【Security Vulnerability Alert】CISA added 10 known exploited vulnerabilities to the KEV catalog (2026/07/13-2026/07/19)

 
2026/7/29 ~ 2027/1/29
View Count:20

Forwarded Taiwan Computer Network Emergency Response Team / Coordination Center Security Advisory TWCERTCC-200-202607-00000011

[Description]
【CVE-2008-4128】Cisco IOS Cross-Site Request Forgery Vulnerability (CVSS v3.1: 4.3)
【Ransomware exploitation: Unknown】 Cisco IOS 12.4 used by Cisco 871 Integrated Services Router contains multiple cross-site request forgery vulnerabilities in the HTTP Administration component. A remote attacker may trick a user into sending crafted requests, thereby executing arbitrary commands on the affected device.

【CVE-2026-56155】Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (CVSS v3.1: 7.8)
【Ransomware exploitation: Unknown】 Microsoft Active Directory Federation Services has an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

【CVE-2026-56164】Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 5.3)
【Ransomware exploitation: Unknown】 Microsoft SharePoint Server has a missing authentication for critical function vulnerability, allowing an unauthorized attacker to elevate privileges over the network.

【CVE-2026-15409】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
【Ransomware exploitation: Unknown】 SonicWall SMA1000 Appliances has a server-side request forgery vulnerability that may allow an unauthenticated remote attacker to make the device send requests to unintended locations.

【CVE-2026-15410】SonicWall SMA1000 Appliances Code Injection Vulnerability (CVSS v3.1: 7.2)
【Ransomware exploitation: Unknown】 SonicWall SMA1000 Appliances has a code injection vulnerability that, under specific conditions, may allow an authenticated remote attacker with administrator privileges to execute arbitrary operating system commands.

【CVE-2026-46817】Oracle E-Business Suite Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 Oracle E-Business Suite has an improper privilege management vulnerability, allowing an unauthenticated attacker with HTTP access to compromise Oracle Payments; successful exploitation may result in takeover of Oracle Payments.

【CVE-2023-4346】KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (CVSS v3.1: 7.5)
【Ransomware exploitation: Unknown】 KNX Association KNX Protocol Connection Authorization Option 1 has an improper account lockout mechanism vulnerability that may allow an attacker to clear all devices without additional security options enabled and set a BCU key to lock the devices.

【CVE-2026-58644】Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 Microsoft SharePoint Server has a deserialization of untrusted data vulnerability that may allow an unauthorized attacker to execute code over the network.

【CVE-2026-25089】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 The Web UI of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS has an OS command injection vulnerability that may allow an unauthenticated attacker to execute unauthorized commands via crafted HTTP requests.

【CVE-2026-39808】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Ransomware exploitation: Unknown】 The API endpoint of Fortinet FortiSandbox has an OS command injection vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

[Impacted Platforms]
【CVE-2008-4128】Cisco IOS 12.4 used by Cisco 871 Integrated Services Router, involving the HTTP Administration component.

【CVE-2026-56155】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155

【CVE-2026-56164】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

【CVE-2026-15409】Please refer to the official listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-15410】Please refer to the official listed affected versions https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-46817】Please refer to the official listed affected versions https://www.oracle.com/security-alerts/cspumay2026.html

【CVE-2023-4346】Please refer to the listed affected versions https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01

【CVE-2026-58644】Please refer to the official listed affected versions https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-25089】Please refer to the official listed affected versions https://fortiguard.fortinet.com/psirt/FG-IR-26-141

【CVE-2026-39808】Please refer to the official listed affected versions https://fortiguard.fortinet.com/psirt/FG-IR-26-100

[Recommended Actions]
【CVE-2008-4128】 The affected product may have reached End of Life (EoL) and/or End of Service (EoS); users are advised to discontinue use of the product. https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html

【CVE-2026-56155】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155

【CVE-2026-56164】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

【CVE-2026-15409】 The vendor has released a patch; please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-15410】 The vendor has released a patch; please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-46817】 The vendor has released a patch; please update to the relevant version https://www.oracle.com/security-alerts/cspumay2026.html

【CVE-2023-4346】 The vendor has released mitigation measures https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01

【CVE-2026-58644】 The vendor has released a patch; please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-25089】 The vendor has released a patch; please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-141

【CVE-2026-39808】 The vendor has released a patch; please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-100

Files
None
Top↑