VendorResearch

July 2026 CVE Landscape


In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.

The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.

Insikt Group previously created a Nuclei template to detect the Langflow vulnerability (CVE-2025-3248) featured in this report. These are available to Recorded Future customers via the Recorded Future Intelligence Platform.

Quick reference: July 2026 Vulnerability Table

All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026. This table does not include the four CVEs that were primarily surfaced through our honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.

#

Vulnerability

Risk
Score

Vendor/Product

KEV

Analysis

RCE

PoC

1

CVE-2008-4128

99

Cisco IOS

2

CVE-2017-17215

99

Huawei HG532

3

CVE-2018-0802

99

Microsoft Office Equation Editor

4

CVE-2021-4034

99

Polkit

5

CVE-2021-27137

99

DD-WRT

6

CVE-2023-4346

99

KNX Association KNX Protocol Connection Authorization Option 1

7

CVE-2025-55182

99

Meta React Server Components

8

CVE-2025-68686

99

Fortinet FortiOS

9

CVE-2026-0770

99

Langflow

10

CVE-2026-15409

99

SonicWall SMA1000 Appliances

11

CVE-2026-15410

99

SonicWall SMA1000 Appliances

12

CVE-2026-16232

99

Check Point SmartConsole

13

CVE-2026-16812

99

Arista VeloCloud Orchestrator

14

CVE-2026-20316

99

Cisco Secure Firewall Management Center (FMC)

15

CVE-2026-25089

99

Fortinet FortiSandbox

16

CVE-2026-34486

99

Apache Tomcat

17

CVE-2026-39808

99

Fortinet FortiSandbox

18

CVE-2026-39987

99

Marimo

19

CVE-2026-46817

99

Oracle E-Business Suite

20

CVE-2026-48282

99

Adobe ColdFusion

21

CVE-2026-48907

99

JoomlaContentEditor.net Joomla Content Editor (JCE)

22

CVE-2026-48908

99

JoomShaper SP Page Builder

23

CVE-2026-48939

99

iCagenda

24

CVE-2026-50522

99

Microsoft SharePoint

25

CVE-2026-55255

99

Langflow

26

CVE-2026-56155

99

Microsoft Active Directory Federation Services

27

CVE-2026-56164

99

Microsoft SharePoint Server

28

CVE-2026-56290

99

Joomlack Page Builder

29

CVE-2026-56291

99

Balbooa Forms

30

CVE-2026-58644

99

Microsoft SharePoint

31

CVE-2026-60137

99

WordPress Core

32

CVE-2026-63030

99

WordPress Core

33

CVE-2021-3156

89

Sudo

34

CVE-2021-29441

89

Alibaba Nacos

35

CVE-2025-6389

89

Sneeit Framework

36

CVE-2025-9491

89

Microsoft Windows

37

CVE-2025-32432

89

Craft CMS

38

CVE-2025-3248

89

Langflow

39

CVE-2025-34152

89

Shenzhen Aitemi M300 Wi-Fi Repeater

40

CVE-2025-49113

89

Roundcube Webmail

41

CVE-2025-66376

89

Zimbra Collaboration

42

CVE-2026-0257

89

Palo Alto Networks PAN-OS and Prisma Access

43

CVE-2026-0740

89

SaturdayDrive Ninja Forms – File Uploads

44

CVE-2026-3055

89

NetScaler ADC and Gateway

45

CVE-2026-6875

89

ServiceNow AI Platform

46

CVE-2026-12569

89

PTC Windchill PDMLink and FlexPLM

47

CVE-2026-29014

89

MetInfo CMS

48

CVE-2026-42897

89

Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM

49

CVE-2026-45659

89

Microsoft SharePoint Server

50

CVE-2026-31843

87

goodoneuz pay-uz

51

CVE-2013-3307

79

Linksys E1000, E1200, and E3200

52

CVE-2016-20016

79

MVPower TV-7104HE and TV-7108HE DVRs

53

CVE-2017-5259

79

Cambium Networks cnPilot

54

CVE-2017-7269

79

Microsoft IIS

55

CVE-2018-11511

79

ASUSTOR ADM Photo Gallery

56

CVE-2018-14558

79

Tenda AC9, AC10, and AC7 firmware

57

CVE-2020-8515

79

DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware

58

CVE-2020-22653

79

Ruckus APs, SmartZone, and ZoneDirector

59

CVE-2020-22658

79

Ruckus APs, SmartZone, and ZoneDirector

60

CVE-2020-25499

79

TOTOLINK A3002RU firmware

61

CVE-2020-36847

79

Eemitch Simple File List

62

CVE-2021-31755

79

Tenda AC11 firmware

63

CVE-2021-32305

79

WebSVN

64

CVE-2022-35733

79

UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders

65

CVE-2023-25717

79

Ruckus Wireless Admin

66

CVE-2024-42009

79

RoundCube Webmail

67

CVE-2025-9528

79

Linksys E1700

68

CVE-2025-12057

79

WavePlayer

69

CVE-2025-12352

79

Gravity Forms

70

CVE-2025-13486

79

Hwk-Fr Advanced Custom Fields: Extended

71

CVE-2025-28137

79

TOTOLINK A810R firmware

72

CVE-2026-1357

79

WPvivid Backup, Migration & Staging

73

CVE-2026-3395

79

MaxSite CMS

74

CVE-2026-3844

79

Cloudways Breeze Cache

75

CVE-2026-16723

79

Alibaba Fastjson

76

CVE-2026-29059

79

Windmill

77

CVE-2026-33824

79

Microsoft Windows IKE Extension

78

CVE-2021-24139

78

Photo Gallery by 10Web

79

CVE-2025-7852

78

Iqonic Design WPBookit

80

CVE-2026-1969

72

ThemeREX Addons WordPress plugin

81

CVE-2025-7443

71

BerqWP Automated Page Speed Optimization

Table 1: List of vulnerabilities that were actively exploited in July, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).

  • In July 2026, the Dysphoria botnet was used to exploit known IoT and embedded-device flaws to build DDoS and relay infrastructure; Cloud Atlas abused Microsoft Equation Editor to deliver CloudAtlasGo; Armored Likho used a malicious Windows shortcut to deploy BusySnake Stealer; and JADEPUFFER and Cl0p targeted exposed AI and product-lifecycle platforms for encryption, data theft, and extortion.
  • 57 of the 85 vulnerabilities enabled remote code execution (RCE), including flaws affecting Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla ecosystems, internet-facing security appliances, and embedded network devices.
  • We identified public proof-of-concept (PoC) exploits and scanners for 60 of the 85 vulnerabilities in this report.
  • The most commonly observed weakness classes were CWE-78 (OS Command Injection), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Code Injection), and CWE-502 (Deserialization of Untrusted Data).
  • 14 of the 85 vulnerabilities in this month’s table are at least 5 years old, with the oldest approximately 18 years old, reinforcing how threat actors continue to exploit long-known weaknesses in environments where patching has lagged. Additionally, the fastest observed time from a vulnerability’s public disclosure to reported exploitation was less than one day.

Trend analysis: Malware-Linked Exploitation Spans IoT, Email, and Enterprise Applications

An Insikt Group® TTP Instance on the Dysphoria botnet linked CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, CVE-2025-9528 to the exploitation of routers, gateways, cameras, repeaters, and other embedded Linux devices. Dysphoria combined known RCE flaws with weak Telnet and Secure Shell credentials to enroll compromised systems into DDoS and relay infrastructure.


China-nexus activity showed a related interest in turning edge infrastructure into operational relay capacity. An Insikt Group® Validated Intelligence Event detailed how UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network. In both the Dysphoria and UAT-7810 campaigns, compromised devices were repurposed as relay infrastructure after initial access. Dysphoria used infected hosts to proxy traffic and obscure backend C2 infrastructure, while UAT-7810 expanded the LapDogs ORB network to support operations by other China-nexus actors.

Email, document, and collaboration platforms were targeted for more focused espionage and payload delivery. A TTP Instance detailed how Cloud Atlas used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo. A Validated Intelligence Event detailed how UNK_MassTraction exploited CVE-2024-42009 in Roundcube and used IceCube during post-exploitation, where the malware attempted to exploit CVE-2025-49113. A TTP Instance detailed CL-STA-1114’s abuse of CVE-2025-66376, and a Validated Intelligence Event detailed TA488’s exploitation of CVE-2026-42897 to deploy OWAReaper. Separately, a Validated Intelligence Event detailed an Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer. Across these campaigns, attackers targeted communications and document workflows to access sensitive information and create opportunities for additional payload execution.

Additional trends and analyses from July are available to Recorded Future customers.

Take action

Timely and relevant information on vulnerabilities in your environment and that of your vendors and suppliers is critical for reducing risk. Find out how Recorded Future can support your team by increasing visibility, improving efficiency, and enabling confident decisions.

Vulnerability Prioritization – Prioritize vulnerabilities based on the likelihood of exploitation – not just the severity. Easily understand the risk of exploitation alongside severity, and real-time contextualized intelligence to help you quickly make confident decisions, patch what matters, and prevent attacks.

Attack Surface Intelligence – Identify internet-facing assets vulnerable to a specific CVE. Attack Surface Intelligence provides an outside-in view of your organization to help you actively discover, prioritize, and respond to unknown, vulnerable, or misconfigured assets.

Third-Party Risk – Gain an external view of the security posture of your vendors and partners. Eliminate time-consuming research and vendor communication cycles with the ability to promptly assess vulnerabilities in their internet-facing systems.

Insikt Group® – Receive access to exclusive reports on new vulnerabilities and trends from Recorded Future’s team of experts, the Insikt Group®. Download Nuclei templates created by Insikt Group® for select CVEs to detect actively exploited vulnerabilities.

Recorded Future Professional Services – Work with our Professional Services team on a Vulnerability Analysis Engagement. Designed to equip your team with advanced strategies for identifying, prioritizing, and mitigating threats effectively, this program delves into technologies and operations essential for a successful vulnerability management program. (Learn more about how our Professional Services team can help your elevate your team by watching our recent Vulnerability Prioritization Workshop)

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.



Source link