CISA Adds One Known Exploited Vulnerability to Catalog
2026-07-29T21:24:05Z•65787db475c07db77da3d9fa6ba1ab5d778c707a1d2f142c564e6c1ddf75270c
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-20316CVE-2026-25089CVE-2026-32201CVE-2026-39808CVE-2026-45659CVE-2026-46817CVE-2026-50522CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030CISA KEVCiscoFortinetMicrosoft SharePointOracle E-Business SuiteSQL injectionWordPressactive exploitationcommand injectiondeserializationhard-coded passwordimproper authenticationprivilege escalationremote code executionvulnerability management
What happened
CISA advisories from July 2026 report active exploitation of multiple vulnerabilities added to the Known Exploited Vulnerabilities catalog, affecting Cisco Secure Firewall Management Center, Fortinet FortiOS/FortiSandbox, Arista VeloCloud Orchestrator, Check Point SmartConsole, Microsoft SharePoint, DD-WRT, Langflow, WordPress, KNX, and Oracle E-Business Suite. A related SharePoint alert describes remote code execution, IIS machine-key theft, deserialization, persistence, and malware deployment. Organizations should prioritize urgent remediation, restrict exposure, and investigate affected on‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 65787db475c07db77da3d9fa6ba1ab5d778c707a1d2f142c564e6c1ddf75270c
- Enrichment time
- 2026-07-29T21:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.