⏳ ACTIVE EXPLOITS · JULY 2026
Wild exploits & mitigation
Critical vulnerabilities in SD‑WAN, AD CS, AI platforms, and more — active attacks in the wild.
📅 Published 30 July 2026
🧩 CISA KEV 7 new additions
⚡ CVSS avg 9.4
🛡️ patches available for all
🖥️ New attack methods
LegacyHive
Windows privilege escalation via registry hive redirection. Bypasses memory protections on fully patched systems.
low-level creds required
TA488 · “Half‑Click”
Outlook Web Access XSS (CVE‑2026‑42897). Opening a malicious email triggers compromise without further interaction.
OWAReaper implant
AI‑assisted zero‑day
AI system found Linux kernel use‑after‑free (CVE‑2026‑53264) days after human discovery — accelerating 0‑day hunting.
AI vs n‑day
🛡️ Mitigation priorities
- 1 Patch Arista VeloCloud, ServiceNow, Citrix, FortiSandbox immediately all have vendor fixes
- 2 Harden SharePoint on‑prem and review AD CS certificate templates CISA guidance
- 3 Treat SaaS platforms (ServiceNow, OWA) as internal attack surface sandbox escape
- 4 Enable email security and restrict OWA until patch for CVE‑2026‑42897 half‑click
📌 references
CISA KEV
cisa.gov/known-exploited-vulnerabilities
NIST NVD
nvd.nist.gov/vuln
vendor bulletins
Arista / Fortinet / Cisco / Microsoft
AI threat brief
CVE‑2026‑53264 · autonomous agents
⏱️ threat intelligence · 30 July 2026 | all CVEs active in the wild