File Turns FFmpeg's MagicYUV Decoder into RCE Against Jellyfin, Nextcloud, and OBS
A heap out-of-bounds write in FFmpeg's MagicYUV decoder (CVE-2026-8461, CVSS 8.8) lets a single crafted media file achieve remote code execution against Jellyfin, Nextcloud, and other self-hosted server infrastructure that auto-processes uploaded video.
SimpleHelp OIDC Auth Bypass (CVE-2026-48558) Under Active Exploitation, Deploying Djinn Stealer Against Dev Credentials
A critical unsigned-token flaw in SimpleHelp RMM's OIDC login is being exploited to plant a cross-platform infostealer that hunts for cloud, source-control, and AI-assistant credentials.
Adobe ColdFusion APSB26-68: Six CVSS 10.0 Flaws, and Exploitation Started Within Hours
Adobe's APSB26-68 bulletin patches 11 ColdFusion flaws — six rated CVSS 10.0 — including a Remote Development Services path-traversal bug (CVE-2026-48282) that attackers began probing within hours of disclosure.
CVE-2026-8451: A New CitrixBleed-Pattern Memory Overread Is Already Under Active Exploitation
Citrix patched CVE-2026-8451, a pre-auth memory overread in NetScaler's SAML IdP parser that leaks session tokens — and attackers were already exploiting it within 24 hours of disclosure.
CVE-2026-8037: Pre-Auth Root RCE in Progress Kemp LoadMaster Now Under Active Exploitation
CVE-2026-8037, a CVSS 9.8 uninitialized-heap flaw in Progress Kemp LoadMaster's escape_quotes() function, lets unauthenticated attackers run root commands on the load balancer's management API. eSentire observed exploitation attempts starting June 29.