Date Posted: 2026/07/24 \

【Vulnerability Alert】CISA Adds 10 Known Exploited Vulnerabilities to KEV Catalog (2026/07/13-2026/07/19)

  • Subject: 【Vulnerability Alert】CISA Adds 10 Known Exploited Vulnerabilities to KEV Catalog (2026/07/13-2026/07/19)

\

  • Description:
    • Forwarded Cybersecurity Alert from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202607-00000011
    • 【CVE-2008-4128】Cisco IOS Cross-Site Request Forgery Vulnerability (CVSS v3.1: 4.3)
    • 【Known Ransomware Use: Unknown】 Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 used by Cisco 871 Integrated Services Router allow remote attackers to execute arbitrary commands on the affected device by enticing users to send crafted requests.
    • 【CVE-2026-56155】Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (CVSS v3.1: 7.8)
    • 【Known Ransomware Use: Unknown】 Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to escalate privileges locally.
    • 【CVE-2026-56164】Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 5.3)
    • 【Known Ransomware Use: Unknown】 Microsoft SharePoint Server contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to escalate privileges over a network.
    • 【CVE-2026-15409】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
    • 【Known Ransomware Use: Unknown】 SonicWall SMA1000 Appliances contain a server-side request forgery (SSRF) vulnerability that could allow an unauthenticated remote attacker to cause the appliance to send requests to an unintended destination.
    • 【CVE-2026-15410】SonicWall SMA1000 Appliances Code Injection Vulnerability (CVSS v3.1: 7.2)
    • 【Known Ransomware Use: Unknown】 SonicWall SMA1000 Appliances contain a code injection vulnerability that, under specific conditions, could allow an authenticated remote attacker with administrator privileges to execute arbitrary operating system commands.
    • 【CVE-2026-46817】Oracle E-Business Suite Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
    • 【Known Ransomware Use: Unknown】 Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful exploitation may result in the takeover of Oracle Payments.
    • 【CVE-2023-4346】KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (CVSS v3.1: 7.5)
    • 【Known Ransomware Use: Unknown】 KNX Association KNX Protocol Connection Authorization Option 1 contains an improper account lockout mechanism vulnerability that could allow an attacker to erase all devices without additional security options enabled and set a BCU key to lock the devices.
    • 【CVE-2026-58644】Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
    • 【Known Ransomware Use: Unknown】 Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.
    • 【CVE-2026-25089】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
    • 【Known Ransomware Use: Unknown】 An OS command injection vulnerability in the Web UI of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS may allow an unauthenticated attacker to execute unauthorized commands via specially crafted HTTP requests.
    • 【CVE-2026-39808】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
    • 【Known Ransomware Use: Unknown】 An OS command injection vulnerability in the API endpoint of Fortinet FortiSandbox may allow an unauthenticated attacker to execute unauthorized code or commands via specially crafted HTTP requests.
  • Affected Platforms:
  • Recommendation:

Computer and Communication Center \ Network System Division