Week 2026-W32
223 stories tracked from July 27 to August 03, 2026, up 19 from the prior 7 days. 3 new KEV entries. 347 ransomware victims claimed.
- vulnerabilitiesCISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2025-68686 in Fortinet FortiOS and CVE-2026-16812 in Arista VeloCloud Orchestrator, both showing active exploitation in the wild. The additions underscore CISA's continued effort to maintain a prioritized list of vulnerabilities being actively exploited, with federal agencies required under Binding Operational Directive 26-04 to prioritize patching these high-risk flaws on publicly exposed systems.
- vulnerabilities2 sourcesCheck Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
Check Point released a security advisory on July 22, 2026 for CVE-2026-16232, an authentication bypass in SmartConsole that allows unauthenticated attackers to obtain administrator tokens and modify security policies on affected Security Management and Multi-Domain Management servers. The vulnerability stems from a broken trust boundary where the server accepts an attacker-supplied certificate distinguished name instead of validating it against the authenticated peer certificate. Rapid7 Labs confirmed exploitation against R81.20 and R82.10 versions and verified that vendor patches successfully remediate the flaw.
- vulnerabilities27th July – Threat Intelligence Report
A weekly threat intelligence bulletin covers major incidents including ransomware attacks on Nichirei (Japan) and Stadler Rail (Switzerland), unauthorized access at Origin Energy (Australia), and a cyberattack on Romania's land registry system. The report details AI model escape incidents, emergence of AI-assisted penetration-testing and malware platforms, and critical vulnerabilities in Check Point SmartConsole, Oracle products, and Microsoft SharePoint Server under active exploitation. Researchers also identified Microsoft as the most impersonated brand in phishing campaigns during Q2 2026.
- vulnerabilities3 sourcesCVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
JetBrains disclosed CVE-2026-63077, a critical unauthenticated remote code execution vulnerability in TeamCity On-Premises with a CVSS score of 9.8, affecting all versions. Attackers exploiting the deserialization flaw via the agent polling protocol can execute arbitrary commands with server process privileges, read credentials, and compromise CI/CD pipelines. JetBrains published fixed versions (TeamCity 2025.11.7 and 2026.1.3) and a security patch plugin for older releases, with no reported active exploitation at disclosure.
- ot ics5 sourcesCoordinated cyberattack hits more than 30 Minnesota water utilities
A coordinated cyberattack targeted operational technology systems at more than 30 Minnesota water utilities on July 26 and 27. Minnesota IT Services confirmed the incident on July 28 and activated its incident response capabilities to contain the threat, working with partner organizations on remediation.
- vulnerabilities2 sourcesCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains disclosed a critical vulnerability in TeamCity on-premises (CVE-2026-63077, CVSS 9.8) that permits unauthenticated arbitrary code execution. The flaw has been patched in versions 2025.11.7 and 2026.1.3, while TeamCity Cloud instances are unaffected.
- vulnerabilities2 sourcesCritical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
Ruby on Rails released patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS 9.5) that allows unauthenticated attackers to read arbitrary server files through specially crafted image uploads. The flaw could expose sensitive data including environment variables, secret keys, database passwords, and cloud storage credentials stored on vulnerable application servers.
- vulnerabilities2 sourcesThree Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Broadcom released security updates for VMware ESX, vCenter, Workstation, and Fusion to address multiple flaws, including three rated critical. CVE-2026-59309, a critical authentication bypass in vCenter with a CVSS score of 9.8, allows network-accessible attackers to exploit the vulnerability.
- vulnerabilitiesAdobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction
Adobe released security updates for Campaign Classic addressing CVE-2026-48449, a CVSS 10.0 vulnerability involving incorrect authorization that enables arbitrary code execution without user interaction. The flaw affects the enterprise marketing automation platform and requires immediate patching.
- industry5 sourcesMicrosoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost
Microsoft introduced MAI-Cyber-1-Flash, a security-focused AI model integrated into MDASH for vulnerability identification and remediation. The company claims the model underwent review by its internal AI Red Team, adversarial testing, and third-party assessment. Microsoft positions the offering as a cost-effective alternative to existing solutions, citing the growing need for AI-driven defenses as attackers leverage AI to search codebases for vulnerabilities.
- CVE-2025-68686Fortinet FortiOSdue 2026-08-10
- CVE-2026-16812Arista VeloCloud Orchestratordue 2026-07-30
- CVE-2026-20316Cisco Secure Firewall Management Center (FMC)due 2026-08-01
- CVE-2026-12569PTC Windchill and FlexPLMEPSS up 28 points in about a week
- CVE-2023-3824PHP PHPEPSS up 13 points in about a week
- CVE-2025-68686Fortinet FortiOSAdded to CISA KEV 2026-07-27; Added to VulnCheck KEV 2026-07-27; Added to ENISA EUVD 2026-07-27
- CVE-2026-50522Microsoft SharePointEPSS up 19 points in about a week
- CVE-2026-16232Check Point SmartConsoleEPSS up 59 points in about a week
- claimFreedom Claims Managementclaimed by Qilin, unverified
- claimINTERTRUST AUSTRALIA PTY LTDclaimed by Qilin, unverified
- claimAsset Flooring Group Australiaclaimed by Qilin, unverified
- claimMairie de Drancyclaimed by Qilin, unverified
- claimThe Saturday Evening Postclaimed by Qilin, unverified
- claimCommercial Furniture Interiorsclaimed by Qilin, unverified
- claimDienst Pack Systemsclaimed by Qilin, unverified
- claimCeragresclaimed by Qilin, unverified
- claimPhilippine Savings Bankclaimed by The Gentlemen, unverified
- claimWorld Wide Fittingsclaimed by The Gentlemen, unverified
- claimChemco Systemsclaimed by The Gentlemen, unverified
- claimTotal Auto Business Solutionsclaimed by The Gentlemen, unverified
- claimOkovolt Solartechnikclaimed by The Gentlemen, unverified
- claimPaula Fishclaimed by The Gentlemen, unverified
- claimAmicellclaimed by The Gentlemen, unverified
- claimKnownclaimed by The Gentlemen, unverified
- claimPhilippine Savings Bankclaimed by Thegentlemen, unverified
- claimLas Cenizasclaimed by Thegentlemen, unverified
- claimKenaitze Indian Tribeclaimed by Thegentlemen, unverified
- claimPertaminaclaimed by Thegentlemen, unverified