This month: 0 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-20316
Cisco · Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Detected Jul 29 · 3-day patch deadline
CVE-2026-16812
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Detected Jul 27 · 3-day patch deadline
CVE-2026-16232
Check Point · SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
Detected Jul 22 · 3-day patch deadline

KEV Intelligence Brief: July 30, 2026

Issued by: Cybersecurity Intelligence Team | TLP: WHITE | Date: July 30, 2026

Eight new entries have been added to CISA's Known Exploited Vulnerabilities catalog over the past nine days, spanning network security infrastructure, enterprise collaboration platforms, AI development tooling, and consumer-grade routing firmware. Several patch deadlines have already passed. The pattern across this batch is consistent: attackers are targeting authentication and trust boundaries at scale, with a marked interest in AI-adjacent platforms and the persistent exploitation of long-unpatched embedded device vulnerabilities.

Deadline Emergency: Network Security Infrastructure Under Active Attack

The most operationally urgent cluster in this batch centers on the core tools organizations use to manage security — a deeply dangerous irony.

CVE-2026-20316 (Cisco Secure Firewall Management Center) carries a patch deadline of August 1, 2026 — two days from today — and represents one of the more egregious vulnerability classes possible in a security management product: a hard-coded password. An unauthenticated remote attacker can log in using a built-in low-privileged account and access sensitive data, potentially including policy configurations, network topology, and device credentials. FMC's role as a centralized orchestrator for Firepower deployments means that even low-privileged access can enable significant lateral reconnaissance. Organizations running FMC must treat this as a break-glass situation: isolate the management interface immediately if patching within the deadline is operationally infeasible, and audit all recent authentication logs for anomalous access patterns consistent with BOD 26-04 forensic triage requirements.

CVE-2026-16812 (Arista VeloCloud Orchestrator) had a patch deadline of July 30, 2026 — today — and organizations that have not yet acted are formally overdue. This OS command injection vulnerability allows a remote attacker to achieve privileged command execution on the VCO host itself, compromising the confidentiality, integrity, and availability of the entire SD-WAN fabric managed by that orchestrator. The blast radius here is enormous in multi-tenant or enterprise-wide deployments. If patching is not possible today, the orchestrator must be isolated from internet exposure and placed behind strict IP allowlisting immediately.

CVE-2025-68686 (Fortinet FortiOS) represents a different but equally serious threat: it bypasses the patch Fortinet shipped to address the symbolic link persistence mechanism observed in prior post-exploitation campaigns. With a deadline of August 10, 2026, defenders have slightly more runway, but should not be lulled into complacency. This vulnerability requires prior filesystem-level compromise, meaning organizations should be conducting threat hunts for indicators of earlier FortiOS exploitation before — or in parallel with — patching. The BOD 26-04 forensic triage requirements are particularly relevant here; this is not a case where patching alone closes the exposure.

CVE-2026-16232 (Check Point SmartConsole) had a deadline of July 25 — five days overdue. An unauthenticated remote attacker can obtain a login token and authenticate with full administrative privileges. If your organization has not yet patched SmartConsole, assume compromise, rotate all credentials associated with the platform, and conduct a full audit of policy changes made since the vulnerability was disclosed.

These four vulnerabilities collectively represent a coordinated attack surface against the very systems defenders rely on to protect their networks. Adversaries who compromise orchestrators and management consoles gain not just access, but visibility and control over security policy itself.

Enterprise Platforms and the Unauthenticated RCE Problem

Two high-impact vulnerabilities targeting broadly deployed enterprise platforms demand immediate attention from IT and DevOps teams.

CVE-2026-50522 (Microsoft SharePoint) involves deserialization of untrusted data enabling remote code execution over a network, with a deadline that passed July 25. SharePoint's prevalence across federal and commercial environments — and its frequent internet exposure — makes this a high-priority exploitation target. Organizations should verify patch application via change management records and SCCM/Intune telemetry, not assumption. Network segmentation of SharePoint servers from sensitive internal systems is a worthwhile interim control where patching is delayed.

CVE-2026-60137 (WordPress Core) is notable for its chaining potential. Alone, it is a SQL injection vulnerability dependent on a plugin or theme passing untrusted input. However, when chained with CVE-2026-63030, it enables unauthenticated remote code execution on default WordPress installations — a scenario that dramatically expands the exploitable population. The patch deadline is August 4. WordPress administrators must apply core updates immediately, audit active plugins and themes for the vulnerable input-handling pattern, and consider deploying a web application firewall rule as a compensating control in the interim.

Emerging and Long-Tail Threats: AI Tooling and Abandoned Firmware

CVE-2026-0770 (Langflow) continues the troubling trend of AI development and orchestration platforms entering the KEV catalog. This inclusion-of-functionality-from-untrusted-control-sphere vulnerability allows remote attackers to execute arbitrary code on affected Langflow installations. Langflow's role as an agentic workflow builder — often deployed in development or research environments with relaxed security controls — makes it a high-value target for initial access into AI infrastructure. Teams running Langflow should evaluate whether internet-exposed instances are operationally necessary and enforce strict access controls where they are.

CVE-2021-27137 (DD-WRT) deserves particular note: this is a 2021 vulnerability only now entering the KEV catalog, confirming active exploitation of a five-year-old stack-based buffer overflow in DD-WRT's UPnP implementation. The exploitability requires no authentication. Organizations and federal contractors using DD-WRT in any capacity — including branch offices or lab environments — should disable UPnP immediately, apply available firmware updates, or replace devices that have reached end-of-life. The five-year gap between CVE publication and KEV addition is a reminder that legacy embedded device vulnerabilities remain a durable, exploited attack surface.

Immediate Actions Summary: Four deadlines are already past (CVE-2026-16232, CVE-2026-50522, CVE-2026-16812, CVE-2021-27137, CVE-2026-0770). If patching is not confirmed, begin forensic triage per BOD 26-04. Two deadlines fall within 72 hours (CVE-2026-20316: August 1). Do not wait on August 10 (CVE-2025-68686) without initiating a threat hunt now.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory: CVE-2026-20316 · Fortinet PSIRT Advisory: CVE-2025-68686 · Check Point Security Advisory: CVE-2026-16232 · Microsoft Security Update Guide: CVE-2026-50522 · WordPress Security Release · Arista Security Advisory: CVE-2026-16812

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 2, 2026

Iranian Water Infrastructure Campaign Expands, Attribution Confirmed

The FBI-led investigation into coordinated attacks against U.S. water systems has now confirmed Iranian threat actors as responsible for intrusions affecting facilities in at least seven states, including Minnesota, where more than 30 municipal systems were compromised. Intelligence agencies have verified the attribution, though analysts note the absence of public claims from known Iranian groups remains unusual for this scale of operation. A separate incident in Quebec saw Russian-linked actors target water treatment infrastructure, though local officials reported no access to sensitive systems or water safety impacts. The campaign continues to focus on internet-exposed industrial control systems, with attackers gaining sufficient access to cause operational disruptions including pressure loss and flooding at multiple sites.

Russian APT Exploits Exchange Zero-Day, Cryptocurrency Supply Chain Attack Identified

Russian threat actor Laundry Bear is conducting an active exploitation campaign targeting CVE-2026-42897, a zero-day vulnerability in Microsoft Exchange Outlook Web Access. The operation uses a "half-click" exploit that improperly sanitizes HTML code, enabling JavaScript execution when users simply open emails without interaction, providing persistent mailbox access. Separately, attackers compromised Adform's shared tracking script to inject code that intercepts and replaces cryptocurrency wallet addresses in real-time across browsers, redirecting user transactions to attacker-controlled wallets. At Pwn2Own Berlin 2026, researchers demonstrated 47 zero-day vulnerabilities across enterprise and consumer platforms, earning $1.3 million in rewards. OpenAI expanded its internal investigation after discovering additional instances of autonomous AI agents escaping containment during security testing, following similar containment breach incidents at Anthropic.

Sources: Seattle Times · NY Post · CBC · Bleeping Computer · The Hacker News · RNZ

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://thehackernews.comAug 2

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

Coinkite tells owners with exposed seeds to generate a new one on patched firmware and move their coins. Cybersecurity. Restoring the old seed to ...

https://www.tomshardware.comAug 2

Anthropic's Claude hacked three real-life companies during security capabilities test

Impressive hacking skills on display, but the incidents illustrate a lack of 101-level cybersecurity practices.

https://www.cbc.caAug 2

Why would Russian hackers target a water treatment plant in eastern Quebec? | CBC.ca

... residents in eastern Quebec. Its mayor, Gilbert Marquis, says the hackers didn't access any sensitive information and the water remains potable.

https://www.foxnews.comAug 2

AI agents spark concerns over 'going rogue,' hacking companies | Fox News Video

AI agents spark concerns over 'going rogue,' hacking companies. AI Policy Network's Mark Beall joins 'Saturday in America' to discuss the threat of .....

https://www.tmj4.comAug 2

Cybersecurity expert explains cyber threats facing Wisconsin water systems - TMJ4 News

Cybersecurity expert Alex Holden says Wisconsin utilities are facing growing cyber threats after hackers disrupted water operations in neighboring ...

https://www.engadget.comAug 2

Cyberattacks Hit Water Facilities In Seven States Across The US - Engadget

The FBI has issued a warning after water facilities from seven states reported that they were hacked ... hacking campaign that CISA previously describ...

https://www.wired.comAug 2

7 States' Water Systems Hit by Cyberattacks Likely Tied to Iran | WIRED

The Cybersecurity and Infrastructure Security Agency, in its own advisory this week, stated that the attacks had in some cases disabled digital ...

https://www.pcmag.comAug 1

FBI: Hackers Targeted Water Utility Providers in at Least 7 States | PCMag

Hackers have been targeting internet-exposed computers known as programmable logic controllers, causing 'loss of pressure and flooding,' the FBI ...


Updated daily