Threat Intelligence Report — July 27, 2026 | 7 New KEVs · 268 Victims

Report Date: 2026-07-27

New KEVs: 7  — unchanged vs last weekRansomware Victims: 268  ▲ +98 vs last week

7 vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog this period. Microsoft products show the strongest concentration of risk signals this week. Ransomware activity is moderate with 268 new victims posted to leak sites over the last 7 days, with Qilin posting the most victims.

Patch This Week

The top 3 KEVs to remediate right now, ranked by CISA deadline proximity, ransomware exploitation, and severity. These are confirmed exploited — if you do nothing else today, patch these.

  1. CVE-2026-63030 – WordPress Core | CVSS 9.8 | EPSS 98.1% / 100th pct
    CISA deadline: 2026-07-24 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  2. CVE-2026-0770 – Langflow Langflow | CVSS 9.8 | EPSS 53.5% / 99th pct
    CISA deadline: 2026-07-24 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
  3. CVE-2021-27137 – DD-WRT DD-WRT | CVSS 8.1 | EPSS 16.5% / 97th pct | PoC Available
    CISA deadline: 2026-07-24 (overdue by 3d) — Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top KEVs

Vulnerabilities confirmed actively exploited in the wild by CISA — ranked by ransomware use, then severity. Patch these before anything else.

New Today

  • CVE-2026-16812 – Arista VeloCloud Orchestrator | CVSS 10.0 (CRITICAL) | AV: Network | Ransomware Use: No
  • CVE-2025-68686 – Fortinet FortiOS | CVSS 5.9 (MEDIUM) | AV: Network | EPSS 0.5% / 38th pct | Ransomware Use: No

Still Outstanding

  • CVE-2026-50522 – Microsoft SharePoint | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 57.1% / 99th pct | Ransomware Use: No
  • CVE-2026-63030 – WordPress Core | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 98.1% / 100th pct | Ransomware Use: No
  • CVE-2026-0770 – Langflow Langflow | CVSS 9.8 (CRITICAL) | AV: Network | EPSS 53.5% / 99th pct | Ransomware Use: No
  • CVE-2026-16232 – Check Point SmartConsole | CVSS 9.1 (CRITICAL) | AV: Network | EPSS 12.7% / 96th pct | Ransomware Use: No
  • CVE-2021-27137 – DD-WRT DD-WRT | CVSS 8.1 (HIGH) | AV: Network | EPSS 16.5% / 97th pct | Ransomware Use: No | PoC Available

Security News

Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.

  • CISA ICS AdvisoryAdvisory · 4 days agoRockwell Automation ThinManager
    View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The followi…
  • CISA ICS AdvisoryAdvisory · 4 days agoWeintek cMT3092X
    View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are affected:…
  • CISA ICS AdvisoryAdvisory · 4 days agoJohnson Controls C-CURE 9000 and Victor application server
    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor applicati…
  • SANS ISCResearch · yesterdayScans for ESAFENET CDG 3 Document Management System Weak Logins, (Sun, Jul 26th)
    ESAFENET&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The "CDG" stands for "Content Data Guard", and …
  • SANS ISCResearch · 4 days agoWhen the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)
    Two disclosures, five days apart, described the same intrusion from opposite ends —
  • Unit 42Incident · 4 days agoRussian Global Webmail Espionage
    Unit 42 details a Russian cyberespionage campaign targeting Zimbra webmail servers using JavaScript injection to steal credentials. The post Russian Global Webmail Espionage appeared first on Unit 42 .
  • Unit 42Research · 10 days agoThree Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
    A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Tri…
  • Sophos X-OpsResearch · today2607-secai
    <p>What that means for Customer Protections </p> Categories: Threat Research, AI Research
  • Sophos X-OpsResearch · 6 days agoJuly Patch Tuesday only feels endless
    <p>AI deluge brings 575 CVEs, 479 advisories, reset to blog-post format</p> Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY
  • The RecordIncident · todayHealth system in South Carolina, Georgia closes offices after malware affects networks
    On Sunday, AnMed published a statement online saying they were “experiencing a cybersecurity disruption involving malware” and were working to restore systems and determine the scope of the incident.
  • The RecordNews · todayTelegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
    Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan.
  • Security Affairs (APT)Incident · yesterdayHackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
    Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hot…
  • Security Affairs (APT)Incident · 2 days agoIran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
    US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside Amer…
  • Security Affairs (Cybercrime)News · todayMedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
    MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful f…
  • Security Affairs (Cybercrime)Incident · todayDentaQuest disclosed a data breach that impacted +23 million individuals
    DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers acces…

Ransomware Activity

Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.

58 new victims posted today
7-day total: 268 via Ransomware.live

Infostealer Exposure: 17,951 employee credentials and 1,003,578 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.

Most Active Groups

Qilin 35 Thegentlemen 32 Global Secret Group 31 Crpxo 20 Section9 18

Group Intelligence

  • QilinQilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
  • ThegentlemenThe Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
  • CrpxoCRPxO is actively recruiting affiliates, offering:
    🔹 70% revenue share
    🔹 XMR/BTC payouts
    🔹 Claimed payouts within 24 hours
    🔹 $333 one-time affiliate access

Most Targeted Sectors

Technology 44 Manufacturing 36 Professional Services 34 Healthcare 28 Financial Services 23

Top Countries

US (107), DE (13), IN (12), CA (11), BR (11)

Notable Incidents

  • BH Security, LLC. (brinkshome.com) (Professional Services · US) — claimed by Shinyhunters. Over 4.9 million Salesforce records containing some PII was compromised. This is a final warning to reach out by 30 July 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the … Press coverage →
  • Thialf (Energy & Utilities · NL) — claimed by Thegentlemen. ***.nl zoominfo.com/c/thialf/430686423 Thialf is a world-renowned ice arena located in Heerenveen, Netherlands, often referred to as the "Cathedral of Speed Skating." It serves as the home base for the Dutch national spe… Press coverage →
  • Plitvička Jezera Nacionalni Park (Hospitality · HR) — claimed by Qilin. N/A Press coverage →
  • Stryker (Healthcare · US) — claimed by Qilin. N/A Press coverage →

Vendor-Specific Risks

Vendors with confirmed KEV exploitation this week — the stacked bar shows how that exposure breaks down across exploited CVEs (red), critical CVEs to watch (orange), and news mentions (yellow). Prioritize patching vendors with the largest red segment.

Microsoft 3 Arista 1 Fortinet 1 Check Point 1 WordPress 1 KEVs CVEs Mentions

Stay Ahead

Found this useful? Get the daily report in your reader.

Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.