Analyst Guidance
This week saw active exploitation of three critical vulnerabilities spanning enterprise collaboration, virtualization, and creative software. Organizations should prioritize patching these three issues immediately, particularly in internet-facing and critical infrastructure environments.
CVE Details & Remediation
How to read this report
🛡️Verified facts — NVD & CISA KEV
⏳Partially verified — awaiting NVD enrichment
🧠AI analysis — synthesis, verify before acting
🛡️Actionable · Verified facts
NVD-published · CISA KEV cross-checked🛡️CVE-2026-16812 – Arista VeloCloud Orchestrator ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P56
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Arista VeloCloud Orchestrator On-Prem as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-72898 – Metabase ✓ NVD
CVSS10 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS10% · P95
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for Metabase Metabase as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-8037 – Progress LoadMaster ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS99% · P100
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Progress Connection Manager For Objectscale as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63077 – JetBrains TeamCity ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS11% · P95
ActionPatch immediately
Remediation Steps
- Check CISA's Known Exploited Vulnerabilities catalog for confirmation that this CVE affects your systems
- Apply the vendor patch immediately
- Monitor systems for evidence of exploitation
- Review access logs for suspicious activity on affected assets
References:
🛡️CVE-2026-9198 – IBM Langflow ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS17% · P97
ActionPatch immediately
Remediation Steps
- Consult CISA Known Exploited Vulnerabilities catalog for affected product details
- Identify affected systems in your environment
- Apply vendor patch as soon as available
- Verify patch installation across all instances
References:
🛡️CVE-2026-50522 – Microsoft SharePoint ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS77% · P100
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Microsoft Sharepoint Server as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-0770 – Langflow ✓ NVD
CVSS9.8 NVD 3.0
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS57% · P99
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for Langflow as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-63030 – WordPress Core ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS96% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for WordPress Core as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-16232 – Check Point SmartConsole ✓ NVD
CVSS9.8 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS73% · P99
ActionPatch immediately
AffectedTechnology Finance
Remediation Steps
- Apply the vendor security update for Checkpoint Multi-Domain Security Management as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20349 – Cisco Secure Firewall Adaptive Security Appliance (ASA) And Secure Firewall Threat Defense (FTD) ✓ NVD
CVSS8.6 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P56
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Cisco Adaptive Security Appliance Software as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18577 – N-Able N-Central ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS4% · P90
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2021-27137 – Dd-Wrt ✓ NVD
CVSS8.1 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS16% · P97
ActionPatch immediately
Remediation Steps
- Apply the vendor security update for DD-WRT DD-WRT as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-34486 – Apache Tomcat ✓ NVD
CVSS7.5 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS83% · P100
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Apache Tomcat as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-18556 – N-Able N-Central ✓ NVD
CVSS7.4 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS<1% · P40
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for N-Able N-Central as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-68820 – Microsoft Windows Ancillary Function Driver For WinSock ✓ NVD
CVSS7 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS<1% · P26
ActionPatch immediately
AffectedTechnology Government
Remediation Steps
- Apply the vendor security update for Microsoft Windows 10 1607 as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-55040 – Microsoft Sharepoint Server ✓ NVD
CVSS9.1 NVD 3.1
Triage statusPoC Available
Exploitation🧪 PoC published ● New this week
EPSS4% · P90
ActionPatch within 48 hours
AffectedTechnology
Remediation Steps
- Apply Microsoft July 2026 Patch Tuesday update for SharePoint
- Verify deployment across all SharePoint server instances
- Monitor authentication logs for exploitation attempts
- Restrict SharePoint access to trusted networks where feasible
References:
🛡️CVE-2025-68686 – Fortinet FortiOS ✓ NVD
CVSS5.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P67
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Fortinet Fortios as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-60137 – WordPress Core ✓ NVD
CVSS5.9 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS73% · P99
ActionPatch immediately
AffectedGovernment Technology
Remediation Steps
- Apply the vendor security update for Wordpress as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC) ✓ NVD
CVSS5.3 NVD 3.1
Triage statusActive Exploit
Exploitation⚠️ In the wild 🔥 In CISA KEV ↻ Ongoing
EPSS1% · P53
ActionPatch immediately
AffectedTechnology
Remediation Steps
- Apply the vendor security update for Cisco Secure Firewall Management Center as a priority.
- Restrict network exposure of the affected service to trusted sources until patched.
- Review logs and detections for indicators of exploitation.
- Confirm fixed versions against the official vendor advisory before deploying.
References:
🛡️CVE-2026-48362 – Adobe Coldfusion ✓ NVD
CVSS10 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS2% · P80
ActionPatch within 48 hours
AffectedTechnology
Remediation Steps
- Apply Adobe security update for ColdFusion OS command injection
- Review and update ColdFusion instances to patched versions
- Audit system command execution logs for suspicious activity
- Restrict ColdFusion application permissions to minimum required
References:
🛡️CVE-2026-59310 – VMware vCenter ✓ NVD
CVSS9.8 NVD 3.1
Triage statusNo Known Exploit
ExploitationNo exploitation reported
EPSS1% · P64
ActionPatch within 48 hours
AffectedTechnology
Remediation Steps
- Apply Broadcom-released patch for vCenter directory-traversal vulnerability
- Conduct forensic review of vCenter logs for unauthorized access indicators
- Isolate and inspect vCenter instances for persistent backdoors
- Restrict network access to vCenter management interfaces to trusted admin networks
- Monitor for lateral movement from compromised vCenter hosts
References:
🤖 This vulnerability report was compiled by defend.network using AI-powered analysis of vulnerability databases, vendor advisories, and threat intelligence feeds. Always verify remediation steps through official vendor channels before implementing changes in production environments.