cbcvebase.
← Exploited This Week

Exploited This Week — Jul 13–Jul 20, 2026

10 KEV · 11 newly weaponized · 0 EPSS surges

Patch now — added to CISA KEV

CVE-2026-39808
Fortinet FortiSandbox OS Command Injection Vulnerability
CISA KEV (added 2026-07-16, due 2026-07-19) · CVSS 9.8 CRITICAL · EPSS 0.84 (100th pct)

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via

Nuclei templateblogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vuldb +1
CVE-2026-25089
Fortinet FortiSandbox OS Command Injection Vulnerability
CISA KEV (added 2026-07-16, due 2026-07-19) · CVSS 9.8 CRITICAL · EPSS 0.36 (98th pct)

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud…

blogs_bleepingcomputer, blogs_checkpoint, blogs_hackernews, vulncheck
CVE-2008-4128
Cisco IOS Cross-Site Request Forgery Vulnerability
CISA KEV (added 2026-07-13, due 2026-07-16) · CVSS 4.3 MEDIUM · EPSS 0.24 (98th pct)

Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show…

ExploitDB PoCblogs_hackernews, vuldb, vulncheck
CVE-2026-56164
Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-17) · CVSS 9.8 CRITICAL · EPSS 0.06 (92th pct)

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

blogs_crowdstrike, blogs_hackernews, blogs_krebs, blogs_qualys +6
CVE-2026-15410
SonicWall SMA1000 Appliances Code Injection Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-17) · CVSS 7.2 HIGH · EPSS 0.01 (71th pct)

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…

blogs_hackernews, blogs_rapid7, blogs_tenable, vulncheck
CVE-2026-58644
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CISA KEV (added 2026-07-16, due 2026-07-19) · CVSS 9.8 CRITICAL · EPSS 0.01 (71th pct)

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

blogs_crowdstrike, blogs_hackernews, blogs_qualys, blogs_rapid7 +5
CVE-2026-15409
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-17) · CVSS 10 CRITICAL · EPSS 0.01 (66th pct)

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

blogs_hackernews, blogs_rapid7, blogs_tenable, vulncheck
CVE-2026-46817
Oracle E-Business Suite Improper Privilege Management Vulnerability
CISA KEV (added 2026-07-15, due 2026-07-18) · CVSS 9.8 CRITICAL · EPSS 0.01 (60th pct)

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network…

blogs_checkpoint, blogs_hackernews, vuldb, vulncheck
CVE-2023-4346
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
CISA KEV (added 2026-07-15, due 2026-07-29) · CVSS 7.5 HIGH · EPSS 0.01 (54th pct)

KNX devices that use KNX Connection Authorization and support Option 1 are, depending on the implementation, vulnerable to being locked and users being unable to reset them to gain access to the device. The BCU key feature on the devices…

blogs_hackernews, vuldb, vulncheck
CVE-2026-56155
Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
CISA KEV (added 2026-07-14, due 2026-07-28) · CVSS 7.8 HIGH · EPSS 0.00 (30th pct)

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.

blogs_crowdstrike, blogs_hackernews, blogs_krebs, blogs_qualys +6

Newly weaponized — exploit code appeared

CVE-2026-63030
WordPress 7.0.2 Release
CVSS 9.8 CRITICAL · EPSS 0.09 (95th pct)

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL…

blogs_rapid7, vuldb, vulncheck
CVE-2026-56291
Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
CISA KEV (added 2026-07-10, due 2026-07-13) · CVSS 9.8 CRITICAL · EPSS 0.09 (95th pct)

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

blogs_hackernews, vuldb, vulncheck
CVE-2026-46339
9router has an Incomplete Fix: Local-Only Access Gate Bypass in 9router via Host Header SpoofING
CVSS 10 CRITICAL · EPSS 0.05 (91th pct)

9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, allowing unauthenticated registration of customPlugins through…

vuldb
CVE-2026-3891
The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check…
CVSS 9.8 CRITICAL · EPSS 0.03 (85th pct)

The Pix for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check and missing file type validation in the 'lkn_pix_for_woocommerce_c6_save_settings' function in all versions up to, and…

blogs_wiz
CVE-2026-59801
9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to…
CVSS 9.8 CRITICAL · EPSS 0.02 (77th pct)

9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API endpoints by sending requests without any credentials due to missing authentication…

vuldb
CVE-2026-60137
WordPress 7.0.2 Release
CVSS 5.9 MEDIUM · EPSS 0.04 (89th pct)

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.

vuldb, vulncheck
CVE-2026-50229
Tomcat vulnerabilities
CVSS 6.1 MEDIUM · EPSS 0.03 (83th pct)

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55…

vuldb
CVE-2026-3326
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL…
CVSS 8.6 HIGH · EPSS 0.01 (58th pct)

The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

blogs_hackernews
CVE-2026-8386
The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public…
CVSS 5.3 MEDIUM · EPSS 0.00 (39th pct)

The WP Go Maps WordPress plugin before 10.0.10 does not perform any approval-state filtering on its public single-marker REST endpoint, allowing unauthenticated users to retrieve marker records that an administrator has not yet approved…

vuldb
CVE-2026-24207
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass
CVSS 9.8 CRITICAL · EPSS 0.02 (80th pct)

NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of…

🔧 no public PoC or detection rule linked yet — detection gap

+1 more lower-signal CVEs gained public exploit code this week.

Get this every Monday

Free weekly digest for blue teams — what got weaponized, with detection coverage.