Correction — the two Progress ShareFile Storage Zone Controller flaws in this pipeline's W29 round-up were never added to the CISA KEV catalogue, so its 'every one KEV-listed' claim was wrong when written
UPDATE · originally covered Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation (2026-07-19)
the delta is a single clause in that entry's summary, and it is one a reader could have acted on.
The entry described four classes of internet-facing enterprise software crossing into confirmed in-the-wild exploitation during ISO week 29, "every one KEV-listed". Eight of the ten identifiers involved bear that out. The SonicWall SMA1000 pair was added on 2026-07-14, Oracle E-Business Suite Payments on 2026-07-15, the AD FS and SharePoint elevation-of-privilege flaws on 2026-07-14, the wider SharePoint remote-code-execution flaw on 2026-07-16, and the two further SharePoint identifiers the entry quoted from CISA's own alert on 2026-04-14 and 2026-07-01 — all before the entry was published. The two Progress ShareFile Storage Zone Controller identifiers, CVE-2026-2699 and CVE-2026-2701, are not in the catalogue and never have been. Because CISA does not remove entries once added, their absence today is not a later withdrawal; the claim did not hold on 2026-07-19 either.
The exploitation claim underneath it is unaffected, and the distinction is the point. The original entry's own sourcing for ShareFile was Shadowserver honeypot telemetry — "first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday", the same day Progress ordered every on-premises Storage Zone Controller powered off (BankInfoSecurity, 2026-07-13). That evidence stood on its own and still does. What the round-up added, and should not have, was a second and independent-looking confirmation from a catalogue that never carried these identifiers. This pipeline's per-CVE coverage made no KEV claim about either identifier at any point — the error entered only in the weekly synthesis, where ten identifiers from four stories were summarised in one clause.
Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Sources
Update chain
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.