Week of 13 to 19 July 2026
197 qualifying stories tracked from Monday-Sunday calendar week, July 13 to July 19, 2026; change from the prior 7 days: -38 vs prior period; 10 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) entries added from Monday-Sunday calendar week, July 13 to July 19, 2026; 202 leak-site claims observed by tracked feeds from Monday-Sunday calendar week, July 13 to July 19, 2026
Monday to Sunday, UTC. Permalink label: 2026-W29.
- vulnerabilities8 sourcesSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)Source ↗
SonicWall has released patches for two actively exploited zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances. The company recommends affected organizations upgrade firmware, search for indicators of compromise, and if found, re-image or re-deploy appliances and reset credentials and multi-factor authentication tokens.
- threat intel3 sourcesOfficials once again warn defenders that Russian hackers are targeting network devicesSource ↗
Russian FSB Center 16 (tracked under multiple names including Berserk Bear and Dragonfly) has conducted sustained targeting of critical infrastructure globally by exploiting poorly configured and outdated networking devices, particularly Cisco routers with default credentials and unpatched vulnerabilities. A joint cybersecurity advisory from the United States and 12 allied nations on Monday detailed the group's tactics and recommended defenses including disabling Cisco Smart Install, enforcing strong authentication, and monitoring local account activity. The warning follows a December 2025 attack attributed to FSB Center 16 on Poland's energy grid and comes nearly a year after similar alerts.
- vulnerabilities2 sourcesCISA Urges SharePoint Hardening After New ExploitationsSource ↗
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
- vulnerabilities2 sourcesCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server VulnerabilitiesSource ↗
CISA confirmed active exploitation of three Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) affecting on-premises deployments across all supported versions. Two additional high-severity flaws (CVE-2026-55040 and CVE-2026-58644) were disclosed July 14-15, 2026, with CVE-2026-58644 confirmed exploited in the wild. Attackers chain these flaws to gain unauthorized access, achieve remote code execution, steal IIS machine keys, and deploy malware for persistence.
- vulnerabilities2 sourcesNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeSource ↗
A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.
- vulnerabilities2 sourcesTwo new high severity WordPress vulnerabilities, patch immediately!Source ↗
WordPress released version 7.0.2 to address one critical and one high severity vulnerability. The issues include CVE-2026-60137, a facilitated SQL injection flaw, and a separate REST API batch-route confusion vulnerability leading to remote code execution. Both require immediate patching across affected WordPress 6.9 installations.
- vulnerabilities2 sourcesiCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-DaysSource ↗
The Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity flaws affecting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. Both vulnerabilities received a CVSS score of 10.0, the highest severity rating.
- vulnerabilitiesProxying to Compromise: SonicWall Secure Mobile Access 0-day ExploitationSource ↗
In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.
- vulnerabilities13th July - Threat Intelligence ReportSource ↗
A weekly threat intelligence bulletin covering significant incidents from July 13 including data breaches at AssuranceAmerica (7 million people), Latvijas Valsts Meži (ransomware exploiting two-year-old vulnerability), Injective Labs (supply chain compromise via malicious npm packages), and Moody Bible Institute (2.3 million donors and supporters). The report also details emerging AI threats such as autonomous ransomware using language models and malicious code injection attacks against coding agents, along with critical vulnerabilities in Tenda routers, Linux KVM hypervisor, U-Boot bootloader, and Opera GX browser.
- vulnerabilitiesABB Ability EdgeniusSource ↗
ABB has released an advisory for CVE-2026-31431, a Linux kernel vulnerability affecting ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 installed on multiple gateway and server models. The flaw allows locally authenticated users or compromised container workloads to escalate privileges to root, potentially granting complete system control. A patch is available in version 3.2.4.1, and ABB recommends immediate application along with access restrictions to SSH and Cockpit.
| Qilin | 34 claims | +3 vs prior week |
| Dragonforce | 29 claims | +22 vs prior week |
| The Gentlemen | 26 claims | -13 vs prior week |
| INC Ransom | 12 claims | +9 vs prior week |
| Nova | 7 claims | +6 vs prior week |
| Akira | 6 claims | 0 vs prior week |
| Arcus Media | 6 claims | +5 vs prior week |
| Arcusmedia | 6 claims | +6 vs prior week |
| KryBit | 5 claims | +2 vs prior week |
| Play | 5 claims | +2 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- CVE-2026-15409SonicWall SMA1000 Appliancesdue
- CVE-2026-15410SonicWall SMA1000 Appliancesdue
- CVE-2026-58644Microsoft SharePointdue
- CVE-2026-39808Fortinet FortiSandboxdue
- CVE-2026-25089Fortinet FortiSandboxdue
- CVE-2026-46817Oracle E-Business Suitedue
- CVE-2026-56155Microsoft Active Directory Federation Servicesdue
- CVE-2026-56164Microsoft SharePoint Serverdue
- CVE-2008-4128Cisco IOSdue
- CVE-2023-4346KNX Association KNX Protocol Connection Authorization Option 1due
- CVE-2026-15409SonicWall SMA1000 AppliancesAdded to CISA KEV 2026-07-14; Added to VulnCheck KEV 2026-07-14; Added to ENISA EUVD 2026-07-14; Exploitation active since 2026-07-14
- CVE-2026-15410SonicWall SMA1000 AppliancesAdded to CISA KEV 2026-07-14; Added to VulnCheck KEV 2026-07-14; Added to ENISA EUVD 2026-07-14; Exploitation active since 2026-07-14
- CVE-2025-33073Microsoft WindowsEPSS up 14 points in about a week
- CVE-2026-8037Progress LoadMasterEPSS up 14 points in about a week
- CVE-2026-50522Microsoft SharePointAdded to VulnCheck KEV 2026-07-20
- claimAssociated Theatrical ContractorsUnverified claim. Claimed by Qilin.
- claimDon Tortaco Mexican GrillUnverified claim. Claimed by Qilin.
- claimCity Ambulance ServiceUnverified claim. Claimed by Qilin.
- claimFamesaUnverified claim. Claimed by Qilin.
- claimPP+KUnverified claim. Claimed by Qilin.
- claimEanaUnverified claim. Claimed by Qilin.
- claimSynergy ProductsUnverified claim. Claimed by Qilin.
- claimThe Nueva SchoolUnverified claim. Claimed by Qilin.
- claimNewNetUnverified claim. Claimed by Dragonforce.
- claimKee Wah BakeryUnverified claim. Claimed by Dragonforce.
- claimPetrini ValoresUnverified claim. Claimed by Dragonforce.
- claimSinai Grand CasinoUnverified claim. Claimed by Dragonforce.
- claimSouthport Outdoor LivingUnverified claim. Claimed by Dragonforce.
- claimMetro Design CenteUnverified claim. Claimed by Dragonforce.
- claimNorth Atlantic Engineering ConsultantsUnverified claim. Claimed by Dragonforce.
- claimHeritage Mechanical LLCUnverified claim. Claimed by Dragonforce.
- claimEcopetrolUnverified claim. Claimed by The Gentlemen.
- claimEcopetrolUnverified claim. Claimed by The Gentlemen.
- claimSunway ScientificUnverified claim. Claimed by The Gentlemen.
- claimMilitary Sealift CommandUnverified claim. Claimed by The Gentlemen.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.