Welcome to the CVE WATCHTOWER briefing. Our latest weekly threat intelligence report reveals an alarming surge in cyber threats. Specifically, security researchers uncovered 2,757 new vulnerabilities between July 13 and July 19, 2026. Therefore, security teams must act quickly to secure their perimeters. Furthermore, we are providing critical active vulnerability updates to help you prioritize your patching efforts. Threat actors are aggressively targeting enterprise infrastructure this week. Consequently, immediate action is necessary to prevent devastating corporate breaches.
CISA KEV Adds Critical Infrastructure Flaws
The Cybersecurity and Infrastructure Security Agency (CISA) recently added 10 vulnerabilities to its Known Exploited Vulnerabilities catalog. Hackers are currently exploiting several severe flaws. For example, Fortinet FortiSandbox suffers from two critical OS command injection bugs. These specific flaws (CVE-2026-25089 and CVE-2026-39808) allow attackers to execute unauthorized commands easily. Additionally, the SMA1000 Appliance Work Place interface contains a maximum-severity Server-Side Request Forgery vulnerability (CVE-2026-15409). Unauthenticated attackers can route malicious requests to unintended internal locations.
Moreover, Microsoft Office SharePoint faces active exploitation through a dangerous deserialization flaw (CVE-2026-58644). Similarly, Oracle Payments users face a critical takeover risk via CVE-2026-46817. Attackers can completely compromise unpatched Oracle financial systems over HTTP. Interestingly, threat actors are also weaponizing legacy bugs. CISA just added a Cisco IOS vulnerability from 2008 (CVE-2008-4128) to the active exploitation list.
Emerging AI and Framework Threats
Beyond the CISA KEV list, our weekly threat intelligence report highlights significant dangers in emerging technologies. Artificial intelligence frameworks remain highly vulnerable. Notably, IBM Langflow OSS exposes users to a severe path traversal vulnerability (CVE-2026-8859). Malicious actors can write arbitrary files directly to the server. Furthermore, Jupyter Enterprise Gateway contains a critical bypass flaw (CVE-2026-44180). This specific bug allows attackers to launch notebooks as the root user. Consequently, hackers can easily escape containers and compromise entire Kubernetes clusters.
Additionally, data scientists must watch out for the Keras machine learning library. A new vulnerability (CVE-2026-12484) allows unsafe deserialization of PyTorch data. Therefore, untrusted model configurations can execute arbitrary code on host machines. Furthermore, security teams discovered a dangerous local file read bug in Anyquery (CVE-2026-54629). Unauthenticated attackers can access sensitive system configurations easily.
Urgent Remediation Strategies
Your organization must immediately deploy active vulnerability updates to prevent network compromises. First, you should patch all Fortinet and SMA1000 appliances without delay. Next, network administrators must isolate any unpatched Microsoft SharePoint servers. Developers must also restrict untrusted access to Jupyter and AI environments.
Additionally, security leaders must monitor third-party vendor risks. Software supply chains remain a highly vulnerable attack vector. Furthermore, you should audit your network for outdated Cisco routers. Old vulnerabilities can still cause catastrophic damage today. Ultimately, swift patching remains your absolute best defense against these relentless attacks. We will continuously monitor the threat landscape to keep your systems safe.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.