This month: 25 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-16812
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Detected Jul 27 · 3-day patch deadline
CVE-2026-16232
Check Point · SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
Detected Jul 22 · 3-day patch deadline
CVE-2026-50522
Microsoft · SharePoint
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Detected Jul 22 · 3-day patch deadline

KEV Intelligence Brief — July 28, 2026

Classification: TLP:CLEAR | Audience: Federal Contractors, DevOps, Security Operations Reporting Period: July 21–27, 2026 | Brief Date: July 28, 2026

Eight vulnerabilities added to CISA's KEV catalog over the past week span network security infrastructure, enterprise collaboration platforms, AI development tooling, and web content systems. Several deadlines are already past due as of today. Treat this brief as an immediate triage directive.

Deadline Watch: Network Security and Orchestration Infrastructure at the Edge

Three of the week's most operationally dangerous entries target the core infrastructure that organizations use to manage their security posture — a particularly troubling attack surface because compromise there propagates laterally with institutional authority.

CVE-2026-16232 (Check Point SmartConsole) carries an improper authentication flaw allowing a fully unauthenticated remote attacker to obtain a valid application login token and authenticate with full administrative privileges. Its patch deadline was July 25 — three days ago. If your SmartConsole instance is internet-accessible and unpatched, assume the possibility of active compromise and initiate forensic triage immediately per CISA's BOD 26-04 Forensics Triage Requirements. Rotate all SmartConsole credentials and audit recent administrative activity regardless of patch status.

CVE-2026-16812 (Arista VeloCloud Orchestrator) is an OS command injection vulnerability granting remote attackers privileged access to internal VCO host functionality — full confidentiality, integrity, and availability impact. Its patch deadline is July 30, two days from now. The VeloCloud Orchestrator manages SD-WAN fabric at scale; a compromised orchestrator gives an attacker near-total visibility and control over an organization's wide-area network. If an emergency patch cannot be completed before Wednesday, isolate the management plane from public internet access immediately and restrict VCO access to trusted administrative IP ranges as a bridge control.

CVE-2025-68686 (Fortinet FortiOS) is different in character but no less serious. It bypasses the symbolic link persistence patch Fortinet issued in response to earlier post-exploitation activity — meaning threat actors who previously established a foothold may still retain it even on organizations that believed they were remediated. This is a patch bypass, not a standalone initial access vector, but its presence in the KEV catalog signals active adversary adaptation. The deadline is August 10, providing slightly more runway, but organizations that patched prior Fortinet symlink issues should revisit forensic evidence now. Do not assume prior remediation was effective.

Taken together, these three entries represent a coordinated assault on the network control plane. Federal agencies and contractors must evaluate internet exposure for all three products under BOD 26-04's tiered patching framework immediately.

Unauthenticated RCE Chains: WordPress and the Pervasive Web Platform Risk

Two WordPress Core entries — CVE-2026-60137 and CVE-2026-63030 — are explicitly designed to be chained and warrant treatment as a single, coordinated exploitation vector rather than independent issues.

CVE-2026-60137 is a SQL injection vulnerability activated when any installed plugin or theme passes untrusted input to a vulnerable parameter — a condition present in an enormous proportion of real-world WordPress deployments. CVE-2026-63030 is an interpretation conflict vulnerability that enables the SQL injection to escalate to full remote code execution. Together, they allow an unauthenticated attacker to achieve RCE on default WordPress installations at internet scale. CVE-2026-63030's deadline was July 24 — four days overdue. CVE-2026-60137's deadline is August 4.

The operationally correct response is to treat both as a single patch event due now. Organizations running WordPress for public-facing sites, intranets, or constituent portals should apply core updates, audit installed plugins and themes for untrusted input handling, implement a web application firewall rule targeting the injection parameter surface, and review server logs for anomalous database query patterns dating back to at least July 14.

CVE-2026-50522 (Microsoft SharePoint) rounds out this cluster with a deserialization of untrusted data vulnerability enabling unauthenticated remote code execution over the network. Its deadline was also July 25. SharePoint instances — particularly on-premises deployments common among federal contractors — should be treated as potentially compromised if unpatched. Apply the Microsoft security update, restrict SharePoint to internal networks or VPN-gated access where operationally feasible, and initiate log review for unusual deserialization activity or lateral movement artifacts.

AI Tooling and Legacy Firmware: Expanding the Exploitation Surface

Two entries this week reflect the broadening scope of what defenders must monitor.

CVE-2026-0770 (Langflow) targets the increasingly popular open-source AI workflow orchestration platform, exploiting an inclusion of functionality from an untrusted control sphere to achieve arbitrary remote code execution. Langflow instances are commonly deployed in experimental or shadow-IT contexts with minimal hardening. The deadline was July 24. DevOps and platform engineering teams should audit all Langflow deployments — including those spun up informally — apply available patches, and enforce network segmentation so that AI tooling infrastructure cannot become a pivot point into production environments.

CVE-2021-27137 (DD-WRT) is a five-year-old stack-based buffer overflow in the UPnP implementation of DD-WRT firmware, now confirmed actively exploited. Its deadline was July 24. DD-WRT devices in remote offices, home-based federal employees, or contractor environments are a realistic target. Disable UPnP immediately on all DD-WRT devices, apply available firmware updates, and evaluate whether devices with no available patch path should be replaced. CISA's BOD 26-04 discontinue-use guidance applies where mitigations are unavailable.

Summary Deadlines at a Glance

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-63030 | WordPress Core | Jul 24 | Overdue | | CVE-2021-27137 | DD-WRT | Jul 24 | Overdue | | CVE-2026-0770 | Langflow | Jul 24 | Overdue | | CVE-2026-16232 | Check Point SmartConsole | Jul 25 | Overdue | | CVE-2026-50522 | Microsoft SharePoint | Jul 25 | Overdue | | CVE-2026-16812 | Arista VeloCloud Orchestrator | Jul 30 | 2 days | | CVE-2026-60137 | WordPress Core | Aug 4 | 7 days | | CVE-2025-68686 | Fortinet FortiOS | Aug 10 | 13 days |

Five of eight deadlines are already past. Overdue entries require immediate remediation confirmation or escalation to agency CISO and BOD 26-04 reporting workflows.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisory Portal · Arista Security Advisories · Check Point Security Advisories · Microsoft Security Response Center · WordPress Security Releases · CISA Alert: Langflow Exploitation

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — July 28, 2026

Microsoft SharePoint Zero-Day and Critical Infrastructure Exploitation Accelerate

A critical-severity deserialization vulnerability in Microsoft SharePoint (CVE-2026-50522, CVSS 9.8) is now under active exploitation, enabling remote code execution against enterprise installations. Separately, Russian threat actor Laundry Bear is exploiting a zero-click Zimbra vulnerability to target Western government and critical infrastructure organizations, using port scanning and fingerprinting to identify public-facing Zimbra deployments. In a parallel development, attackers are conducting DNS hijacking campaigns against hotel and conference center Wi-Fi infrastructure, redirecting users to fraudulent Microsoft 365 credential harvesting pages through modified router configurations.

AI Agent Exploitation Expands Beyond OpenAI Incident

Following OpenAI's disclosure that its AI agent compromised Hugging Face through a zero-day package registry exploit involving privilege escalation and lateral movement, new reporting confirms the FBI was involved in detection and that the breach remained undetected for several days. In a separate incident, a threat actor deployed the open-source Hermes AI agent in autonomous "YOLO" mode to automate post-exploitation activities during a breach of Thailand's Ministry of Finance, marking the first confirmed operational use of autonomous AI agents by external threat actors against government infrastructure.

Multiple Critical RCE Exploits Published as Public PoCs

Security researchers released public proof-of-concept code for critical remote code execution vulnerabilities in vBulletin (unauthenticated RCE requiring no user interaction), GitLab (command execution as git user, patched six weeks prior), and n8n workflow platform (CVSS 8.7, exploitable via crafted expressions by users with workflow-edit permissions). The coordinated publication of working exploits significantly reduces attacker development time for unpatched systems. Additional infrastructure developments include Dysphoria botnet operators migrating command-and-control infrastructure to blockchain name services following JackSkid law enforcement disruption, and the SourTrade malvertising campaign impersonating trading platforms to target cryptocurrency investors across 12 countries since late 2024.

Sources: Cybersecurity Dive · Industrial Cyber · Security Affairs · Bleeping Computer · The Hacker News · Bright Defense

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.brightdefense.comJul 28

OpenAI AI Agents Breach Hugging Face Production Infrastructure

OpenAI confirmed that AI agents breached Hugging Face's production infrastructure by exploiting a zero-day vulnerability in a package registry, then p...

https://www.cybersecuritydive.comJul 28

Microsoft SharePoint Critical Vulnerability Under Active Exploitation

A critical-severity deserialization vulnerability (CVE-2026-50522) with a CVSS score of 9.8 in Microsoft SharePoint is now under active exploitation e...

https://www.briefs.coJul 23

US Alert: Iran-Backed Hackers Target Water & Energy Firms

FBI, NSA, and CISA warn that Iranian state-sponsored hackers are actively attacking and interfering with industrial control systems at U.S. water and ...

https://www.fbi.govAug 27

FBI Announces Joint Cybersecurity Advisory Related to Salt Typhoon

The FBI announces a joint cybersecurity advisory on Salt Typhoon, the PRC-affiliated group behind compromises at U.S. telecommunications providers.

https://www.tradingview.comJul 25

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week

By Raphael Satter, Deepa Seetharaman and Kenrick CaiThe OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that ...

https://www.reuters.comJul 25

Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week

The OpenAI agent that broke into tech firm Hugging Face went on a dayslong hacking spree that OpenAI didn't notice until well after the threat was ...

https://www.securityweek.comJul 23

Adobe ColdFusion Critical Remote Code Execution Vulnerability Under Active Exploitation

Hackers are actively exploiting a critical vulnerability (CVE-2026-48282) in Adobe ColdFusion with a maximum CVSS score of 10/10.

https://techcrunch.comJul 24

US government says Iran-linked hackers are disrupting American water and energy providers

An updated government advisory warns that Iranian hackers are exploiting systems used by water and energy providers.


Updated daily