Stay ahead of it

Security advisories

Vulnerabilities that attackers are actively exploiting right now, straight from CISA’s public Known Exploited Vulnerabilities (KEV) catalog. If any of these affect gear you use, patch it — or let us help.

What this actually means

What is a “known exploited vulnerability,” and why should a small business care?

Not theoretical — confirmed, in the wild

Security researchers find thousands of software flaws every year, but most are never actually used against real victims. CISA’s KEV catalog is different: it only lists vulnerabilities the federal government has confirmed are being actively exploited by real attackers, right now. That’s what makes this list worth checking, not the raw size of it.

Why a small business, specifically

Attackers running these exploits usually aren’t hand-picking targets — they’re scanning the whole internet for anything still running the affected software, small business or Fortune 500. A shop running an old router firmware or an unpatched web server is just as reachable as a large company, and often has fewer defenses watching for it.

Live feed

Recently added to the KEV catalog

Source: CISA KEV · as of this build, July 28, 2026

CVE-2026-16812 Jul 27, 2026

Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidenti

CVE-2025-68686 Jul 27, 2026

Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in so

CVE-2026-50522 Jul 22, 2026

Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.

CVE-2026-16232 Jul 22, 2026

Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.

CVE-2021-27137 Jul 21, 2026

DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

CVE-2026-0770 Jul 21, 2026

Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

CVE-2026-63030 Jul 21, 2026

WordPress Core

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137.

CVE-2026-60137 Jul 21, 2026

WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution o

CVE-2026-39808 Jul 16, 2026

Fortinet FortiSandbox

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CVE-2026-25089 Jul 16, 2026

Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CVE-2026-58644 Jul 16, 2026

Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.

CVE-2023-4346 Jul 15, 2026

KNX Association KNX Protocol Connection Authorization Option 1

KNX Association KNX Protocol Connection Authorization Option 1 contains an overly restrictive account lockout mechanism vulnerability that could allow an attacker to purge all devices without additional security options enabled and set a BC

CVE-2026-46817 Jul 15, 2026

Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeo

CVE-2026-15410 Jul 14, 2026

SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

CVE-2026-15409 Jul 14, 2026

SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

CVE-2026-56164 Jul 14, 2026

Microsoft SharePoint Server

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-56155 Jul 14, 2026

Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

CVE-2008-4128 Jul 13, 2026

Cisco IOS

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to

CVE-2026-48939 Jul 10, 2026

iCagenda iCagenda

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVE-2026-56291 Jul 10, 2026

Balbooa Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

CVE-2026-48282 Jul 7, 2026

Adobe ColdFusion

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

CVE-2026-56290 Jul 7, 2026

Joomlack Page Builder

Joomlack Page Builder contains an improper access control vulnerability that could allow for remote code execution via unauthenticated arbitrary file upload.

CVE-2026-55255 Jul 7, 2026

Langflow Langflow

Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request.

CVE-2026-48908 Jul 7, 2026

JoomShaper SP Page Builder

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

This is a snapshot of the most recently added entries, refreshed when the site rebuilds — not a live real-time ticker. For the full, always-current list, see the CISA catalog directly.

What to actually do

If something here touches your gear

1. Check if it applies

Look at the vendor and product name, not just the headline. Most entries affect specific versions of specific software or firmware — check what you’re actually running before assuming the worst.

2. Patch it — don’t wait

These aren’t "someday" updates. If a fix is available for something on this list, that’s the update to prioritize this week, ahead of routine patching.

3. Not sure? Ask us

If you don’t know whether your network, website, or devices are affected — or you just don’t have time to check — that’s exactly what a scoped penetration test or a quick call can answer.

Not sure if you’re exposed?

We do authorized security testing for small businesses and can check whether these affect you.