
The CISA-maintained KEV catalog is the authoritative source of vulnerabilities exploited in the wild; organizations should monitor it and prioritize remediation.
Notable additions include Cisco Secure Firewall Management Center, Arista VeloCloud Orchestrator, and several Microsoft SharePoint flaws, plus Fortinet, SonicWall, Oracle, WordPress, and Adobe products, and a legacy Cisco IOS CSRF flaw tied to Berserk Bear, Energetic Bear, and Static Tundra.
Exploitation
The table below lists every CVE added to the KEV catalog in July 2026, with vendor/product, CVSS score, due date, and threat actor/tooling.
| CVE ID | Vendor / Product | Vulnerability Name | CVSS 3.x Score | Due Date | Known Threat Actor / Attack |
|---|---|---|---|---|---|
CVE-2026-20316 | Cisco Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability | 5.3 | August 01, 2026 | — |
CVE-2025-68686 | Fortinet FortiOS | Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability | 5.9 | August 10, 2026 | — |
CVE-2026-16812 | Arista VeloCloud Orchestrator | Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability | 10.0 | July 30, 2026 | — |
CVE-2026-16232 | Check Point SmartConsole | Check Point SmartConsole Improper Authentication Vulnerability | 9.1 | July 25, 2026 | — |
CVE-2026-50522 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | July 25, 2026 | — |
CVE-2026-60137 | WordPress Core | WordPress Core SQL Injection Vulnerability | 5.9 | August 04, 2026 | — |
CVE-2026-63030 | WordPress Core | WordPress Core Interpretation Conflict Vulnerability | 9.8 | July 24, 2026 | — |
CVE-2026-0770 | Langflow | Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability | 9.8 | July 24, 2026 | — |
CVE-2021-27137 | DD-WRT | DD-WRT Stack-Based Buffer Overflow Vulnerability | 8.1 | July 24, 2026 | C0XMO |
CVE-2026-58644 | Microsoft SharePoint | Microsoft SharePoint Deserialization of Untrusted Data Vulnerability | 9.8 | July 19, 2026 | — |
CVE-2026-25089 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.8 | July 19, 2026 | — |
CVE-2026-39808 | Fortinet FortiSandbox | Fortinet FortiSandbox OS Command Injection Vulnerability | 9.8 | July 19, 2026 | — |
CVE-2026-46817 | Oracle E-Business Suite | Oracle E-Business Suite Improper Privilege Management Vulnerability | 9.8 | July 18, 2026 | — |
CVE-2023-4346 | KNX Association KNX Protocol | KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability | 7.5 | July 29, 2026 | — |
CVE-2026-56155 | Microsoft Active Directory Federation Services | Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability | 7.8 | July 28, 2026 | — |
CVE-2026-56164 | Microsoft SharePoint Server | Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability | 9.8 | July 17, 2026 | — |
CVE-2026-15409 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability | 10.0 | July 17, 2026 | — |
CVE-2026-15410 | SonicWall SMA1000 Appliances | SonicWall SMA1000 Appliances Code Injection Vulnerability | 7.2 | July 17, 2026 | — |
CVE-2008-4128 | Cisco IOS | Cisco IOS Cross-Site Request Forgery Vulnerability | 4.3 | July 16, 2026 | Berserk Bear, Energetic Bear, Static Tundra |
CVE-2026-56291 | Balbooa Forms (Joomla) | Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability | 9.8 | July 13, 2026 | — |
CVE-2026-48939 | iCagenda | iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability | 9.8 | July 13, 2026 | — |
CVE-2026-48908 | JoomShaper SP Page Builder | JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability | 9.8 | July 10, 2026 | ChocoPoC RAT |
CVE-2026-55255 | Langflow | Langflow Authorization Bypass Through User-Controlled Key Vulnerability | 8.4 | July 10, 2026 | — |
CVE-2026-56290 | Joomlack Page Builder CK | Joomlack Page Builder Improper Access Control Vulnerability | 9.8 | July 10, 2026 | — |
CVE-2026-48282 | Adobe ColdFusion | Adobe ColdFusion Path Traversal Vulnerability | 10.0 | July 10, 2026 | — |
CVE-2026-45659 | Microsoft SharePoint Server | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability | 8.8 | July 04, 2026 | — |
All 26 CVE IDs above were added to the CISA KEV catalog in July 2026; due dates reflect CISA's recommended remediation deadline.
Guidance
01Patch Before the CISA Due Date
Prioritize the vulnerabilities above and patch before the CISA-assigned due date.
02Comply with BOD 26-04
Comply with CISA's BOD 26-04, the minimum standard federal agencies must follow against known exploited vulns.
03Use the Affected-Product List
The affected-product list helps identify impacted assets without a full scan; patch them first to reduce risk.
Definitions
Known Exploited Vulnerabilities (KEV): Vulnerabilities with public exploits or PoC code posing high risk if unaddressed; the source of record for flaws exploited in the wild.
Due Date: CISA's recommended deadline for remediating a known exploited vulnerability.
References
Next Steps
At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.