Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 20 July 2026 - Nine New Known Exploited Vulnerabilities Added

CISA added nine new vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog during the past seven days, spanning enterprise collaboration platforms (Microsoft SharePoint), identity services (AD FS), sandboxing solutions (Fortinet FortiSandbox), access gateways (SonicWall SMA1000), financial ERP suites (Oracle E-Business Suite), and industrial automation protocols (KNX). The most significant operational trend is the concentrated targeting of remote access gateways, internal sandboxing infrastructure, and enterprise collaboration platforms for unauthenticated command injection, SSRF, and privilege escalation. Security, vulnerability management, and infrastructure teams should prioritize perimeter appliances, identity providers, and SharePoint environments for immediate validation and remediation activity.

Reading time 10 minutes

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

This Week's KEV Additions

 

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Reachability
CVE-2026-58644 Microsoft SharePoint Server 9.8 (Critical) 16 July 2026 06 Aug 2026 Untrusted Deserialization → Network RCE 1.00% (0.01000) Network
CVE-2026-25089 Fortinet FortiSandbox 9.8 (Critical) 16 July 2026 06 Aug 2026 OS Command Injection → Unauthenticated RCE 2.03% (0.02030) Network
CVE-2026-39808 Fortinet FortiSandbox 9.8 (Critical) 16 July 2026 06 Aug 2026 OS Command Injection via HTTP Requests 48.67% (0.48670) Network
CVE-2026-46817 Oracle E-Business Suite 9.8 (Critical) 15 July 2026 05 Aug 2026 Improper Privilege Management / Takeover 1.05% (0.01050) Network
CVE-2023-4346 KNX Association Protocol 7.5 (High) 15 July 2026 05 Aug 2026 Restrictive Lockout / Device Account Purge 0.86% (0.00860) Network
CVE-2026-56155 Microsoft AD FS 7.8 (High) 14 July 2026 04 Aug 2026 Insufficient Granularity Access Control → Local EoP 0.38% (0.00380) Network
CVE-2026-56164 Microsoft SharePoint Server 9.8 (Critical) 14 July 2026 04 Aug 2026 Missing Authentication → Network EoP 7.05% (0.07047) Network
CVE-2026-15409 SonicWall SMA1000 10.0 (Critical) 14 July 2026 04 Aug 2026 Server-Side Request Forgery (SSRF) 1.40% (0.01404) Network
CVE-2026-15410 SonicWall SMA1000 7.2 (High) 14 July 2026 04 Aug 2026 Authenticated Admin Code Injection → OS Command Exec 1.65% (0.01647) Network

 

 

Analysis

 

CVE-2026-58644 - Microsoft SharePoint Server

What it is → An unauthenticated remote code execution flaw caused by improper deserialization of untrusted data in Microsoft SharePoint Server. 

Affected versions → Supported versions of Microsoft SharePoint Server (refer to MSRC July 2026 guidance).

Exploitation status Active zero-day exploitation confirmed via CISA KEV inclusion.

Patch available Yes. Security updates available via Microsoft MSRC.

Operational risk Allows network-adjacent or remote unauthenticated attackers to execute arbitrary code on SharePoint hosts, serving as an immediate entry point into corporate intranet domains.

 

CVE-2026-25089 - Fortinet FortiSandbox

What it is→ An OS command injection flaw (CWE-78) in the Web UI resulting from improper neutralization of special elements in HTTP requests.

Affected versions → FortiSandbox 5.0.0 through 5.0.5 → FortiSandbox 4.4.0 through 4.4.8 → FortiSandbox 4.2 (all versions) → FortiSandbox Cloud & PaaS 5.0.4 through 5.0.5

Exploitation status Active exploitation confirmed via CISA KEV inclusion.

Patch available Yes. Addressed in Fortinet Advisory FG-IR-26-141.

Operational risk Compromising security sandboxing appliances grants threat actors root-level access, blinding internal malware inspection mechanisms and enabling network lateral movement.

 

CVE-2026-39808 - Fortinet FortiSandbox

What it is→ An unauthenticated OS command injection vulnerability in FortiSandbox handling specific HTTP request routes.

Affected versions → FortiSandbox 4.4.0 through 4.4.8

Exploitation status Active exploitation confirmed; elevated EPSS score indicates widespread scanning and exploitation attempts.

Patch available Yes. Fixed in FortiSandbox version 4.4.9 (FG-IR-26-100).

Operational risk High reliability unauthenticated code execution path targeting threat analysis infrastructure.

 

CVE-2026-46817 - Oracle E-Business Suite

What it is→ An improper privilege management vulnerability (CWE-269/CWE-287) in the Oracle Payments component (File Transmission).

Affected versions → Oracle E-Business Suite 12.2.3 through 12.2.15

Exploitation status Active exploitation confirmed through KEV inclusion.

Patch available Yes. Addressed in Oracle Critical Patch Update advisory.

Operational risk Allows unauthenticated HTTP network attackers to fully compromise Oracle Payments, presenting immediate risk to enterprise financial transaction processing.

 

CVE-2023-4346 - KNX Association Protocol

What it is → An overly restrictive account lockout vulnerability in KNX Connection Authorization Option 1.

Affected versions → KNX Connection Authorization Option 1 compliant implementations.

Exploitation status Active exploitation confirmed via KEV inclusion.

Patch available Yes. Vendor mitigation and configuration guidance published.

Operational risk Network-reachable attackers can purge all devices lacking secondary security options and set unauthorized BCU keys, causing permanent loss of access and physical facility management disruption.

 

CVE-2026-56155 - Microsoft Active Directory Federation Services

What it is → An elevation of privilege vulnerability stemming from insufficient granularity of access control within AD FS.

Affected versions → Supported versions of Windows Server running AD FS.

Exploitation status Active exploitation confirmed via MSRC and CISA KEV.

Patch available Yes. Patched in Microsoft July 2026 Patch Tuesday release.

Operational risk Allows local authenticated users to escalate privileges to full identity infrastructure control on AD FS servers.

 

CVE-2026-56164 - Microsoft SharePoint Server

What it is →A missing authentication flaw for critical functions in Microsoft SharePoint Server enabling remote privilege escalation. 

Affected versions → Supported Microsoft SharePoint Server editions. Exploitation status Active zero-day exploitation confirmed.

Patch available Yes. Available via Microsoft MSRC.

Operational risk Unauthenticated network attackers can bypass security controls to escalate rights across farm resources without credentials.

 

CVE-2026-15409 - SonicWall SMA1000

What it is →A Server-Side Request Forgery (SSRF) vulnerability in the Work Place management interface. 

Affected versions → SonicWall SMA1000 Series Appliances (Firmware prior to emergency hotfix).

Exploitation status Active zero-day exploitation confirmed by threat intelligence teams.

Patch available Yes. SonicWall released emergency patches and hotfixes.

Operational risk Critical perimeter bypass allowing unauthenticated attackers to force the appliance to issue unauthorized requests to internal network services.

 

CVE-2026-15410 - SonicWall SMA1000

What it is →Improper control of generation of code (Code Injection) in the Appliance Management Console (AMC). 

Affected versions → SonicWall SMA1000 Series Appliances.

Exploitation status Active zero-day exploitation confirmed in conjunction with perimeter targeting.

Patch available Yes. Hotfixes released by SonicWall.

Operational risk Allows authenticated administrative users (or attackers leveraging chained credentials/SSRF) to execute arbitrary OS commands at the system level.

 

 

Exploitation Context

 

This week's KEV additions reflect aggressive threat actor focus on edge remote-access devices (SonicWall SMA1000), identity/collaboration hubs (Microsoft AD FS & SharePoint), and security detection assets (Fortinet FortiSandbox).

Attackers are combining perimeter SSRF and unauthenticated OS command injection to gain immediate footholds on internal subnets without requiring endpoint interaction. The simultaneous targeting of security sandboxes highlights an intentional tactic to neutralize detection platforms prior to lateral movement or ransomware deployment.

 

 

Remediation Priorities

 

Priority CVE Recommended Action Timeline
Critical CVE-2026-15409 Apply SonicWall hotfix immediately; restrict Work Place interface exposure. Immediate
Critical CVE-2026-58644 Patch SharePoint Server; audit server logs for untrusted deserialization objects. Immediate
Critical CVE-2026-56164 Apply SharePoint privilege escalation patches. Immediate
Critical CVE-2026-25089 Upgrade FortiSandbox to fixed builds (FG-IR-26-141); isolate Web UI. Immediate
Critical CVE-2026-39808 Upgrade FortiSandbox to 4.4.9 or later. Immediate
Critical CVE-2026-46817 Patch Oracle E-Business Suite (Oracle Payments component). Within 24 Hours
High CVE-2026-15410 Patch SonicWall SMA1000 AMC; restrict administrative console access. Within 24 Hours
High CVE-2026-56155 Apply Microsoft security updates to all AD FS infrastructure hosts. Within 72 Hours
Medium CVE-2023-4346 Enforce secondary security options on KNX networks; restrict local interface access. Next Patch Window

 

 

Detection and Monitoring Guidance

 

 

CVE Minimum Detection Guidance
CVE-2026-58644 Inspect IIS logs for anomalous POST requests targeting SharePoint endpoints and monitor for unexpected child process creation (cmd.exe, powershell.exe) under w3wp.exe.
CVE-2026-25089 Monitor FortiSandbox Web UI traffic for HTTP requests containing shell metacharacters (|, ;, $()); inspect egress traffic for new outbound connections.
CVE-2026-39808 Monitor HTTP access logs on FortiSandbox management interfaces for malformed parameters and unauthenticated command strings.
CVE-2026-46817 Review Oracle E-Business Suite web server logs for unauthorized access to File Transmission endpoints in Oracle Payments.
CVE-2023-4346 Audit KNX network traffic for unusual BCU key assignment commands or repetitive lockout triggers across bus devices.
CVE-2026-56155 Audit Windows Event Logs (Event ID 4624/4672) on AD FS servers for abnormal local privilege assignments and token manipulation.
CVE-2026-56164 Monitor SharePoint API calls and web requests attempting unauthenticated administrative function calls.
CVE-2026-15409 Monitor SMA1000 Work Place web logs for outbound HTTP/HTTPS requests directed toward internal IP ranges or loopback addresses.
CVE-2026-15410 Audit SMA1000 AMC administrative activity logs for anomalous OS-level command strings executed during active web sessions.

 

Hackerstorm Analysis

 

This week's KEV updates emphasize a critical shift in attacker methodology: targeting the platforms organizations rely on for security and remote connectivity. By compromising FortiSandbox appliances and SonicWall gateways, threat actors disable early warning telemetry and establish persistent network footholds simultaneously.

Furthermore, zero-day exploitation against core enterprise productivity tools—specifically Microsoft SharePoint—underlines that internal collaboration servers remain primary targets for initial access and privilege expansion.

Practitioners must prioritize KEV listings above standard CVSS metrics. CISA KEV inclusion confirms real-world adversary adoption, requiring immediate exposure validation, interface hardening, and rapid patch deployment across perimeter and identity systems.

 

Further Reading

 

🔗 Exposure-Based Vulnerability Prioritization: EPSS, KEV & Risk
Why read this: Integrate EPSS scoring with KEV intelligence for exposure-driven remediation decisions.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/vulnerability-management-operational-risk-exposure-prioritization

 

🔗 CVE Overload: Why Most Patch Programs Fail
Why read this: Identify systemic vulnerabilities in traditional patching workflows.
https://www.hackerstorm.com/articles/our-blog/vulnerabililty-intelligence/why-most-patch-programs-fail

 

🔗 CVSS vs EPSS: How to Prioritise Vulnerabilities by Real Exploitation Risk
Why read this: Replace static severity scoring with probability-based threat modeling.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/cvss-vs-epss-vulnerability-prioritisation-exploitation-risk

 

 

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

CISA Known Exploited Vulnerabilities (KEV) Catalog Primary source used to verify KEV additions, inclusion dates, exploitation status, and Federal Civilian Executive Branch (FCEB) remediation deadlines.

Microsoft Security Response Center (MSRC) Advisory — CVE-2026-58644 / CVE-2026-56155 / CVE-2026-56164 Used to validate affected SharePoint and AD FS versions, exploitation conditions, and security update releases.

Fortinet Security Advisories — FG-IR-26-141 / FG-IR-26-100 Used to confirm affected FortiSandbox builds, vulnerability mechanisms, and patch availability.

Oracle Critical Patch Update — CVE-2026-46817 Used to validate affected Oracle E-Business Suite versions and privilege management impact.

SonicWall Security Advisories — CVE-2026-15409 / CVE-2026-15410 Used to validate SMA1000 zero-day exploitation details, SSRF mechanics, and hotfix requirements.

KNX Association Security Guidance — CVE-2023-4346 Used to confirm protocol lockout conditions, affected options, and mitigation controls.

FIRST Exploit Prediction Scoring System (EPSS) Database Used to provide exploitation probability metrics supporting threat-informed patch prioritization.

Hackerstorm CVE Intelligence Portal Used for internal CVE enrichment, analyst workflow integration, vulnerability correlation, and report linking.

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy