CISA Adds One Known Exploited Vulnerability to Catalog

2026-07-29T21:24:05Z65787db475c07db77da3d9fa6ba1ab5d778c707a1d2f142c564e6c1ddf75270c
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-16232CVE-2026-16812CVE-2026-20316CVE-2026-25089CVE-2026-32201CVE-2026-39808CVE-2026-45659CVE-2026-46817CVE-2026-50522CVE-2026-55040CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030CISA KEVCiscoFortinetMicrosoft SharePointOracle E-Business SuiteSQL injectionWordPressactive exploitationcommand injectiondeserializationhard-coded passwordimproper authenticationprivilege escalationremote code executionvulnerability management

What happened

CISA advisories from July 2026 report active exploitation of multiple vulnerabilities added to the Known Exploited Vulnerabilities catalog, affecting Cisco Secure Firewall Management Center, Fortinet FortiOS/FortiSandbox, Arista VeloCloud Orchestrator, Check Point SmartConsole, Microsoft SharePoint, DD-WRT, Langflow, WordPress, KNX, and Oracle E-Business Suite. A related SharePoint alert describes remote code execution, IIS machine-key theft, deserialization, persistence, and malware deployment. Organizations should prioritize urgent remediation, restrict exposure, and investigate affected on‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
65787db475c07db77da3d9fa6ba1ab5d778c707a1d2f142c564e6c1ddf75270c
Enrichment time
2026-07-29T21:24:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA Adds One Known Exploited Vulnerability to Catalog · Baitaphish