CISA KEV: Fortinet FortiOS SSL-VPN Sensitive Information Exposure — Patch Bypass Actively Exploited (CVE-2025-68686)
CVE-2025-68686 is an information exposure vulnerability (CWE-200) in Fortinet FortiOS SSL-VPN that allows a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism used in post-exploitation persistence cases. The attacker must first gain filesystem-level access via a separate vulnerability before abusing this flaw to re-access sensitive resources that should have been sealed by the prior patch. CISA added it to the KEV on July 27, 2026 with a remediation deadline of August 10, 2026.
Cisco Advance Notification — August 5, 2026 Security Advisories: IOS, IOS XE, Catalyst SD-WAN IMC
Cisco PSIRT issued an advance notification on July 29, 2026 that on August 5, 2026 it will publish security advisories for vulnerabilities in Cisco IOS Software, IOS XE Software, and Catalyst SD-WAN Integrated Management Controller (IMC). These products are high-value attack targets and have been subject to sustained nation-state and criminal exploitation in prior cycles. Defenders should prepare patching workflows immediately ahead of the August 5 disclosure.
Fortinet FortiSandbox Unauthenticated OS Command Injection via Web UI (FG-IR-26-141)
Fortinet PSIRT advisory FG-IR-26-141 discloses an improper neutralization of special elements in an OS command (CWE-78) vulnerability in FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS Web UI that may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted requests. FortiSandbox is a critical detection layer in many enterprise security stacks; unauthenticated RCE in the web UI represents a high-impact attack surface for threat actors seeking to blind sandboxing and malware analysis infrastructure.
CISA ICS Advisory: Toptech Systems RCU II+ / Multiload II+ Unauthenticated Root Access via Exposed Debug Interface (CVE-2026-12562)
CISA published ICS Advisory ICSA-26-211-03 on July 30, 2026, disclosing a critical unauthenticated root access vulnerability in Toptech Systems RCU II+ and Multiload II+ petroleum load control devices used in the Energy sector. The flaw exposes a network-accessible Target Communications Framework (TCF) debug service port that requires no authentication, granting full root-level Linux system access to any attacker on the network. Successful exploitation allows full system control and manipulation of connected OT networks and resources.
Cisco Identity Services Engine (ISE) Critical RCE and Information Disclosure (CVE-2026-20181, CVE-2026-20190)
Cisco disclosed two critical vulnerabilities (CVSS 9.1) in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), affecting deployments regardless of configuration. CVE-2026-20181 is a remote code execution flaw caused by improper validation of user-supplied input; an authenticated administrator can exploit it via crafted HTTP requests to execute arbitrary OS commands. CVE-2026-20190 enables unauthorized information disclosure. No workarounds are available, and earlier versions require migration to supported releases — making ISE a high-priority patch target across enterprise networks.
Cisco Secure FMC Critical Authentication Bypass Enabling Root RCE (CVE-2026-20079)
Cisco updated its advisory for CVE-2026-20079 (CVSS 10.0) on July 29, 2026 — a critical authentication bypass in Cisco Secure FMC Software caused by an improper system process created at boot time. An unauthenticated remote attacker can bypass authentication and execute arbitrary executable scripts to obtain root access via crafted HTTP requests, without requiring any credentials or prior device access. Cisco published the same /var/tmp/license.tmp indicator of compromise as for the actively exploited CVE-2026-20316, strongly suggesting these two flaws are being chained in active attacks.
CISA ICS Advisory: MikroTik RouterOS WireGuard Private Key Extraction via Session Management Flaw (CVE-2026-14227)
CISA published ICS Advisory ICSA-26-211-01 on July 30, 2026, disclosing a session management vulnerability (Insufficient Session Expiration, CWE-613) in MikroTik RouterOS affecting all versions with the RouterOS API enabled. An attacker with low-privilege API access can extract the router's WireGuard VPN private key in plaintext due to improper session expiration and permission retention, enabling full VPN impersonation and decryption of all WireGuard-protected traffic. This advisory affects a globally deployed product used widely in IT and critical infrastructure environments.
Cisco Secure FMC Hard-Coded Password — Zero-Day Under Active Exploitation, Chains with CVSS 10.0 Auth Bypass (CVE-2026-20316 + CVE-2026-20079)
CVE-2026-20316 is an actively exploited use of hard-coded credentials in Cisco Secure Firewall Management Center (FMC) that allows an unauthenticated remote attacker to log in via a low-privileged account and access sensitive data. CISA added it to the KEV on July 29, 2026 with a federal patch deadline of August 1, 2026. In tandem, Cisco updated its advisory for the CVSS 10.0 authentication bypass CVE-2026-20079 — which enables arbitrary script execution with root access — to include shared indicators of compromise, suggesting threat actors may be chaining both flaws for full FMC compromise.
Arista VeloCloud Orchestrator On-Prem — CVSS 10.0 Unauthenticated OS Command Injection (CVE-2026-16812)
A maximum-severity (CVSS 10.0) unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem allows remote attackers to reach privileged internal functionality, execute arbitrary commands, and fully compromise the orchestrator host and all managed SD-WAN edge devices. Active exploitation was confirmed by Arista and CISA added it to the KEV catalog on July 27, 2026 with a federal FCEB remediation deadline of July 30. Hosted and dedicated VCO versions were patched ahead of the disclosure; only on-premises deployments require customer action.
Microsoft July 2026 Patch Tuesday — Two Actively Exploited Zero-Days: AD FS EoP (CVE-2026-56155) and SharePoint EoP (CVE-2026-56164)
Microsoft's record-breaking July 2026 Patch Tuesday (570–622 CVEs) included two actively exploited zero-days: CVE-2026-56155, an elevation of privilege flaw in Active Directory Federation Services discovered by Microsoft DART during active attack investigations, and CVE-2026-56164, a missing authentication vulnerability in SharePoint Server that allows unauthenticated remote privilege escalation. Both were added to CISA KEV on July 14, 2026. The release also patches critical unauthenticated RCE flaws in Windows DHCP Server and SharePoint (CVE-2026-50522, CVE-2026-58644) and a publicly disclosed BitLocker bypass (CVE-2026-50661).
WordPress Core 'wp2shell' Pre-Auth RCE Chain — CVE-2026-63030 & CVE-2026-60137 (CISA KEV, Mass Exploitation Underway)
Dubbed 'wp2shell', this critical exploit chain in WordPress Core combines CVE-2026-63030 (REST API batch-route confusion, CWE-664) and CVE-2026-60137 (SQL injection in WP_Query author__not_in parameter, CWE-89) to achieve fully unauthenticated remote code execution on default WordPress installations requiring no plugins or special configuration. Disclosed July 17, 2026, public PoC exploits appeared within hours and mass exploitation was confirmed by July 18–21; CISA added both CVEs to KEV on July 21, 2026. The attack surface covers an estimated 500+ million WordPress installations worldwide.
CISA ICS Advisory Batch — MikroTik RouterOS API Auth Brute-Force & Multiple OT/IIoT Vulnerabilities (ICSA-26-209-01 through -05)
CISA published five ICS advisories on July 28, 2026. Most notably, ICSA-26-209-05 covers a lack of effective rate-limiting and account lockout controls in MikroTik RouterOS and Cloud Hosted Router API authentication (CVE-2026-16347), allowing attackers to rapidly brute-force passwords and gain unauthorized system access across all current RouterOS versions. MikroTik devices are widely deployed as enterprise and ISP routers globally, and unpatched API exposure represents a significant network perimeter risk.
CISA KEV: Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) — Actively Exploited Zero-Day
CVE-2026-16812 is a CVSS 10.0 unauthenticated OS command injection flaw in Arista VeloCloud Orchestrator On-Prem that allows remote attackers to access privileged internal functionality and execute arbitrary OS commands on the VCO host. Arista confirmed active exploitation and stated the on-premises orchestrator is exposed by default with no configuration capable of removing that exposure entirely. CISA added it to the KEV on July 27, 2026, with a federal remediation deadline of July 30, 2026 under BOD 26-04.
Fortinet FortiOS Patch Bypass Actively Exploited — Symbolic Link Persistence Technique (CVE-2025-68686)
CISA added CVE-2025-68686 to its KEV catalog on July 27, 2026, after confirming active exploitation. The flaw (CWE-200) in Fortinet FortiOS allows a remote unauthenticated attacker to bypass the patch designed to prevent a symbolic link persistence technique used by threat actors to maintain post-exploitation access on compromised FortiGate devices. Exploitation requires the attacker to have first obtained filesystem-level access via a separate vulnerability. Federal FCEB agencies must apply mitigations by August 10, 2026 per BOD 26-04.
Microsoft Windows WalletService EoP — Public PoC Released, SYSTEM Privileges (CVE-2026-49176)
CVE-2026-49176 (CVSS 7.8) is a local privilege escalation vulnerability in Windows WalletService stemming from improper privilege management and link-following behavior (CWE-269/CWE-59). A standard local user can redirect the Documents known folder to an attacker-controlled path, causing WalletService to process a malicious wallet.db and execute code at SYSTEM level — requiring no memory corruption, race condition, or admin privileges. A full public proof-of-concept was published on July 27/28, 2026 by researcher David Carliez, significantly elevating exploitation risk despite no confirmed in-the-wild exploitation yet.
AA26-097A UPDATE — Iranian-Affiliated APT Expands PLC Targeting to Schneider Electric and Siemens Alongside Rockwell Automation
FBI, CISA, NSA, EPA, DOE, US Cyber Command, and Treasury updated joint advisory AA26-097A on July 22, 2026, expanding the confirmed scope of Iranian-affiliated (IRGC CEC / CyberAv3ngers) OT intrusions to include Schneider Electric and Siemens PLCs alongside Rockwell Automation/Allen-Bradley. Threat actors connect to internet-exposed PLCs using vendors' own legitimate engineering software (Studio 5000, EcoStruxure Control Expert, TIA Portal), manipulate ladder logic, alter SCADA displays, and in at least one confirmed U.S. victim site disabled alarm and safety shutdown logic. New July 2026 STIX-formatted IOCs were released alongside the update.
AA26-194A — Russian FSB Center 16 Exploits Poorly Configured Routers Across Global Critical Infrastructure
A 19-agency joint advisory (NSA, CISA, FBI, DC3, and 15 international partners from 13 countries) details decade-long campaigns by Russian FSB Center 16 (aka Berserk Bear / Turla / Ghost Blizzard) exploiting internet-exposed routers with weak or default SNMP community strings. Actors issue SNMP Set-Requests abusing Cisco CISCO-CONFIG-COPY-MIB to exfiltrate device configurations and credentials via TFTP, providing persistent access to critical infrastructure across communications, defense industrial base, energy, financial services, state/local government, and healthcare sectors. No zero-day required — default credentials alone suffice for initial access.
Cisco RoomOS Security Hardening Release July 2026 — Multiple High-Severity Vulnerabilities (CVSS 8.8)
Cisco published a security hardening release for RoomOS on July 15, 2026, addressing multiple internally discovered vulnerabilities including improper access control flaws grouped under CWE-284 (CVE-2026-20150, CVE-2026-20153, CVE-2026-20156, CVE-2026-20157, CVE-2026-20158, CVE-2026-20187) rated High with CVSS 8.8. The vulnerabilities were found during internal testing as part of Cisco's new risk-based disclosure model and are not yet known to be actively exploited. There are no workarounds; software upgrade is the only remediation. The high CVSS score and network-attack-vector rating make this a priority patch for enterprise video conferencing infrastructure.
CISA Urges Emergency SharePoint Hardening — Active Exploitation of Multiple CVEs Including Zero-Days (CVE-2026-58644, CVE-2026-32201, CVE-2026-45659)
CISA issued an urgent alert documenting active exploitation of four on-premises SharePoint Server vulnerabilities — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644 (CVSS 9.8) — with the latter two exploited as zero-days before Microsoft patched them on July 14, 2026. Threat actors are chaining these flaws to achieve RCE, steal IIS machine keys, perform deserialization-based persistence, and deploy malware across enterprise SharePoint farms. All supported on-premises SharePoint versions (Subscription Edition, 2019, 2016) are affected. The alert was updated on July 22 to add CVE-2026-50522 to the KEV catalog with a July 25 federal deadline.
Russian APT LAUNDRY BEAR Exploits Zimbra Zero-Day XSS for Email Espionage (CVE-2025-66376)
CISA, NSA, FBI, and over two dozen international partners jointly warned that Russian state-sponsored APT LAUNDRY BEAR (aka Void Blizzard / TA488) has been exploiting a stored XSS flaw in Zimbra Collaboration Suite (ZCS) Classic UI since July 2025 — originally as a zero-day — to silently exfiltrate email, passwords, and 2FA tokens from government, defense, energy, law enforcement, and NGO targets across Western nations. The exploit requires only that a victim opens a malicious email in vulnerable Zimbra webmail; no click or download is needed. The implanted payload creates a fake app-specific credential ('ZimbraWeb') that survives password resets, and enables IMAP for persistent mailbox access.