Graphic visualization of monthly vulnerability trends and high-impact security threats

July 2026 CVE Landscape

In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation, 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data.

The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.

Insikt Group previously created a Nuclei template to detect the Langflow vulnerability (CVE-2025-3248) featured in this report. These are available to Recorded Future customers via the Recorded Future Intelligence Platform.

Quick reference: July 2026 Vulnerability Table

All 81 vulnerabilities below were actively exploited or operationally weaponized in July 2026. This table does not include the four CVEs that were primarily surfaced through our honeypot data, which are available to Recorded Future Intelligence Platform customers via the CVE Monthly report. The table below also provides examples of public PoCs identified by Insikt Group. These PoCs were not tested for accuracy or efficacy. Vulnerability management teams should exercise caution and verify the validity of PoCs before testing.

#
Vulnerability
Risk
Score
Vendor/Product
KEV
Analysis
RCE
PoC
1
CVE-2008-4128
99
Cisco IOS
✓ Link
2
CVE-2017-17215
99
Huawei HG532
✓ Link
3
CVE-2018-0802
99
Microsoft Office Equation Editor
✓ Link
4
CVE-2021-4034
99
Polkit
✓ Link
5
CVE-2021-27137
99
DD-WRT
✓ Link
6
CVE-2023-4346
99
KNX Association KNX Protocol Connection Authorization Option 1
7
CVE-2025-55182
99
Meta React Server Components
✓ Link
8
CVE-2025-68686
99
Fortinet FortiOS
9
CVE-2026-0770
99
Langflow
✓ Link
10
CVE-2026-15409
99
SonicWall SMA1000 Appliances
✓ Link
11
CVE-2026-15410
99
SonicWall SMA1000 Appliances
✓ Link
12
CVE-2026-16232
99
Check Point SmartConsole
✓ Link
13
CVE-2026-16812
99
Arista VeloCloud Orchestrator
14
CVE-2026-20316
99
Cisco Secure Firewall Management Center (FMC)
15
CVE-2026-25089
99
Fortinet FortiSandbox
✓ Link
16
CVE-2026-34486
99
Apache Tomcat
17
CVE-2026-39808
99
Fortinet FortiSandbox
✓ Link
18
CVE-2026-39987
99
Marimo
✓ Link
19
CVE-2026-46817
99
Oracle E-Business Suite
✓ Link
20
CVE-2026-48282
99
Adobe ColdFusion
✓ Link
21
CVE-2026-48907
99
JoomlaContentEditor.net Joomla Content Editor (JCE)
✓ Link
22
CVE-2026-48908
99
JoomShaper SP Page Builder
✓ Link
23
CVE-2026-48939
99
iCagenda
✓ Link
24
CVE-2026-50522
99
Microsoft SharePoint
✓ Link
25
CVE-2026-55255
99
Langflow
✓ Link
26
CVE-2026-56155
99
Microsoft Active Directory Federation Services
27
CVE-2026-56164
99
Microsoft SharePoint Server
✓ Link
28
CVE-2026-56290
99
Joomlack Page Builder
✓ Link
29
CVE-2026-56291
99
Balbooa Forms
✓ Link
30
CVE-2026-58644
99
Microsoft SharePoint
31
CVE-2026-60137
99
WordPress Core
✓ Link
32
CVE-2026-63030
99
WordPress Core
✓ Link
33
CVE-2021-3156
89
Sudo
✓ Link
34
CVE-2021-29441
89
Alibaba Nacos
✓ Link
35
CVE-2025-6389
89
Sneeit Framework
✓ Link
36
CVE-2025-9491
89
Microsoft Windows
✓ Link
37
CVE-2025-32432
89
Craft CMS
✓ Link
38
CVE-2025-3248
89
Langflow
✓ Link
39
CVE-2025-34152
89
Shenzhen Aitemi M300 Wi-Fi Repeater
✓ Link
40
CVE-2025-49113
89
Roundcube Webmail
✓ Link
41
CVE-2025-66376
89
Zimbra Collaboration
42
CVE-2026-0257
89
Palo Alto Networks PAN-OS and Prisma Access
✓ Link
43
CVE-2026-0740
89
SaturdayDrive Ninja Forms - File Uploads
✓ Link
44
CVE-2026-3055
89
NetScaler ADC and Gateway
✓ Link
45
CVE-2026-6875
89
ServiceNow AI Platform
✓ Link
46
CVE-2026-12569
89
PTC Windchill PDMLink and FlexPLM
47
CVE-2026-29014
89
MetInfo CMS
✓ Link
48
CVE-2026-42897
89
Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM
✓ Link
49
CVE-2026-45659
89
Microsoft SharePoint Server
50
CVE-2026-31843
87
goodoneuz pay-uz
51
CVE-2013-3307
79
Linksys E1000, E1200, and E3200
52
CVE-2016-20016
79
MVPower TV-7104HE and TV-7108HE DVRs
✓ Link
53
CVE-2017-5259
79
Cambium Networks cnPilot
54
CVE-2017-7269
79
Microsoft IIS
✓ Link
55
CVE-2018-11511
79
ASUSTOR ADM Photo Gallery
✓ Link
56
CVE-2018-14558
79
Tenda AC9, AC10, and AC7 firmware
57
CVE-2020-8515
79
DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware
✓ Link
58
CVE-2020-22653
79
Ruckus APs, SmartZone, and ZoneDirector
59
CVE-2020-22658
79
Ruckus APs, SmartZone, and ZoneDirector
60
CVE-2020-25499
79
TOTOLINK A3002RU firmware
✓ Link
61
CVE-2020-36847
79
Eemitch Simple File List
✓ Link
62
CVE-2021-31755
79
Tenda AC11 firmware
63
CVE-2021-32305
79
WebSVN
✓ Link
64
CVE-2022-35733
79
UNIMO Technology UDR-JA1004, UDR-JA1008, and UDR-JA1016 digital video recorders
65
CVE-2023-25717
79
Ruckus Wireless Admin
✓ Link
66
CVE-2024-42009
79
RoundCube Webmail
✓ Link
67
CVE-2025-9528
79
Linksys E1700
✓ Link
68
CVE-2025-12057
79
WavePlayer
✓ Link
69
CVE-2025-12352
79
Gravity Forms
70
CVE-2025-13486
79
Hwk-Fr Advanced Custom Fields: Extended
✓ Link
71
CVE-2025-28137
79
TOTOLINK A810R firmware
✓ Link
72
CVE-2026-1357
79
WPvivid Backup, Migration & Staging
✓ Link
73
CVE-2026-3395
79
MaxSite CMS
✓ Link
74
CVE-2026-3844
79
Cloudways Breeze Cache
✓ Link
75
CVE-2026-16723
79
Alibaba Fastjson
✓ Link
76
CVE-2026-29059
79
Windmill
77
CVE-2026-33824
79
Microsoft Windows IKE Extension
78
CVE-2021-24139
78
Photo Gallery by 10Web
79
CVE-2025-7852
78
Iqonic Design WPBookit
80
CVE-2026-1969
72
ThemeREX Addons WordPress plugin
81
CVE-2025-7443
71
BerqWP Automated Page Speed Optimization

Table 1: List of vulnerabilities that were actively exploited in July, 2026 based on Recorded Future data (excluding honeypot-sourced CVEs).

Trend analysis: Malware-Linked Exploitation Spans IoT, Email, and Enterprise Applications

An Insikt Group® TTP Instance on the Dysphoria botnet linked CVE-2013-3307, CVE-2016-20016, CVE-2017-17215, CVE-2017-5259, CVE-2018-14558, CVE-2020-25499, CVE-2020-8515, CVE-2022-35733, CVE-2025-28137, CVE-2025-34152, CVE-2025-55182, CVE-2025-9528 to the exploitation of routers, gateways, cameras, repeaters, and other embedded Linux devices. Dysphoria combined known RCE flaws with weak Telnet and Secure Shell credentials to enroll compromised systems into DDoS and relay infrastructure.

Figure 1: Vulnerability Intelligence Card® for CVE-2017-17215 in Recorded Future (Source: Recorded Future)

China-nexus activity showed a related interest in turning edge infrastructure into operational relay capacity. An Insikt Group® Validated Intelligence Event detailed how UAT-7810 exploited CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand the LapDogs operational relay box network. In both the Dysphoria and UAT-7810 campaigns, compromised devices were repurposed as relay infrastructure after initial access. Dysphoria used infected hosts to proxy traffic and obscure backend C2 infrastructure, while UAT-7810 expanded the LapDogs ORB network to support operations by other China-nexus actors.

Email, document, and collaboration platforms were targeted for more focused espionage and payload delivery. A TTP Instance detailed how Cloud Atlas used malicious Office documents to exploit CVE-2018-0802 and deliver CloudAtlasGo. A Validated Intelligence Event detailed how UNK_MassTraction exploited CVE-2024-42009 in Roundcube and used IceCube during post-exploitation, where the malware attempted to exploit CVE-2025-49113. A TTP Instance detailed CL-STA-1114's abuse of CVE-2025-66376, and a Validated Intelligence Event detailed TA488's exploitation of CVE-2026-42897 to deploy OWAReaper. Separately, a Validated Intelligence Event detailed an Armored Likho campaign that used a malicious shortcut to abuse CVE-2025-9491, execute obfuscated PowerShell, and deploy BusySnake Stealer. Across these campaigns, attackers targeted communications and document workflows to access sensitive information and create opportunities for additional payload execution.

Additional trends and analyses from July are available to Recorded Future customers.

Take action

Timely and relevant information on vulnerabilities in your environment and that of your vendors and suppliers is critical for reducing risk. Find out how Recorded Future can support your team by increasing visibility, improving efficiency, and enabling confident decisions.

Vulnerability Prioritization – Prioritize vulnerabilities based on the likelihood of exploitation – not just the severity. Easily understand the risk of exploitation alongside severity, and real-time contextualized intelligence to help you quickly make confident decisions, patch what matters, and prevent attacks.

Attack Surface Intelligence – Identify internet-facing assets vulnerable to a specific CVE. Attack Surface Intelligence provides an outside-in view of your organization to help you actively discover, prioritize, and respond to unknown, vulnerable, or misconfigured assets.

Third-Party Risk – Gain an external view of the security posture of your vendors and partners. Eliminate time-consuming research and vendor communication cycles with the ability to promptly assess vulnerabilities in their internet-facing systems.

Insikt Group® – Receive access to exclusive reports on new vulnerabilities and trends from Recorded Future’s team of experts, the Insikt Group®. Download Nuclei templates created by Insikt Group® for select CVEs to detect actively exploited vulnerabilities.

Recorded Future Professional Services – Work with our Professional Services team on a Vulnerability Analysis Engagement. Designed to equip your team with advanced strategies for identifying, prioritizing, and mitigating threats effectively, this program delves into technologies and operations essential for a successful vulnerability management program. (Learn more about how our Professional Services team can help your elevate your team by watching our recent Vulnerability Prioritization Workshop)

About Insikt Group®

Recorded Future’s Insikt Group, the company’s threat research division, comprises analysts and security researchers with deep government, law enforcement, military, and intelligence agency experience. Their mission is to produce intelligence that reduces risk for customers, enables tangible outcomes, and prevents business disruption.

Explore expert insights, reports, and tools to strengthen your cybersecurity strategy.