Week Ending: July 19, 2026 | Overall Risk Posture: Critical
CISA added ten vulnerabilities to the Known Exploited Vulnerabilities catalog during the week ending July 19: one affecting Cisco IOS, two affecting SonicWall SMA1000 appliances, one affecting Microsoft Active Directory Federation Services, two affecting Microsoft SharePoint Server, two affecting Fortinet FortiSandbox, one affecting Oracle E-Business Suite, and one affecting the KNX building-automation protocol.
The week crossed nearly every layer of trusted infrastructure. Remote-access appliances, federation servers, collaboration platforms, routers, security sandboxes, enterprise business systems, and building controls all appeared in the same exploitation window.
The common issue is not one vendor or one vulnerability class. It is the concentration of risk in systems that control access, workflow, trust, inspection, and physical operations. When attackers compromise these platforms, they gain leverage over the environments those platforms were designed to manage or protect.
Threat at a Glance
| Area | Key Issue | Defender Priority |
|---|---|---|
| Microsoft Identity and Collaboration | Exploited flaws affect AD FS and on-premises SharePoint Server, including unauthenticated access and remote-code-execution paths. | Patch every node, investigate for persistence, and rotate exposed secrets where compromise is possible. |
| SonicWall SMA1000 | Two exploited vulnerabilities affect an internet-facing remote-access appliance. | Patch immediately, restrict management exposure, and investigate unusual sessions or internal connections. |
| Fortinet FortiSandbox | Two OS command-injection flaws affect a platform designed to analyze untrusted content. | Upgrade affected appliances, isolate management access, and review for unauthorized commands or configuration changes. |
| Oracle E-Business Suite | An exploited improper privilege-management flaw affects an enterprise platform that often handles finance, procurement, HR, and supply-chain workflows. | Apply Oracle guidance, review privileged activity, and examine integrations and service accounts. |
| KNX Building Automation | An exploited protocol flaw can disrupt connection authorization in building-control environments. | Identify exposed KNX installations, segment building systems, and apply vendor or integrator mitigations. |
| Cisco IOS | A legacy cross-site request-forgery flaw returned to operational relevance. | Find unsupported routers, remove internet-facing administration, and replace obsolete equipment. |
Active Exploitation and Immediate Risk
-
Microsoft identity and collaboration systems
CVE-2026-56155 affects Microsoft Active Directory Federation Services. AD FS is a high-trust identity component that issues and validates claims between users, applications, and connected environments.
CVE-2026-56164 and CVE-2026-58644 affect on-premises Microsoft SharePoint Server. The SharePoint flaws include missing authentication for a critical function and unsafe deserialization leading to remote code execution.
CISA has urged organizations to treat SharePoint remediation as more than a patching exercise. Attackers may steal IIS machine keys, deploy web shells, alter files, or preserve access after the vulnerable code is replaced. -
SonicWall SMA1000 remote-access appliances
CVE-2026-15409 is a server-side request-forgery vulnerability, while CVE-2026-15410 is a code-injection vulnerability affecting the same appliance family.
SMA1000 systems sit at the remote-access boundary and already broker trusted connections into internal networks. Compromise therefore creates a stronger position than an ordinary endpoint foothold. Defenders should investigate the appliance as a possible breach point, not simply mark the ticket complete after patching. -
FortiSandbox command injection
CVE-2026-25089 and CVE-2026-39808 are OS command-injection vulnerabilities affecting Fortinet FortiSandbox.
Sandboxes receive suspicious files by design and frequently connect to broader security tooling, file-transfer systems, and management networks. A compromise can undermine the inspection layer and create a trusted route into adjacent systems. -
Oracle E-Business Suite privilege abuse
CVE-2026-46817 is an improper privilege-management vulnerability affecting Oracle E-Business Suite.
E-Business Suite commonly supports high-value business processes, including finance, procurement, human resources, and supply-chain operations. An attacker who reaches privileged functions may gain access to sensitive records or manipulate business workflows that sit beyond the immediate application server.
Defenders should apply Oracle’s remediation guidance and review privileged accounts, recent administrative changes, concurrent-program activity, integrations, and service-account use. -
KNX building-automation protocol disruption
CVE-2023-4346 affects KNX Protocol Connection Authorization Option 1. The vulnerability involves an overly restrictive lockout mechanism that can allow an attacker to purge authorized users and interfere with legitimate connections.
KNX is used in commercial and residential building automation for functions such as lighting, HVAC, access control, energy management, and other facility operations. The addition expands this week’s risk beyond enterprise IT and into the systems that influence physical environments.
Organizations should identify KNX deployments, involve facilities teams and integrators, restrict network reachability, and ensure recovery procedures exist if authorized connections are disrupted. -
Legacy Cisco IOS exposure
CVE-2008-4128 is a Cisco IOS cross-site request-forgery vulnerability added to KEV on July 13.
Its age is part of the risk. Old network devices often remain in service for years, receive limited monitoring, and preserve management interfaces designed before current threat models. Attackers do not need a new vulnerability when unsupported infrastructure remains reachable.
Common Failure Patterns
-
Trusted systems receive excessive access
Federation servers, remote-access gateways, sandboxes, ERP platforms, and building controllers often receive broad permissions because they perform trusted functions. That trust increases the blast radius when the platform is compromised. -
Internet-facing control planes
Appliances and administrative interfaces are frequently exposed for convenience. A management service reachable from the internet can turn a maintenance feature into an initial-access path. -
IT and OT ownership remain separated
KNX environments may be managed by facilities teams or outside integrators rather than security operations. Fragmented ownership makes inventory, logging, patching, and incident response slower. -
Patching without compromise assessment
Replacing vulnerable code does not remove stolen keys, malicious accounts, altered configurations, implanted files, or credentials collected before remediation. -
Legacy platforms remain outside normal inventory
The Cisco IOS addition shows how old equipment can survive beyond expected refresh cycles and escape vulnerability scanning or centralized monitoring.
Defender Priorities
-
Patch exposed SonicWall and SharePoint systems first
These platforms are commonly reachable from outside the network. Apply the available security updates, restrict access, and verify successful remediation across every node. -
Investigate for persistence
Review authentication events, new accounts, modified files, scheduled tasks, configuration changes, unusual sessions, and outbound connections from affected systems. -
Protect identity secrets
Patch all AD FS servers and inspect permissions protecting federation configuration and key material. Rotate secrets when evidence suggests exposure. -
Review Oracle privileged activity
Examine administrative accounts, application roles, service accounts, integrations, and recent changes to sensitive E-Business Suite workflows. -
Bring building automation into vulnerability management
Inventory KNX gateways, management software, controllers, and remote-access paths. Coordinate remediation with facilities teams and system integrators. -
Segment security and OT infrastructure
Limit the systems that FortiSandbox and KNX components can reach. Use restricted management networks and avoid direct internet exposure. -
Retire obsolete network equipment
Find aging Cisco IOS devices, weak credentials, legacy protocols, and unsupported software. Replace devices that cannot meet a supported security baseline.
Signals to Watch
-
Continued SharePoint exploitation
Additional KEV entries, revised Microsoft guidance, or new evidence of post-patch persistence would indicate that the campaign is still expanding. -
Attack chains crossing identity and business systems
A foothold in a remote-access appliance or federation server may be used to reach SharePoint, Oracle, or other high-value applications. Monitoring each platform separately can miss the sequence. -
More building-automation vulnerabilities entering KEV
The KNX addition is a reminder that smart-building systems are operational technology. Similar flaws may affect environments that have limited telemetry and long replacement cycles. -
Security tools becoming targets
FortiSandbox reinforces a broader pattern: products deployed to inspect or protect infrastructure are valuable because they already sit inside trusted workflows.
Weekly Pulse
This week’s KEV additions were not confined to one technology stack. They reached from routers and remote-access gateways into identity, collaboration, enterprise applications, security tooling, and building automation.
Microsoft and SonicWall present the clearest immediate internet-facing exposure. Oracle raises the business-process impact, FortiSandbox shows that defensive infrastructure can become an execution surface, and KNX brings physical operations into the same vulnerability-prioritization conversation.
The operational lesson is to prioritize by trust position and business function, not only by CVSS score. A flaw in a system that controls access, financial workflows, or building operations can produce consequences far beyond the affected host.
Bottom Line
Ten exploited vulnerabilities entered the KEV catalog this week across Cisco IOS, SonicWall SMA1000, Microsoft AD FS, Microsoft SharePoint, Fortinet FortiSandbox, Oracle E-Business Suite, and the KNX building-automation protocol.
The immediate priorities are to patch exposed systems, investigate for compromise, rotate affected secrets, review privileged activity, segment security and building-control infrastructure, and remove unsupported equipment.
The systems trusted to connect users, run the business, inspect threats, and control buildings are now part of the same attack surface.
Sources
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — One KEV Addition, July 13, 2026
- CISA — Four KEV Additions, July 14, 2026
- CISA — Two KEV Additions, July 15, 2026
- CISA — Three KEV Additions, July 16, 2026
- CISA — SharePoint Hardening Guidance
- Oracle — Security Alerts and Critical Patch Updates
- KNX Association — KNX Secure
- NVD — CVE-2026-46817 Oracle E-Business Suite
- NVD — CVE-2023-4346 KNX Protocol

