2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks
Items already in motion at the close of 2026-W31, each with a source and a date. None of these is a prediction.
A firmware release with a committed deadline — 12 August. CERT@VDE's advisory covering 20 vulnerabilities in Phoenix Contact CHARX SEC-3xxx EV charging controllers, five of them CVSS 9.8 with an unauthenticated network vector, published without the fix: "the updated firmware will be made available as soon as possible, but no later than August 12, 2026." (CERT@VDE, 2026-07-30). Until then the vendor's only offered control is closed-network operation behind a firewall — and one of the flaws makes the on-device firewall unavailable for a window during every shutdown. The date is checkable and worth checking.
Permanent WebSphere fix packs not expected before 3Q2026. IBM has no workaround for the CVSS 9.8 missing-authentication flaw in the WebSphere Application Server traditional administrative console, and targets the permanent Fix Packs 9.0.5.29 and 8.5.5.31 for 3Q2026, leaving the interim fix under APAR DT496500 as the only remediation now (IBM PSIRT, 2026-07-28); a companion bulletin the same day carries the deserialization flaw and APAR PH72166 (IBM PSIRT, 2026-07-28). Estates that defer interim fixes on principle are deferring past a quarter boundary.
An extortion campaign between exfiltration and publication. Cl0p-affiliated actors have been sending staff-wide emails naming PTC Windchill as the breach vector, but as of the last reported observation the second shoe had not dropped: "as of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign." (Ransom-ISAC, 2026-07-22). Any organisation that ran an internet-exposed, unpatched Windchill or FlexPLM instance in June sits inside that gap, and the campaign's own precedent is that listings follow.
Three flaws with no fix, and one of them exploited. Langflow's pre-authentication eval injection is being exploited with no documented fixed version, and ZDI's only stated mitigation is to restrict interaction with the product (Zero Day Initiative, 2026-01-09). fastjson 1.x will not receive one: "FastJson 1.x is no longer actively maintained, and no patched 1.x version has been released for this vulnerability." (Imperva, 2026-07-24). And Siemens records the entire Desigo CC V7 family under remediation category none_available, with network segmentation as the only offered control (Siemens ProductCERT, 2026-07-14). These three leave the vulnerability queue by being made unreachable or not at all.
An embargo that has already broken. The Rails security team abandoned its plan to withhold the CVE-2026-66066 Active Storage exploitation details until 2026-08-28, publishing the attack write-up four weeks early along with a forensic-evidence guide and tooling to determine whether an application was vulnerable and whether it was exploited (Ruby on Rails security team, 2026-07-31). The window in which the chain was private is closed; what remains in motion is the population of unpatched applications, and the published forensic check is how an operator establishes which side of it they are on.
The CRA reporting clock, at six weeks. "Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026." (Hunton Andrews Kurth, 2026-07-29). From that date the regulation's reporting obligations bind manufacturers of products with digital elements — which for this constituency is a change in what EU-market suppliers owe their customers, arriving more than a year before the rest of the regulation applies. The notification window and article number are deliberately not stated here: no source fetched this run carries them.
The updated firmware will be made available as soon as possible, but no later than August 12, 2026.
As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.
Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.