LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
CVE-2008-4128high

July 2026 CVE Landscape

In July 2026, a significant increase in high-impact vulnerabilities was observed, with 85 critical flaws identified, 36 of which had a Very Critical Recorded Future Risk Score. A notable portion of these vulnerabilities were either already listed in CISA's Known Exploited Vulnerabilities catalog or were reported by vendors. The vulnerabilities affected a wide range of products from 61 vendors, with Microsoft products being the most frequently impacted.

zeroday.news ·

Cybersecurity researchers identified 85 high-impact vulnerabilities in July 2026 that require urgent remediation, marking a 44% increase from the previous month. Of these, 36 were assigned a "Very Critical" risk score by Insikt Group. The vulnerabilities affected products from 61 vendors, with Microsoft accounting for approximately 12% of the total.

The United States Cybersecurity and Infrastructure Security Agency (CISA) listed 26 of these vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog. An additional 55 were reported by vendors, and four were primarily discovered through honeypot data.

A significant portion of the identified flaws, 57 out of 85, allowed for remote code execution (RCE). These RCE vulnerabilities impacted a wide range of systems, including products from Microsoft, Fortinet, Langflow, ServiceNow, WordPress, and Joomla, as well as internet-facing security appliances and embedded network devices. Public proof-of-concept (PoC) exploits or scanners were found for 60 of the 85 vulnerabilities.

Common weakness classes observed in July 2026 included CWE-78 (OS Command Injection), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Code Injection), and CWE-502 (Deserialization of Untrusted Data).

Notably, 14 of the 85 vulnerabilities were at least five years old, with the oldest dating back approximately 18 years, highlighting the continued exploitation of long-unpatched weaknesses. Conversely, the fastest observed time from public disclosure to reported exploitation for a vulnerability was less than one day.

Several prominent threat actor groups and botnets were active in July 2026. The Dysphoria botnet was observed exploiting known vulnerabilities in IoT and embedded devices to establish DDoS and relay infrastructure. Specifically, Dysphoria leveraged CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, and CVE-2025-9528 to compromise routers, gateways, cameras, repeaters, and other embedded Linux devices.

Other observed campaigns included Cloud Atlas abusing Microsoft Equation Editor (CVE-2018-0802) to deliver CloudAtlasGo malware, and Armored Likho deploying BusySnake Stealer via malicious Windows shortcuts. JADEPUFFER and Cl0p were noted for targeting exposed AI and product-lifecycle platforms, focusing on encryption, data theft, and extortion.

Specific vulnerabilities with a "Very Critical" risk score of 99 include CVE-2008-4128 in Cisco IOS, CVE-2017-17215 in Huawei HG532, CVE-2018-0802 in Microsoft Office Equation Editor, CVE-2021-4034 in Polkit, and CVE-2021-27137 in DD-WRT. Newer vulnerabilities with the same critical score include CVE-2025-55182 in Meta React Server Components, CVE-2025-68686 in Fortinet FortiOS, CVE-2026-0770 in Langflow, and CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 Appliances. Microsoft SharePoint also featured prominently with CVE-2026-50522, CVE-2026-56164, and CVE-2026-58644 all rated 99.

vulnerability managementthreat intelligenceexploitmalwareiot
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.