This month: 0 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-20316
Cisco · Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Detected Jul 29 · 3-day patch deadline
CVE-2026-16812
Arista · VeloCloud Orchestrator
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Detected Jul 27 · 3-day patch deadline
CVE-2026-16232
Check Point · SmartConsole
Check Point SmartConsole Improper Authentication Vulnerability
Detected Jul 22 · 3-day patch deadline

KEV Intelligence Brief: July 30, 2026

Issued by: Cybersecurity Intelligence Team | TLP: WHITE | Date: July 30, 2026

Eight new entries have been added to CISA's Known Exploited Vulnerabilities catalog over the past nine days, spanning network security infrastructure, enterprise collaboration platforms, AI development tooling, and consumer-grade routing firmware. Several patch deadlines have already passed. The pattern across this batch is consistent: attackers are targeting authentication and trust boundaries at scale, with a marked interest in AI-adjacent platforms and the persistent exploitation of long-unpatched embedded device vulnerabilities.

Deadline Emergency: Network Security Infrastructure Under Active Attack

The most operationally urgent cluster in this batch centers on the core tools organizations use to manage security — a deeply dangerous irony.

CVE-2026-20316 (Cisco Secure Firewall Management Center) carries a patch deadline of August 1, 2026 — two days from today — and represents one of the more egregious vulnerability classes possible in a security management product: a hard-coded password. An unauthenticated remote attacker can log in using a built-in low-privileged account and access sensitive data, potentially including policy configurations, network topology, and device credentials. FMC's role as a centralized orchestrator for Firepower deployments means that even low-privileged access can enable significant lateral reconnaissance. Organizations running FMC must treat this as a break-glass situation: isolate the management interface immediately if patching within the deadline is operationally infeasible, and audit all recent authentication logs for anomalous access patterns consistent with BOD 26-04 forensic triage requirements.

CVE-2026-16812 (Arista VeloCloud Orchestrator) had a patch deadline of July 30, 2026 — today — and organizations that have not yet acted are formally overdue. This OS command injection vulnerability allows a remote attacker to achieve privileged command execution on the VCO host itself, compromising the confidentiality, integrity, and availability of the entire SD-WAN fabric managed by that orchestrator. The blast radius here is enormous in multi-tenant or enterprise-wide deployments. If patching is not possible today, the orchestrator must be isolated from internet exposure and placed behind strict IP allowlisting immediately.

CVE-2025-68686 (Fortinet FortiOS) represents a different but equally serious threat: it bypasses the patch Fortinet shipped to address the symbolic link persistence mechanism observed in prior post-exploitation campaigns. With a deadline of August 10, 2026, defenders have slightly more runway, but should not be lulled into complacency. This vulnerability requires prior filesystem-level compromise, meaning organizations should be conducting threat hunts for indicators of earlier FortiOS exploitation before — or in parallel with — patching. The BOD 26-04 forensic triage requirements are particularly relevant here; this is not a case where patching alone closes the exposure.

CVE-2026-16232 (Check Point SmartConsole) had a deadline of July 25 — five days overdue. An unauthenticated remote attacker can obtain a login token and authenticate with full administrative privileges. If your organization has not yet patched SmartConsole, assume compromise, rotate all credentials associated with the platform, and conduct a full audit of policy changes made since the vulnerability was disclosed.

These four vulnerabilities collectively represent a coordinated attack surface against the very systems defenders rely on to protect their networks. Adversaries who compromise orchestrators and management consoles gain not just access, but visibility and control over security policy itself.

Enterprise Platforms and the Unauthenticated RCE Problem

Two high-impact vulnerabilities targeting broadly deployed enterprise platforms demand immediate attention from IT and DevOps teams.

CVE-2026-50522 (Microsoft SharePoint) involves deserialization of untrusted data enabling remote code execution over a network, with a deadline that passed July 25. SharePoint's prevalence across federal and commercial environments — and its frequent internet exposure — makes this a high-priority exploitation target. Organizations should verify patch application via change management records and SCCM/Intune telemetry, not assumption. Network segmentation of SharePoint servers from sensitive internal systems is a worthwhile interim control where patching is delayed.

CVE-2026-60137 (WordPress Core) is notable for its chaining potential. Alone, it is a SQL injection vulnerability dependent on a plugin or theme passing untrusted input. However, when chained with CVE-2026-63030, it enables unauthenticated remote code execution on default WordPress installations — a scenario that dramatically expands the exploitable population. The patch deadline is August 4. WordPress administrators must apply core updates immediately, audit active plugins and themes for the vulnerable input-handling pattern, and consider deploying a web application firewall rule as a compensating control in the interim.

Emerging and Long-Tail Threats: AI Tooling and Abandoned Firmware

CVE-2026-0770 (Langflow) continues the troubling trend of AI development and orchestration platforms entering the KEV catalog. This inclusion-of-functionality-from-untrusted-control-sphere vulnerability allows remote attackers to execute arbitrary code on affected Langflow installations. Langflow's role as an agentic workflow builder — often deployed in development or research environments with relaxed security controls — makes it a high-value target for initial access into AI infrastructure. Teams running Langflow should evaluate whether internet-exposed instances are operationally necessary and enforce strict access controls where they are.

CVE-2021-27137 (DD-WRT) deserves particular note: this is a 2021 vulnerability only now entering the KEV catalog, confirming active exploitation of a five-year-old stack-based buffer overflow in DD-WRT's UPnP implementation. The exploitability requires no authentication. Organizations and federal contractors using DD-WRT in any capacity — including branch offices or lab environments — should disable UPnP immediately, apply available firmware updates, or replace devices that have reached end-of-life. The five-year gap between CVE publication and KEV addition is a reminder that legacy embedded device vulnerabilities remain a durable, exploited attack surface.

Immediate Actions Summary: Four deadlines are already past (CVE-2026-16232, CVE-2026-50522, CVE-2026-16812, CVE-2021-27137, CVE-2026-0770). If patching is not confirmed, begin forensic triage per BOD 26-04. Two deadlines fall within 72 hours (CVE-2026-20316: August 1). Do not wait on August 10 (CVE-2025-68686) without initiating a threat hunt now.

Sources: CISA KEV Catalog · CISA BOD 26-04 · Cisco Security Advisory: CVE-2026-20316 · Fortinet PSIRT Advisory: CVE-2025-68686 · Check Point Security Advisory: CVE-2026-16232 · Microsoft Security Update Guide: CVE-2026-50522 · WordPress Security Release · Arista Security Advisory: CVE-2026-16812

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — August 1, 2026

Federal Investigation Links Water System Intrusions to Iranian Threat Actor

The FBI confirmed that threat actors targeted water utility providers in at least seven states, compromising internet-exposed programmable logic controllers and causing loss of pressure and flooding at affected facilities. The agency's investigation, disclosed late Thursday, identified the attackers as Iranian-linked operators conducting a coordinated infrastructure campaign. Over 30 municipal water systems in Minnesota were affected, with researchers at Sublime Security assessing the operation aims to generate psychological impact rather than immediate physical destruction. The campaign represents the most extensive targeting of U.S. water infrastructure since CISA issued warnings about increased reconnaissance activity against operational technology systems.

Chinese-Speaking Actor Deploys Autonomous AI Attack Framework

Palo Alto Networks Unit 42 researchers documented a Chinese-speaking threat actor leveraging the DeepSeek AI model and Hermes Agent framework to conduct autonomous cyberattacks against seven distinct vulnerabilities across Langflow, n8n, Citrix NetScaler, and other infrastructure platforms. The campaign marks the first publicly documented use of commercially available AI models integrated into an operational attack framework for widespread exploitation. Separately, SOCRadar identified a North Korean-linked social engineering operation targeting cryptocurrency and Web3 professionals through fraudulent job interviews and interactive web portals designed to deliver remote access trojans. The campaign employs fake macOS update screens with clipboard manipulation to steal cryptocurrency wallet credentials and developer access tokens.

Sources: PCMag · JPost · Unit 42 · Infosecurity Magazine · Cybersecurity News

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.pcmag.comAug 1

FBI: Hackers Targeted Water Utility Providers in at Least 7 States | PCMag

Hackers have been targeting internet-exposed computers known as programmable logic controllers, causing 'loss of pressure and flooding,' the FBI ...

https://www.npr.orgAug 1

Why did OpenAI's and Anthropic's AI models hack other companies? - NPR

Shoring up defenses in a world of autonomous hacking. During testing for cybercapabilities, OpenAI and Anthropic remove some safety guardrails from .....

https://www.wired.comAug 1

Nobody Knows if OpenAI's and Anthropic's AI Hacking Sprees Are Illegal | WIRED

Both major AI labs' models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would ...

https://www.techtimes.comAug 1

Anthropic's Claude Hacked 3 Real Companies During Misconfigured Cybersecurity Evaluations

Anthropic Claude cybersecurity evaluation breach: a review of 141006 runs found three Claude models hacked real organizations during misconfigured ...

https://abcnews.comAug 1

Trump blames Minnesota governor, not Iran, for cyberattacks on the state's water systems

The governor also noted federal cuts by the Department of Government Efficiency (DOGE) weakened cybersecurity. "DOGE took an axe to CISA and left ...

https://www.darkreading.comAug 1

CISA Issues Fresh SBOM Guidance. Did They Get It Right? - Dark Reading

The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities ...

https://thehackernews.comJul 31

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

CISA added a Cisco Secure Firewall Management Center zero-day vulnerability (CVE-2026-20316) to its Known Exploited Vulnerabilities catalog after repo...

https://thehackernews.comJul 30

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean threat actors are conducting a sophisticated macOS malvertising campaign using fake update screens with ClickFix techniques to deliver ma...


Updated daily