2026-07-19 · view entry permalink →
2026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT
This roll-up tracks the week's CVEs by exploitation trajectory, not severity score. Per-CVE mechanics, affected/fixed versions and evidence are in the referenced operational entries.
Confirmed exploited / newly KEV-listed this week. Four Microsoft on-prem items moved: AD FS CVE-2026-56155 and SharePoint CVE-2026-56164 shipped 2026-07-14 as exploited zero-days KEV-listed the same day, and CVE-2026-58644 — a July SharePoint RCE first rated only "Exploitation More Likely" — was confirmed exploited and KEV-added on 2026-07-16, with CISA naming it in a cluster it is "aware of active exploitation" of (CISA, 2026-07-16). SonicWall SMA1000 CVE-2026-15409/-15410 (KEV 2026-07-14) and Oracle EBS Payments CVE-2026-46817 (KEV 2026-07-15, CISA) both carried confirmed in-the-wild exploitation, as did ShareFile SZC CVE-2026-2699. Two older CVEs joined KEV as actively exploited: Cisco Smart Install CVE-2018-0171 (the FSB Centre 16 router vector) and — notably for OT — KNX Connection Authorization CVE-2023-4346, a three-year-old account-lockout flaw whose fix is procedural, not a patch.
Public exploit code, no confirmed in-the-wild abuse (short fuse). WordPress core's "WP2Shell" chain (CVE-2026-63030 route-confusion in the unauthenticated REST batch endpoint + CVE-2026-60137 WP_Query SQL injection) reaches pre-auth RCE on a stock install; public PoC is already on GitHub and NCSC-NL assesses short-term exploitation is expected. Firefox 152.0.6 fixed a WebAssembly memory bug (CVE-2026-15718) and a site-isolation bypass (CVE-2026-15719) with public exploit code, though Mozilla states no in-the-wild abuse — contrary to some aggregator "zero-day" framing.
Critical-but-unexploited tail (scheduled, exposure-driven action). No confirmed exploitation yet, but each is a pre-auth or high-impact flaw on exposed or CI-relevant software: SAP's July set (CVE-2026-44747 NetWeaver kernel, CVE-2026-27690 Approuter request-smuggling, CVE-2026-44761 Commerce Cloud hardcoded credential — the last a config exposure a patch alone does not close); VMware Avi Load Balancer control-plane auth bypass CVE-2026-47865 (reported by NATO NCSC, no workaround); Siemens RUGGEDCOM ROX II's three-CVE chain to persistent root (CVE-2025-40947/40948/40949); Rockwell 1715-AENTR CVE-2026-10577 (CVSS 10.0 unauthenticated debug-port takeover) and the ABB T-MAC chain; Abacus ERP's unauthenticated RCE (CVSS 9.8, no CVE, NCSC-CH-flagged, ubiquitous in Switzerland); and Moodle's local_o365 JWT-signature-non-verification takeover CVE-2026-54733 across the European public-sector LMS estate.
Builds on: 2026-07-18/sonicwall-sma1000-uta0533-exploitation-kill-chain · 2026-07-14/progress-sharefile-szc-active-exploitation-confirmed · 2026-07-16/cve-2026-46817-oracle-ebs-payments-preauth-rce-kev-listed · 2026-07-17/cve-2026-58644-sharepoint-confirmed-exploited-kev · 2026-07-14/microsoft-july-2026-patch-tuesday-two-exploited-zero-days · 2026-07-15/microsoft-july-patch-tuesday-sharepoint-dynamics-followup · 2026-07-13/fsb-centre-16-static-tundra-router-hijacking-advisory · 2026-07-16/cve-2023-4346-knx-building-automation-lockout-dos-kev · 2026-07-18/wordpress-core-wp2shell-preauth-rce-chain-cve-2026-63030 · 2026-07-17/firefox-152-0-6-wasm-site-isolation-public-exploit · 2026-07-14/sap-july-2026-patch-day-netweaver-approuter-commerce-cloud · 2026-07-18/vmware-avi-load-balancer-cve-2026-47865-auth-bypass · 2026-07-18/siemens-ruggedcom-rox-ii-unit42-three-cve-chain · 2026-07-15/cisa-ics-batch-rockwell-abb-energy-water-ot · 2026-07-17/abacus-erp-unauth-rce-path-traversal-ncsc-ch · 2026-07-18/moodle-local-o365-jwt-forgery-admin-takeover-cve-2026-54733