CISA Adds Two Known Exploited Vulnerabilities to Catalog

2026-07-27T21:24:03Z976c9aa0777c92c9c94cf4921aea3fa84c61c0e5ab3da31ef962c5b58325bd2f
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-15409CVE-2026-15410CVE-2026-16232CVE-2026-16812CVE-2026-25089CVE-2026-32201CVE-2026-39808CVE-2026-45659CVE-2026-46817CVE-2026-50522CVE-2026-55040CVE-2026-56155CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030BOD-26-04CISAFortinetKEVMicrosoft-SharePointOS-command-injectionSQL-injectionSSRFSonicWallactive-exploitationcommand-injectiondeserializationknown-exploited-vulnerabilitiesprivilege-escalationremote-code-executionvulnerability-management

What happened

CISA reports multiple additions to its Known Exploited Vulnerabilities Catalog in July 2026, covering Fortinet, Arista VeloCloud, Check Point, Microsoft SharePoint and AD FS, SonicWall, WordPress, Langflow, DD-WRT, Oracle E-Business Suite, and KNX products. The entries are supported by evidence of active exploitation, and CISA specifically warns that SharePoint vulnerabilities enable unauthorized access, remote code execution, persistence, IIS machine-key theft, deserialization, and malware deployment. Organizations should prioritize patching, hardening, exposure reduction, and compromise-hunt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ncas_current_activity
Record identifier
976c9aa0777c92c9c94cf4921aea3fa84c61c0e5ab3da31ef962c5b58325bd2f
Enrichment time
2026-07-27T21:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.