CISA Known Exploited Vulnerabilities Catalog: July 2026

CISA KEV
Download Now
CISA KEV July 2026 | Known Exploited Vulnerabilities Catalog Digest

Summary

The CISA-maintained KEV catalog is the authoritative source of vulnerabilities exploited in the wild; organizations should monitor it and prioritize remediation.

Notable additions include Cisco Secure Firewall Management Center, Arista VeloCloud Orchestrator, and several Microsoft SharePoint flaws, plus Fortinet, SonicWall, Oracle, WordPress, and Adobe products, and a legacy Cisco IOS CSRF flaw tied to Berserk Bear, Energetic Bear, and Static Tundra.


Vulnerability Details

The table below lists every CVE added to the KEV catalog in July 2026, with vendor/product, CVSS score, due date, and threat actor/tooling.

CVE IDVendor / ProductVulnerability NameCVSS 3.x ScoreDue DateKnown Threat Actor / Attack
CVE-2026-20316Cisco Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability5.3August 01, 2026
CVE-2025-68686Fortinet FortiOSFortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability5.9August 10, 2026
CVE-2026-16812Arista VeloCloud OrchestratorArista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability10.0July 30, 2026
CVE-2026-16232Check Point SmartConsoleCheck Point SmartConsole Improper Authentication Vulnerability9.1July 25, 2026
CVE-2026-50522Microsoft SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability9.8July 25, 2026
CVE-2026-60137WordPress CoreWordPress Core SQL Injection Vulnerability5.9August 04, 2026
CVE-2026-63030WordPress CoreWordPress Core Interpretation Conflict Vulnerability9.8July 24, 2026
CVE-2026-0770LangflowLangflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability9.8July 24, 2026
CVE-2021-27137DD-WRTDD-WRT Stack-Based Buffer Overflow Vulnerability8.1July 24, 2026C0XMO
CVE-2026-58644Microsoft SharePointMicrosoft SharePoint Deserialization of Untrusted Data Vulnerability9.8July 19, 2026
CVE-2026-25089Fortinet FortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability9.8July 19, 2026
CVE-2026-39808Fortinet FortiSandboxFortinet FortiSandbox OS Command Injection Vulnerability9.8July 19, 2026
CVE-2026-46817Oracle E-Business SuiteOracle E-Business Suite Improper Privilege Management Vulnerability9.8July 18, 2026
CVE-2023-4346KNX Association KNX ProtocolKNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability7.5July 29, 2026
CVE-2026-56155Microsoft Active Directory Federation ServicesMicrosoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability7.8July 28, 2026
CVE-2026-56164Microsoft SharePoint ServerMicrosoft SharePoint Server Missing Authentication for Critical Function Vulnerability9.8July 17, 2026
CVE-2026-15409SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability10.0July 17, 2026
CVE-2026-15410SonicWall SMA1000 AppliancesSonicWall SMA1000 Appliances Code Injection Vulnerability7.2July 17, 2026
CVE-2008-4128Cisco IOSCisco IOS Cross-Site Request Forgery Vulnerability4.3July 16, 2026Berserk Bear, Energetic Bear, Static Tundra
CVE-2026-56291Balbooa Forms (Joomla)Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability9.8July 13, 2026
CVE-2026-48939iCagendaiCagenda Unrestricted Upload of File with Dangerous Type Vulnerability9.8July 13, 2026
CVE-2026-48908JoomShaper SP Page BuilderJoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability9.8July 10, 2026ChocoPoC RAT
CVE-2026-55255LangflowLangflow Authorization Bypass Through User-Controlled Key Vulnerability8.4July 10, 2026
CVE-2026-56290Joomlack Page Builder CKJoomlack Page Builder Improper Access Control Vulnerability9.8July 10, 2026
CVE-2026-48282Adobe ColdFusionAdobe ColdFusion Path Traversal Vulnerability10.0July 10, 2026
CVE-2026-45659Microsoft SharePoint ServerMicrosoft SharePoint Server Deserialization of Untrusted Data Vulnerability8.8July 04, 2026

All 26 CVE IDs above were added to the CISA KEV catalog in July 2026; due dates reflect CISA's recommended remediation deadline.


Recommendations

01

Patch Before the CISA Due Date

Prioritize the vulnerabilities above and patch before the CISA-assigned due date.

02

Comply with BOD 26-04

Comply with CISA's BOD 26-04, the minimum standard federal agencies must follow against known exploited vulns.

03

Use the Affected-Product List

The affected-product list helps identify impacted assets without a full scan; patch them first to reduce risk.


Appendix

Known Exploited Vulnerabilities (KEV): Vulnerabilities with public exploits or PoC code posing high risk if unaddressed; the source of record for flaws exploited in the wild.

Due Date: CISA's recommended deadline for remediating a known exploited vulnerability.


References


What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.