Analyst Guidance
This week's reporting corroborates two critical vulnerabilities with active exploitation or public proof-of-concept availability: CVE-2026-42533 affecting nginx/NGINX Plus, and wp2shell RCE flaws in WordPress Core. A denial-of-service condition in OpenSSL (HollowByte) and multiple Rockwell Automation OT vulnerabilities require urgent patching. Prioritize nginx and WordPress updates immediately, followed by assessment of OpenSSL deployments and OT assets.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-15409 – SonicWall SMA1000 Appliances ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P66
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Sonicwall Sma6210 Firmware as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48282 – Adobe ColdFusion ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS29% · P98
ActionPatch immediately
Remediation Steps
- Apply the latest security patch from Adobe for ColdFusion path traversal vulnerability
- Implement input validation and sanitization on all file path parameters
- Restrict directory access permissions to the minimum required
- Review recent application logs for path traversal exploitation attempts
References:
🛡️CVE-2026-48558 – Simple-Help Simplehelp ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P64
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for SimpleHelp as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34910 – Ubiquiti UniFi OS ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS79% · P100
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Ubiquiti UniFi OS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34909 – Ubiquiti UniFi OS ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P81
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Ubiquiti UniFi OS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34908 – Ubiquiti UniFi OS ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P83
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Ubiquiti UniFi OS as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-25089 – Fortinet FortiSandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV
EPSS36% · P98
ActionPatch immediately
AffectedGovernment
Remediation Steps
- Check Fortinet advisory for FortiSandbox OS patches addressing command injection vulnerability
- Apply the latest security update from Fortinet
- Restrict command injection attack vectors by limiting command execution contexts where possible
References:
🛡️CVE-2026-39808 – Fortinet FortiSandbox ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS84% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Fortinet Fortisandbox as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-46817 – Oracle E-Business Suite ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P60
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Oracle E-Business Suite as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56164 – Microsoft SharePoint Server ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS6% · P92
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48939 – Joomlic Icagenda ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P72
ActionPatch immediately
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for iCagenda advisory
- Apply vendor patch for unrestricted file upload vulnerability
- Review upload directories for any suspicious or unexpected files
- Restrict file upload functionality to authenticated users with appropriate permissions
References:
🛡️CVE-2026-48908 – JoomShaper SP Page Builder ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS2% · P73
ActionPatch immediately
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for JoomShaper advisory and patch details
- Apply vendor patch for unrestricted file upload vulnerability
- Audit filesystem for unauthorized files or modifications
- Implement upload restrictions and validate file types server-side
References:
🛡️CVE-2026-12569 – PTC Windchill And FlexPLM ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P66
ActionPatch immediately
Remediation Steps
- Refer to CISA Known Exploited Vulnerabilities catalog for vendor-specific remediation guidance
- Apply patches provided by the affected vendor
- Monitor systems for signs of compromise
- Verify that systems are no longer vulnerable before returning to production
References:
🛡️CVE-2025-67038 – Lantronix EDS5000 ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P55
ActionPatch immediately
Remediation Steps
- Apply vendor patches immediately per Lantronix security advisory
- Isolate affected Lantronix EDS5000 devices from untrusted network segments
- Monitor for signs of unauthorized access or code execution
- Implement network access controls to restrict inbound traffic to EDS5000 management interfaces
References:
🛡️CVE-2026-56291 – Balbooa Forms ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS9% · P95
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Balbooa Forms as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56290 – Joomlack Page Builder ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS3% · P85
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Joomlack Page Builder as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-58644 – Microsoft SharePoint ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P71
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Microsoft SharePoint as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-45659 – Microsoft SharePoint Server ✓ NVD
CVSS8.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS3% · P87
ActionPatch immediately
AffectedGovernment
Remediation Steps
- Apply Microsoft security update for SharePoint Server immediately
- Restrict Internet exposure of on-premises SharePoint Server instances using firewall rules and network segmentation
- Review access logs for indicators of compromise
- Enable enhanced logging and monitoring on affected SharePoint deployments
References:
🛡️CVE-2026-20230 – Cisco Unified Communications Manager ✓ NVD
CVSS8.6 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS42% · P99
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Cisco Unified Communications Manager Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-55255 – Langflow ✓ NVD
CVSS8.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P43
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Langflow Langflow as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-56155 – Microsoft Active Directory Federation Services ✓ NVD
CVSS7.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS<1% · P30
ActionPatch immediately
AffectedGovernment Transportation
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2023-4346 – KNX Association KNX Protocol Connection Authorization Option 1 ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P54
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for KNX Association KNX Protocol Connection Authorization Option 1 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-15410 – SonicWall SMA1000 Appliances ✓ NVD
CVSS7.2 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P71
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for SonicWall SMA1000 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2008-4128 – Cisco IOS ✓ NVD
CVSS4.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS24% · P98
ActionPatch immediately
AffectedGovernment Energy
Remediation Steps
- Check CISA Known Exploited Vulnerabilities Catalog for Cisco advisory and patch information
- Apply vendor patch from Cisco Security Advisories
- Verify Cisco IOS version after patching
- Monitor for signs of unauthorized access or configuration changes on affected devices
References:
🛡️CVE-2026-42533 – nginx / NGINX Plus ✓ NVD
CVSS8.1 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported ● New this week
EPSS1% · P53
ActionPatch this week
Remediation Steps
- Upgrade nginx to version 1.30.4 (stable branch) or 1.31.3 (mainline branch) immediately
- For NGINX Plus users, update to version 37.0.3.1 or later
- Reload or restart the nginx service after upgrade
- Monitor worker process logs for crashes or restarts during transition
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.