CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief: July 30, 2026
Issued by: Cybersecurity Intelligence Team | TLP: WHITE | Date: July 30, 2026
Eight new entries have been added to CISA's Known Exploited Vulnerabilities catalog over the past nine days, spanning network security infrastructure, enterprise collaboration platforms, AI development tooling, and consumer-grade routing firmware. Several patch deadlines have already passed. The pattern across this batch is consistent: attackers are targeting authentication and trust boundaries at scale, with a marked interest in AI-adjacent platforms and the persistent exploitation of long-unpatched embedded device vulnerabilities.
Deadline Emergency: Network Security Infrastructure Under Active Attack
The most operationally urgent cluster in this batch centers on the core tools organizations use to manage security — a deeply dangerous irony.
CVE-2026-20316 (Cisco Secure Firewall Management Center) carries a patch deadline of August 1, 2026 — two days from today — and represents one of the more egregious vulnerability classes possible in a security management product: a hard-coded password. An unauthenticated remote attacker can log in using a built-in low-privileged account and access sensitive data, potentially including policy configurations, network topology, and device credentials. FMC's role as a centralized orchestrator for Firepower deployments means that even low-privileged access can enable significant lateral reconnaissance. Organizations running FMC must treat this as a break-glass situation: isolate the management interface immediately if patching within the deadline is operationally infeasible, and audit all recent authentication logs for anomalous access patterns consistent with BOD 26-04 forensic triage requirements.
CVE-2026-16812 (Arista VeloCloud Orchestrator) had a patch deadline of July 30, 2026 — today — and organizations that have not yet acted are formally overdue. This OS command injection vulnerability allows a remote attacker to achieve privileged command execution on the VCO host itself, compromising the confidentiality, integrity, and availability of the entire SD-WAN fabric managed by that orchestrator. The blast radius here is enormous in multi-tenant or enterprise-wide deployments. If patching is not possible today, the orchestrator must be isolated from internet exposure and placed behind strict IP allowlisting immediately.
CVE-2025-68686 (Fortinet FortiOS) represents a different but equally serious threat: it bypasses the patch Fortinet shipped to address the symbolic link persistence mechanism observed in prior post-exploitation campaigns. With a deadline of August 10, 2026, defenders have slightly more runway, but should not be lulled into complacency. This vulnerability requires prior filesystem-level compromise, meaning organizations should be conducting threat hunts for indicators of earlier FortiOS exploitation before — or in parallel with — patching. The BOD 26-04 forensic triage requirements are particularly relevant here; this is not a case where patching alone closes the exposure.
CVE-2026-16232 (Check Point SmartConsole) had a deadline of July 25 — five days overdue. An unauthenticated remote attacker can obtain a login token and authenticate with full administrative privileges. If your organization has not yet patched SmartConsole, assume compromise, rotate all credentials associated with the platform, and conduct a full audit of policy changes made since the vulnerability was disclosed.
These four vulnerabilities collectively represent a coordinated attack surface against the very systems defenders rely on to protect their networks. Adversaries who compromise orchestrators and management consoles gain not just access, but visibility and control over security policy itself.
Enterprise Platforms and the Unauthenticated RCE Problem
Two high-impact vulnerabilities targeting broadly deployed enterprise platforms demand immediate attention from IT and DevOps teams.
CVE-2026-50522 (Microsoft SharePoint) involves deserialization of untrusted data enabling remote code execution over a network, with a deadline that passed July 25. SharePoint's prevalence across federal and commercial environments — and its frequent internet exposure — makes this a high-priority exploitation target. Organizations should verify patch application via change management records and SCCM/Intune telemetry, not assumption. Network segmentation of SharePoint servers from sensitive internal systems is a worthwhile interim control where patching is delayed.
CVE-2026-60137 (WordPress Core) is notable for its chaining potential. Alone, it is a SQL injection vulnerability dependent on a plugin or theme passing untrusted input. However, when chained with CVE-2026-63030, it enables unauthenticated remote code execution on default WordPress installations — a scenario that dramatically expands the exploitable population. The patch deadline is August 4. WordPress administrators must apply core updates immediately, audit active plugins and themes for the vulnerable input-handling pattern, and consider deploying a web application firewall rule as a compensating control in the interim.
Emerging and Long-Tail Threats: AI Tooling and Abandoned Firmware
CVE-2026-0770 (Langflow) continues the troubling trend of AI development and orchestration platforms entering the KEV catalog. This inclusion-of-functionality-from-untrusted-control-sphere vulnerability allows remote attackers to execute arbitrary code on affected Langflow installations. Langflow's role as an agentic workflow builder — often deployed in development or research environments with relaxed security controls — makes it a high-value target for initial access into AI infrastructure. Teams running Langflow should evaluate whether internet-exposed instances are operationally necessary and enforce strict access controls where they are.
CVE-2021-27137 (DD-WRT) deserves particular note: this is a 2021 vulnerability only now entering the KEV catalog, confirming active exploitation of a five-year-old stack-based buffer overflow in DD-WRT's UPnP implementation. The exploitability requires no authentication. Organizations and federal contractors using DD-WRT in any capacity — including branch offices or lab environments — should disable UPnP immediately, apply available firmware updates, or replace devices that have reached end-of-life. The five-year gap between CVE publication and KEV addition is a reminder that legacy embedded device vulnerabilities remain a durable, exploited attack surface.
Immediate Actions Summary: Four deadlines are already past (CVE-2026-16232, CVE-2026-50522, CVE-2026-16812, CVE-2021-27137, CVE-2026-0770). If patching is not confirmed, begin forensic triage per BOD 26-04. Two deadlines fall within 72 hours (CVE-2026-20316: August 1). Do not wait on August 10 (CVE-2025-68686) without initiating a threat hunt now.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory: CVE-2026-20316 · Fortinet PSIRT Advisory: CVE-2025-68686 · Check Point Security Advisory: CVE-2026-16232 · Microsoft Security Update Guide: CVE-2026-50522 · WordPress Security Release · Arista Security Advisory: CVE-2026-16812
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — July 30, 2026
First Fully Autonomous LLM Ransomware Operation Documented
Security researchers have identified JadePuffer, the first ransomware operation carried out entirely by an LLM agent without human operator involvement. The campaign represents a milestone in autonomous threat actor capabilities, demonstrating AI systems can now conduct complete attack lifecycles from initial access through encryption and ransom demands. Separately, the Anubis hacking group has claimed responsibility for the ransomware attack on Fairlife, Coca-Cola's dairy products division, marking another significant food and beverage sector compromise. The emergence of fully autonomous ransomware operations alongside traditional threat actor activity signals a bifurcation in the threat landscape between human-directed campaigns and machine-executed attacks.
State-Nexus Groups Target Critical Infrastructure and Government Entities
Russian state-linked group Laundry Bear has expanded operations beyond their February webmail compromises, now exploiting a vulnerability in Microsoft Outlook Web Access to maintain persistent access to targets. CISA updated its advisory on Iranian APT actors targeting industrial control systems, adding new detection guidance for exploitation of programmable logic controllers from Rockwell Automation, Schneider Electric, and Siemens. TAG-140 has been observed targeting Indian government organizations with a modified DRAT trojan while spoofing the Ministry of Defence. Additionally, a malvertising campaign distributed SectopRAT through malicious Claude Artifacts between July 21-22, compromising at least 29 organizations. Bank of Baroda disclosed a breach exposing nearly 1 TB of customer data from India's second largest bank, now circulating on dark web markets.
Sources: Hornetsecurity · Inc · The Record · CISA · The Hacker News · SharkStriker
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Allied spy agencies blame 3 Chinese tech companies for Salt Typhoon attacks
Thirteen allied nations' intelligence agencies formally blamed three Chinese tech companies for enabling the Salt Typhoon espionage campaign that impa...
Amazon identifies North Korean hacker group behind open-source supply chain attacks
Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor,...
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
A maximum-severity command injection vulnerability (CVE-2026-16812 with CVSS 10.0) in Arista VeloCloud Orchestrator is being actively exploited in the...
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
A critical unauthenticated remote code execution vulnerability (CVE-2026-59726 with CVSS 10.0) was discovered in the Ruflo AI agent orchestration plat...
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26-27, causing one water plant to ...
China used three private companies to hack global telecoms, U.S. says
The U.S. revealed that China's Ministry of State Security used three private companies—Beijing Huanyu Tianqiong Information Technology, Sichuan Zhixin...
Chinese Hacked US Telecom a Year Before Known Wireless Breaches
Corporate investigators found evidence that Chinese hackers broke into a U.S. telecommunications company in the summer of 2023, indicating the hackers...
Chinese Group Hacks 'Edge' Devices in Ongoing Telecom Targeting
Salt Typhoon has continued to target phone and wireless providers around the world, compromising devices tied to seven telecommunications companies si...
Updated daily
