Week 2026-W30
193 stories tracked from July 13 to July 20, 2026, down 28 from the prior 7 days. 10 new KEV entries. 239 ransomware victims claimed.
- vulnerabilities8 sourcesSonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)
SonicWall has released patches for two actively exploited zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 Series appliances. The company recommends affected organizations upgrade firmware, search for indicators of compromise, and if found, re-image or re-deploy appliances and reset credentials and multi-factor authentication tokens.
- vulnerabilities13th July – Threat Intelligence Report
A weekly threat intelligence bulletin covering significant incidents from July 13 including data breaches at AssuranceAmerica (7 million people), Latvijas Valsts Meži (ransomware exploiting two-year-old vulnerability), Injective Labs (supply chain compromise via malicious npm packages), and Moody Bible Institute (2.3 million donors and supporters). The report also details emerging AI threats such as autonomous ransomware using language models and malicious code injection attacks against coding agents, along with critical vulnerabilities in Tenda routers, Linux KVM hypervisor, U-Boot bootloader, and Opera GX browser.
- vulnerabilities2 sourcesCISA Urges SharePoint Hardening After New Exploitations
CISA has confirmed active exploitation of three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164) affecting all supported on-premises versions, with attackers achieving remote code execution and stealing credentials for persistence. The agency identified two additional unpatched vulnerabilities posing risk and published detection signatures for AMSI and Microsoft Defender. CISA recommends immediate patching, enabling AMSI scanning in Full Mode, hardening network exposure, implementing enhanced logging, and hunting for existing compromise artifacts.
- threat intel3 sourcesOfficials once again warn defenders that Russian hackers are targeting network devices
Russian FSB Center 16 (tracked under multiple names including Berserk Bear and Dragonfly) has conducted sustained targeting of critical infrastructure globally by exploiting poorly configured and outdated networking devices, particularly Cisco routers with default credentials and unpatched vulnerabilities. A joint cybersecurity advisory from the United States and 12 allied nations on Monday detailed the group's tactics and recommended defenses including disabling Cisco Smart Install, enforcing strong authentication, and monitoring local account activity. The warning follows a December 2025 attack attributed to FSB Center 16 on Poland's energy grid and comes nearly a year after similar alerts.
- vulnerabilities2 sourcesCVE-2026-32201, CVE-2026-45659, CVE-2026-56164: Frequently Asked Questions About Active Exploitation of Microsoft SharePoint Server Vulnerabilities
CISA confirmed active exploitation of three Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) affecting on-premises deployments across all supported versions. Two additional high-severity flaws (CVE-2026-55040 and CVE-2026-58644) were disclosed July 14-15, 2026, with CVE-2026-58644 confirmed exploited in the wild. Attackers chain these flaws to gain unauthorized access, achieve remote code execution, steal IIS machine keys, and deploy malware for persistence.
- vulnerabilitiesABB Ability Edgenius
ABB has released an advisory for CVE-2026-31431, a Linux kernel vulnerability affecting ABB Ability Edgenius versions 3.2.0.0 through 3.2.4.0 installed on multiple gateway and server models. The flaw allows locally authenticated users or compromised container workloads to escalate privileges to root, potentially granting complete system control. A patch is available in version 3.2.4.1, and ABB recommends immediate application along with access restrictions to SSH and Cockpit.
- vulnerabilitiesProxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.
- vulnerabilitiesCISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2023-4346 affecting KNX Protocol and CVE-2026-46817 in Oracle E-Business Suite. The agency emphasized that federal agencies must prioritize patching these vulnerabilities under Binding Operational Directive 26-04, and encouraged all organizations to adopt risk-based vulnerability management.
- vulnerabilitiesCISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA added CVE-2026-58644, a critical remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on Thursday. The flaw carries a CVSS score of 9.8 and involves a deserialization issue. Federal civilian agencies must patch the vulnerability by July 19, 2026.
- vulnerabilitiesMicrosoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record
Microsoft disclosed 622 vulnerabilities during July 2026 Patch Tuesday, more than triple the previous month's record of 206 and reflecting an exponential surge driven by artificial intelligence tools discovering defects at scale. Two actively exploited zero-day vulnerabilities in Active Directory Federation Services and SharePoint Server were included among the batch, with 63 rated as critical. The pace suggests Microsoft will exceed 2,000 or more Common Vulnerabilities and Exposures (CVEs) for the calendar year, far surpassing historical annual records.
- CVE-2026-39808Fortinet FortiSandboxdue 2026-07-19
- CVE-2026-25089Fortinet FortiSandboxdue 2026-07-19
- CVE-2026-58644Microsoft SharePointdue 2026-07-19
- CVE-2026-15409SonicWall SMA1000 Appliancesdue 2026-07-17
- CVE-2026-46817Oracle E-Business Suitedue 2026-07-18
- CVE-2026-15410SonicWall SMA1000 Appliancesdue 2026-07-17
- CVE-2026-56164Microsoft SharePoint Serverdue 2026-07-17
- CVE-2008-4128Cisco IOSdue 2026-07-16
- CVE-2023-4346KNX Association KNX Protocol Connection Authorization Option 1due 2026-07-29
- CVE-2026-56155Microsoft Active Directory Federation Servicesdue 2026-07-28
- CVE-2026-39808Fortinet FortiSandboxAdded to CISA KEV 2026-07-16; Added to ENISA EUVD 2026-07-16; EPSS up 35 points in about a week
- CVE-2026-25089Fortinet FortiSandboxAdded to CISA KEV 2026-07-16; Added to ENISA EUVD 2026-07-16; EPSS up 13 points in about a week
- CVE-2025-33073Microsoft WindowsEPSS up 14 points in about a week
- CVE-2026-58644Microsoft SharePointAdded to CISA KEV 2026-07-16; Added to VulnCheck KEV 2026-07-14; Added to ENISA EUVD 2026-07-16
- CVE-2026-15409SonicWall SMA1000 AppliancesAdded to CISA KEV 2026-07-14; Added to VulnCheck KEV 2026-07-14; Added to ENISA EUVD 2026-07-14; Exploitation active since 2026-07-14
- claimBolt & Nut Manufacturingclaimed by Qilin, unverified
- claimAssociated Theatrical Contractorsclaimed by Qilin, unverified
- claimDon Tortaco Mexican Grillclaimed by Qilin, unverified
- claimCity Ambulance Serviceclaimed by Qilin, unverified
- claimFamesaclaimed by Qilin, unverified
- claimSynergy Productsclaimed by Qilin, unverified
- claimEanaclaimed by Qilin, unverified
- claimPP+Kclaimed by Qilin, unverified
- claimNewNetclaimed by Dragonforce, unverified
- claimPetrini Valoresclaimed by Dragonforce, unverified
- claimKee Wah Bakeryclaimed by Dragonforce, unverified
- claimSinai Grand Casinoclaimed by Dragonforce, unverified
- claimMetro Design Centeclaimed by Dragonforce, unverified
- claimSouthport Outdoor Livingclaimed by Dragonforce, unverified
- claimNorth Atlantic Engineering Consultantsclaimed by Dragonforce, unverified
- claimHeritage Mechanical LLCclaimed by Dragonforce, unverified
- claimEcopetrolclaimed by The Gentlemen, unverified
- claimSunway Scientificclaimed by The Gentlemen, unverified
- claimMilitary Sealift Commandclaimed by The Gentlemen, unverified
- claimAdvantage Home Health Careclaimed by The Gentlemen, unverified