ctipilot.ch
← Back to Weekly 2026-W30
HIGHexploitedNATOA1vulnerability

2026-W30 vulnerability status roll-up — five CVEs crossed into confirmed exploitation/KEV, three more carry public exploit code, and a dense CVSS-9-to-10 tail hit edge, ERP, OT and file-transfer

discovered 2026-07-26 23:45 UTCrun 2026-07-26T2309Z-weekly5 sourcesmulti-source

Consolidated trajectory of the CVEs this pipeline covered operationally in ISO week 2026-W30. Per-CVE mechanics, affected/fixed versions and primary sources are in the referenced operational entries; this roll-up records only what moved this week.

Confirmed exploited / newly KEV-listed this week. ServiceNow AI Platform CVE-2026-6875 (pre-auth sandbox-escape RCE) was marked actively exploited by NCSC-CH, with activity from 2026-07-18. Microsoft SharePoint Server CVE-2026-50522 (pre-auth deserialization RCE) went to active exploitation within hours of a public PoC, with machine-key theft giving persistence that survives patching. Check Point SmartConsole CVE-2026-16232 (auth bypass to full admin) was confirmed exploited against a handful of internet-exposed management servers and added to CISA KEV on 2026-07-22 (CISA, 2026-07-22). Langflow CVE-2026-0770 (unauthenticated exec_globals RCE) was added to CISA KEV on 2026-07-21 (CISA, 2026-07-21). The WordPress core "WP2Shell" chain CVE-2026-63030 (route confusion, pre-auth) with CVE-2026-60137 (SQL injection) moved from "no confirmed exploitation" to confirmed in-the-wild abuse and KEV-listing. A correction landed the same week: Langflow's July batch is not fully fixed in 1.10.1 — the authenticated command injection CVE-2026-14499 needs 1.10.2 — so any org that upgraded only to 1.10.1 on the earlier advice remains exposed.

Public exploit code or full mechanics, no confirmed in-the-wild abuse. Windows Server AD CS "Certighost" CVE-2026-54121 (a low-privileged domain user forges a Domain Controller certificate and DCSyncs the krbtgt hash) gained a full public PoC — weaponizable now against any AD CS estate that has not applied the July 2026 cumulative update. Exodus Intelligence published a working heap-overflow-to-RCE chain for dnsmasq CVE-2026-2291, materially worse than the DoS impact the NVD score implies and broad across OpenWrt and embedded gateways. And for nginx / NGINX Plus CVE-2026-42533, the credited discoverer demonstrated a reliable pre-auth RCE, with the exploit PoC withheld for roughly 21 days — a public-exploit clock, not a current in-the-wild threat.

Critical-but-unexploited tail requiring scheduled or exposure-driven action. Oracle's July 2026 Critical Patch Update carries nine distinct CVSS-10.0 unauthenticated flaws in Fusion Middleware (including Oracle Data Integrator CVE-2026-47056 and Coherence CVE-2026-60217), with NCSC-NL assessing that large-scale abuse in the short term is very likely (NCSC-NL, 2026-07-22). SolarWinds Serv-U 2026.3 fixes a 16-CVE IDOR/broken-access-control cluster (15 rated CVSS 9.1) letting an authenticated user escalate to root on the file-transfer host. GLPI 11.0.8 / 10.0.26 fixes a form-import RCE (CVE-2026-48482) and a complete MFA bypass (CVE-2026-52848) in an ITSM platform heavily deployed across French and EU public administration. Mitel MiCollab AWV has an unauthenticated command-injection flaw (CVSS 9.8, internal id MTLVULN-1694, CVE pending). Zimbra 10.1.20 fixed an SNMP command-injection RCE plus stored-XSS bugs. The Check Point management siblings CVE-2026-62144 (CVSS 10.0 unauth RCE) and CVE-2026-62145 (Gaia root escalation) sit on the same surface as the actively-attacked auth bypass. OT protocol libraries libIEC61850/lib60870 carry an unauthenticated heap-overflow RCE (CVE-2026-49035) embedded in IEC 61850 / IEC 60870-5-104 substation and SCADA gear. And a GitLab CE/EE RCE via the Jupyter-notebook diff renderer (two ~5-year-old Oj Ruby-parser bugs) shipped a silent, un-CVE'd dependency bump in the 10 June releases, leaving feed-gated operators exposed for 44 days before the public PoC.

The webmail-espionage CVEs of the week — Zimbra CVE-2025-66376 and SOGo CVE-2026-8496 — are treated in this week's state-nexus webmail top-story rather than repeated here.

ATT&CK mapping

4 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1136Create Account

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1552.004Unsecured Credentials: Private Keys

Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and certificates are used for authentication, encryption/decryption, and digital signatures. Common key and certificate file extensions include: .key, .pgp, .gpg, .ppk., .p12, .pem, .pfx, .cer, .p7b, .asc.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.