CISA Adds Two Known Exploited Vulnerabilities to Catalog
2026-07-27T21:24:03Z•976c9aa0777c92c9c94cf4921aea3fa84c61c0e5ab3da31ef962c5b58325bd2f
CVE-2021-27137CVE-2023-4346CVE-2025-68686CVE-2026-0770CVE-2026-15409CVE-2026-15410CVE-2026-16232CVE-2026-16812CVE-2026-25089CVE-2026-32201CVE-2026-39808CVE-2026-45659CVE-2026-46817CVE-2026-50522CVE-2026-55040CVE-2026-56155CVE-2026-56164CVE-2026-58644CVE-2026-60137CVE-2026-63030BOD-26-04CISAFortinetKEVMicrosoft-SharePointOS-command-injectionSQL-injectionSSRFSonicWallactive-exploitationcommand-injectiondeserializationknown-exploited-vulnerabilitiesprivilege-escalationremote-code-executionvulnerability-management
What happened
CISA reports multiple additions to its Known Exploited Vulnerabilities Catalog in July 2026, covering Fortinet, Arista VeloCloud, Check Point, Microsoft SharePoint and AD FS, SonicWall, WordPress, Langflow, DD-WRT, Oracle E-Business Suite, and KNX products. The entries are supported by evidence of active exploitation, and CISA specifically warns that SharePoint vulnerabilities enable unauthorized access, remote code execution, persistence, IIS machine-key theft, deserialization, and malware deployment. Organizations should prioritize patching, hardening, exposure reduction, and compromise-hunt
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ncas_current_activity
- Record identifier
- 976c9aa0777c92c9c94cf4921aea3fa84c61c0e5ab3da31ef962c5b58325bd2f
- Enrichment time
- 2026-07-27T21:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.