2026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT
This roll-up tracks the week's CVEs by exploitation trajectory, not severity score. Per-CVE mechanics, affected/fixed versions and evidence are in the referenced operational entries.
Confirmed exploited / newly KEV-listed this week. Four Microsoft on-prem items moved: AD FS CVE-2026-56155 and SharePoint CVE-2026-56164 shipped 2026-07-14 as exploited zero-days KEV-listed the same day, and CVE-2026-58644 — a July SharePoint RCE first rated only "Exploitation More Likely" — was confirmed exploited and KEV-added on 2026-07-16, with CISA naming it in a cluster it is "aware of active exploitation" of (CISA, 2026-07-16). SonicWall SMA1000 CVE-2026-15409/-15410 (KEV 2026-07-14) and Oracle EBS Payments CVE-2026-46817 (KEV 2026-07-15, CISA) both carried confirmed in-the-wild exploitation, as did ShareFile SZC CVE-2026-2699. Two older CVEs joined KEV as actively exploited: Cisco Smart Install CVE-2018-0171 (the FSB Centre 16 router vector) and — notably for OT — KNX Connection Authorization CVE-2023-4346, a three-year-old account-lockout flaw whose fix is procedural, not a patch.
Public exploit code, no confirmed in-the-wild abuse (short fuse). WordPress core's "WP2Shell" chain (CVE-2026-63030 route-confusion in the unauthenticated REST batch endpoint + CVE-2026-60137 WP_Query SQL injection) reaches pre-auth RCE on a stock install; public PoC is already on GitHub and NCSC-NL assesses short-term exploitation is expected. Firefox 152.0.6 fixed a WebAssembly memory bug (CVE-2026-15718) and a site-isolation bypass (CVE-2026-15719) with public exploit code, though Mozilla states no in-the-wild abuse — contrary to some aggregator "zero-day" framing.
Critical-but-unexploited tail (scheduled, exposure-driven action). No confirmed exploitation yet, but each is a pre-auth or high-impact flaw on exposed or CI-relevant software: SAP's July set (CVE-2026-44747 NetWeaver kernel, CVE-2026-27690 Approuter request-smuggling, CVE-2026-44761 Commerce Cloud hardcoded credential — the last a config exposure a patch alone does not close); VMware Avi Load Balancer control-plane auth bypass CVE-2026-47865 (reported by NATO NCSC, no workaround); Siemens RUGGEDCOM ROX II's three-CVE chain to persistent root (CVE-2025-40947/40948/40949); Rockwell 1715-AENTR CVE-2026-10577 (CVSS 10.0 unauthenticated debug-port takeover) and the ABB T-MAC chain; Abacus ERP's unauthenticated RCE (CVSS 9.8, no CVE, NCSC-CH-flagged, ubiquitous in Switzerland); and Moodle's local_o365 JWT-signature-non-verification takeover CVE-2026-54733 across the European public-sector LMS estate.
ATT&CK mapping
3 techniques mapped from the cited reporting · MITRE ATT&CK v19.1
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Persistence TA0003
T1505.003Server Software Component: Web Shell
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.