The Data at a Glance
Our threat monitors recorded a massive volume of security alerts. Specifically, analysts logged nearly three thousand new vulnerabilities this week. Furthermore, 407 of these flaws earned a critical severity rating. Additionally, researchers classified 996 vulnerabilities as high risk. Therefore, you must ruthlessly prioritize your incident response. You cannot manually patch every single software bug. Instead, you must focus entirely on actively weaponized threats. Consequently, this weekly threat intelligence briefing serves as your ultimate survival guide.
Exploited CVEs Added to CISA KEV (July 20–26, 2026)
CISA flagged six actively exploited CVEs during the week of July 20–26, 2026. They rose out of a field of 2,887 newly published CVEs. Each one earned a place in the Known Exploited Vulnerabilities catalog because attackers are using it right now. Several enable remote code execution on internet-facing systems.
| # | CVE | Vendor / Product | CVSS | Severity | Impact |
|---|---|---|---|---|---|
| 1 | CVE-2026-50522 | Microsoft SharePoint Server | 9.8 | Critical | Untrusted deserialization leading to unauthenticated RCE; linked to IIS machine-key theft |
| 2 | CVE-2026-63030 | WordPress Core | 9.8 | Critical | REST API batch route confusion chained with SQL injection to reach RCE |
| 3 | CVE-2026-0770 | Langflow | 9.8 | Critical | Unauthenticated RCE as root via the exec_globals parameter on the validate endpoint |
| 4 | CVE-2026-16232 | Check Point SmartConsole | 9.1 | Critical | Authentication bypass that yields full administrative access |
| 5 | CVE-2021-27137 | DD-WRT | 8.1 | High | Unauthenticated UPnP buffer overflow reachable through an M-SEARCH request |
| 6 | CVE-2026-60137 | WordPress Core | 5.9 | Medium | SQL injection through the author__not_in parameter of WP_Query |
Source: CVE WATCHTOWER weekly report, July 20–26, 2026. All six were added to the CISA KEV catalog during that week.
The Standouts
SharePoint deserialization RCE
CVE-2026-50522 tops the list for real-world impact. It is a critical deserialization flaw in on-premises Microsoft SharePoint Server. A public proof-of-concept appeared on July 20, and attacks followed within hours. CISA added it to the catalog on July 22. Worse, attackers pull IIS machine keys, so a patch alone may not evict them. Rotate those keys after you update.
Check Point SmartConsole auth bypass
CVE-2026-16232 lets an unauthenticated attacker grab an admin login token. From there, they can rewrite security policies and configurations. CISA confirmed active exploitation and listed the flaw on July 22. Check Point says the attacks reached only a small number of customers.
WordPress SQL injection to RCE
Two WordPress Core flaws made the cut. CVE-2026-60137 allows SQL injection through the author__not_in parameter. Chained with the REST API route confusion in CVE-2026-63030, an attacker can reach remote code execution. Update to WordPress 6.9.5 or 7.0.2 without delay.
Langflow and DD-WRT
CVE-2026-0770 grants unauthenticated RCE as root through Langflow’s validate endpoint. Meanwhile, CVE-2021-27137 revives an old DD-WRT UPnP buffer overflow. Both now sit on the actively exploited CVEs list, so exposed instances need quick attention.
Maximum Severity Flaws Uncovered
Our weekly threat intelligence briefing also tracks catastrophic CVSS 10.0 vulnerabilities. Specifically, Microsoft Exchange Online suffers from a devastating improper authentication bug (CVE-2026-56191). Attackers easily tamper with cloud communications over the network. Meanwhile, Oracle enterprise products harbor multiple maximum-severity vulnerabilities.
For example, Oracle Weblogic Server Proxy Plug-in (CVE-2026-60365) exposes networks to complete compromise. Additionally, Oracle Access Manager (CVE-2026-60358) and Oracle Unified Directory (CVE-2026-60360) face similar threats. Hackers can rapidly destroy entire corporate networks using these flaws.
Furthermore, open-source hardware projects also suffer from critical pipeline vulnerabilities. Meshtastic is a popular open-source mesh networking solution. Prior to version 2.7.21, the main GitHub repository contained a fatal workflow flaw (CVE-2026-44359). Consequently, malicious contributors could hijack the entire deployment process. You must always secure your software supply chain tightly.
Active Vulnerability Update: Fastjson Under Attack
We detected aggressive exploitation of Fastjson in the wild. A remote code execution vulnerability (CVE-2026-16723-admin) plagues versions 1.2.68 through 1.2.83. Unfortunately, this exploit works under default configurations. Therefore, developers must upgrade their Java libraries immediately.
You must digest this active vulnerability update and act immediately. First, patch your Check Point firewalls and Microsoft SharePoint servers. Next, secure your Oracle middleware deployments without delay. Finally, update all WordPress installations rapidly. You cannot ignore these glaring security holes. We will consistently deliver this intelligence to help you defend your infrastructure.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.