National Cyber Warfare Foundation (NCWF)

July 2026 CVE Landscape


0 user ratings
2026-08-10 10:15:42
milo
Blue Team (CND)
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month.

In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.


The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.


Insikt Group previously created a Nuclei template to detect the Langflow vulnerability (CVE-2025-3248) featured in this report. These are available to Recorded Future customers via the Recorded Future Intelligence Platform.


Quick reference: July 2026 Vulnerability Table


All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026. This table does not include the four CVEs that were primarily surfaced through our honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.




#

Vulnerability

Risk
Score

Vendor/Product

KEV

Analysis

RCE

PoC



1

CVE-2008-4128

99

Cisco IOS

✓


✓




2

CVE-2017-17215

99

Huawei HG532


✓

✓




3

CVE-2018-0802

99

Microsoft Office Equation Editor


✓

✓




4

CVE-2021-4034

99

Polkit


✓





5

CVE-2021-27137

99

DD-WRT

✓


✓




6

CVE-2023-4346

99

KNX Association KNX Protocol Connection Authorization Option 1

✓






7

CVE-2025-55182

99

Meta React Server Components


✓

✓




8

CVE-2025-68686

99

Fortinet FortiOS

✓






9

CVE-2026-0770

99

Langflow

✓


✓




10

CVE-2026-15409

99

SonicWall SMA1000 Appliances

✓






11

CVE-2026-15410

99

SonicWall SMA1000 Appliances

✓


✓




12

CVE-2026-16232

99

Check Point SmartConsole

✓






13

CVE-2026-16812

99

Arista VeloCloud Orchestrator

✓






14

CVE-2026-20316

99

Cisco Secure Firewall Management Center (FMC)

✓






15

CVE-2026-25089

99

Fortinet FortiSandbox

✓


✓




16

CVE-2026-34486

99

Apache Tomcat


✓





17

CVE-2026-39808

99

Fortinet FortiSandbox

✓


✓




18

CVE-2026-39987

99

Marimo


✓

✓




19

CVE-2026-46817

99

Oracle E-Business Suite

✓






20

CVE-2026-48282

99

Adobe ColdFusion

✓


✓




21

CVE-2026-48907

99

JoomlaContentEditor.net Joomla Content Editor (JCE)


✓

✓




22

CVE-2026-48908

99

JoomShaper SP Page Builder

✓


✓




23

CVE-2026-48939

99

iCagenda

✓


✓




24

CVE-2026-50522

99

Microsoft SharePoint

✓


✓




25

CVE-2026-55255

99

Langflow

✓






26

CVE-2026-56155

99

Microsoft Active Directory Federation Services

✓






27

CVE-2026-56164

99

Microsoft SharePoint Server

✓






28

CVE-2026-56290

99

Joomlack Page Builder

✓


✓




29

CVE-2026-56291

99

Balbooa Forms

✓


✓




30

CVE-2026-58644

99

Microsoft SharePoint

✓


✓




31

CVE-2026-60137

99

WordPress Core

✓






32

CVE-2026-63030

99

WordPress Core

✓


✓




33

CVE-2021-3156

89

Sudo


✓





34

CVE-2021-29441

89

Alibaba Nacos


✓





35

CVE-2025-6389

89

Sneeit Framework


✓

✓




36

CVE-2025-9491

89

Microsoft Windows


✓

✓




37

CVE-2025-32432

89

Craft CMS


✓

✓




38

CVE-2025-3248

89

Langflow


✓

✓




39

CVE-2025-34152

89

Shenzhen Aitemi M300 Wi-Fi Repeater


✓

✓




40

CVE-2025-49113

89

Roundcube Webmail


✓

✓




41

CVE-2025-66376

89

Zimbra Collaboration


✓





42

CVE-2026-0257

89

Palo Alto Networks PAN-OS and Prisma Access


✓





43

CVE-2026-0740

89

SaturdayDrive Ninja Forms - File Uploads


✓

✓




44

CVE-2026-3055

89

NetScaler ADC and Gateway


✓





45

CVE-2026-6875

89

ServiceNow AI Platform


✓

✓




46

CVE-2026-12569

89

PTC Windchill PDMLink and FlexPLM


✓

✓




47

CVE-2026-29014

89

MetInfo CMS


✓

✓




48

CVE-2026-42897

89

Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM


✓





49

CVE-2026-45659

89

Microsoft SharePoint Server

✓


✓




50

CVE-2026-31843

87

goodoneuz pay-uz


✓

✓




51

CVE-2013-3307

79

Linksys E1000, E1200, and E3200


✓

✓




52

CVE-2016-20016

79

MVPower TV-7104HE and TV-7108HE DVRs


✓

✓




53

CVE-2017-5259

79

Cambium Networks cnPilot


✓

✓




54

CVE-2017-7269

79

Microsoft IIS


✓

✓




55

CVE-2018-11511

79

ASUSTOR ADM Photo Gallery


✓





56

CVE-2018-14558

79

Tenda AC9, AC10, and AC7 firmware


✓

✓




57

CVE-2020-8515

79

DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware


✓

✓




58

CVE-2020-22653

79

Ruckus APs, SmartZone, and ZoneDirector


✓





59

CVE-2020-22658

79

Ruckus APs, SmartZone, and ZoneDirector


✓





60

CVE-2020-25499

79

TOTOLINK A3002RU firmware


✓

✓




61

CVE-2020-36847

79

Eemitch Simple File List


✓

✓




62

CVE-2021-31755

79

Tenda AC11 firmware


✓

✓




63

CVE-2021-32305

79

WebSVN


✓

✓




64

CVE-2022-35733

79

UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders


✓

✓




65

CVE-2023-25717

79

Ruckus Wireless Admin


✓

✓




66

CVE-2024-42009

79

RoundCube Webmail


✓





67

CVE-2025-9528

79

Linksys E1700


✓

✓




68

CVE-2025-12057

79

WavePlayer


✓

✓




69

CVE-2025-12352

79

Gravity Forms


✓

✓




70

CVE-2025-13486

79

Hwk-Fr Advanced Custom Fields: Extended


✓

✓




71

CVE-2025-28137

79

TOTOLINK A810R firmware


✓

✓




72

CVE-2026-1357

79

WPvivid Backup, Migration & Staging


✓

✓




73

CVE-2026-3395

79

MaxSite CMS


✓

✓




74

CVE-2026-3844

79

Cloudways Breeze Cache


✓

✓




75

CVE-2026-16723

79

Alibaba Fastjson


✓

✓




76

CVE-2026-29059

79

Windmill


✓





77

CVE-2026-33824

79

Microsoft Windows IKE Extension


✓

✓




78

CVE-2021-24139

78

Photo Gallery by 10Web


✓





79

CVE-2025-7852

78

Iqonic Design WPBookit


✓

✓




80

CVE-2026-1969

72

ThemeREX Addons WordPress plugin


✓





81

CVE-2025-7443

71

BerqWP Automated Page Speed Optimization


✓

✓




Table 1: List of vulnerabilities that were actively exploited in July, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).


Key trends: July 2026



  • In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure; Cloud Atlas abused Microsoft Equation Editor to deliver CloudAtlasGo; Armored Likho used a malicious Windows shortcut to deploy BusySnake Stealer; and JADEPUFFER and Cl0p targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.

  • 57 of the 85 vulnerabilities enabled remote code execution (RCE), including flaws affecting Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla ecosystems, internet-facing security appliances, and embedded network devices.

  • We identified public proof-of-concept (PoC) exploits and scanners for 60 of the 85 vulnerabilities in this report.

  • The most commonly observed weakness classes were CWE-78 (OS Command Injection), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Code Injection), and CWE-502 (Deserialization of Untrusted Data).

  • 14 of the 85 vulnerabilities in this month’s table are at least 5 years old, with the oldest approximately 18 years old, reinforcing how threat actors continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to reported exploitation was less than one day.


Trend analysis: Malware-Linked Exploitation Spans IoT, Email, and Enterprise Applications


An Insikt Group® TTP Instance on the Dysphoria botnet linked CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, CVE-2025-9528 to the exploitation of routers, gateways, cameras, repeaters, and other embedded Linux devices. Dysphoria combined known RCE flaws with weak Telnet and Secure Shell credentials to enroll compromised systems into DDoS and relay infrastructure.









Figure 1: Vulnerability Intelligence Card® for CVE-2017-17215 in Recorded Future (Source: Recorded Future)




Source: RecordedFuture
Source Link: https://www.recordedfuture.com/blog/july-2026-cve-landscape


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.