Major Exploits

Author: JJustis | Published: 2026-07-30 23:19:24
⏳ ACTIVE EXPLOITS · JULY 2026

Wild exploits & mitigation

Critical vulnerabilities in SD‑WAN, AD CS, AI platforms, and more — active attacks in the wild.
📅 Published 30 July 2026 🧩 CISA KEV 7 new additions ⚡ CVSS avg 9.4 🛡️ patches available for all
Exploit / CVE Affected Severity Impact
CVE‑2026‑16812 Arista VeloCloud SD‑WAN Orchestrator CVSS 10.0 unauthenticated OS command injection → full infrastructure compromise CISA KEV
CVE‑2026‑54121 Certighost AD CS (Active Directory) Critical any domain user → impersonate Domain Controller, full AD takeover
CVE‑2026‑6875 ServiceNow AI ServiceNow instances CVSS 9.5 pre‑auth sandbox escape RCE, actively exploited with alternative gadget chain
CVE‑2026‑8451 Citrix NetScaler ADC & Gateway CVSS 8.8 memory over‑read → leaks session tokens, credentials via SAML exploited in 48h
CVE‑2026‑25089 / 39808 FortiSandbox FortiSandbox appliances CVSS 9.8 unauthenticated OS command injection via crafted HTTP requests; exploitation seen within 24h
CVE‑2026‑58644 SharePoint SharePoint Server (on‑prem) CVSS 9.8 deserialization RCE; actively exploited, patched July 2026 CISA KEV
CVE‑2026‑20230 Cisco CUCM Unified Communications Manager Critical unauthenticated RCE → root access, full voice/PSTN takeover CISA KEV
🖥️ New attack methods
LegacyHive
Windows privilege escalation via registry hive redirection. Bypasses memory protections on fully patched systems.
low-level creds required
TA488 · “Half‑Click”
Outlook Web Access XSS (CVE‑2026‑42897). Opening a malicious email triggers compromise without further interaction.
OWAReaper implant
AI‑assisted zero‑day
AI system found Linux kernel use‑after‑free (CVE‑2026‑53264) days after human discovery — accelerating 0‑day hunting.
AI vs n‑day
🛡️ Mitigation priorities
  • 1 Patch Arista VeloCloud, ServiceNow, Citrix, FortiSandbox immediately all have vendor fixes
  • 2 Harden SharePoint on‑prem and review AD CS certificate templates CISA guidance
  • 3 Treat SaaS platforms (ServiceNow, OWA) as internal attack surface sandbox escape
  • 4 Enable email security and restrict OWA until patch for CVE‑2026‑42897 half‑click
📌 references
CISA KEV cisa.gov/known-exploited-vulnerabilities
NIST NVD nvd.nist.gov/vuln
vendor bulletins Arista / Fortinet / Cisco / Microsoft
AI threat brief CVE‑2026‑53264 · autonomous agents
⏱️ threat intelligence · 30 July 2026  |  all CVEs active in the wild