grc-scanSecurity & governance
Patch tracker20 July 2026Archived edition

What to patch now

This edition was published on 20 July 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest briefing for the current picture.

The takeaway

Look at what's on this fortnight's list: two separate SharePoint bugs, two Fortinet appliance bugs, two SonicWall VPN gateway bugs — every one of them lives on a box built specifically to sit at the edge of a network, facing the internet, brokering access into everything behind it (your documents, your remote-access connection, your inbound file scanning). That's not a coincidence — attackers focus disproportionately on exactly this kind of "front door" equipment, because breaking one gets them past everything else in a single step, and because these boxes are often set up once by an installer or IT provider and then left alone for years. The 17-year-old Cisco router bug on this list makes the same point from the other direction: age alone doesn't make equipment safer, it just makes it more likely nobody's watching it anymore. If you don't know exactly which internet-facing boxes your business — or the IT provider you pay — has running (VPN gateway, mail/file scanner, document server, even the building's smart controls), that's the gap worth closing first, because you can't patch, replace, or even ask about something you don't know is there.

What to patch now — 20 July 2026

Source: CISA Known Exploited Vulnerabilities (KEV) catalog — the most recently added entries as of today. Every vulnerability below has been confirmed by CISA as actively exploited in the wild, meaning attackers are already using it, not just researching it. If you (or a supplier) run any of this software, treat it as urgent.


1. Microsoft SharePoint — malicious data unpacks into an attacker's code (CVE-2026-58644)

🛠️ Microsoft SharePoint · added 16 Jul 2026 · CISA fix-by date 19 Jul 2026

What it is: "Deserialization" is the jargon — it's how a program unpacks data it receives back into something it can use. Here, SharePoint can be tricked into unpacking crafted data that isn't really data at all, but instructions, which then run as code on the server.

Who's affected: Businesses running an on-premises SharePoint Server to store or share documents. (Cloud "SharePoint Online" inside Microsoft 365 is patched centrally by Microsoft and isn't affected.)

What to do: Apply Microsoft's update immediately. If you're not sure whether you run SharePoint on your own server or in the cloud, ask whoever manages it.


2–3. Fortinet FortiSandbox — two flaws let an outsider run commands with no login (CVE-2026-25089, CVE-2026-39808)

🛠️ Fortinet FortiSandbox · added 16 Jul 2026 · CISA fix-by date 19 Jul 2026

What it is: "OS command injection" means an attacker slips operating-system commands into a request the device expects to be harmless data, and the device runs them as if it had typed them itself. CISA added two separate command-injection bugs in FortiSandbox in the same week, both exploitable over the network with no password.

Who's affected: Businesses (or their outsourced IT/security provider) running a FortiSandbox appliance — a box that automatically opens suspicious email attachments and files in an isolated area to check if they're malware. More common at mid-sized firms and managed-service providers than a single-owner shop, but if your IT provider uses one to protect your inbox, it protects you too.

What to do: Apply Fortinet's fix for both CVEs now. If a managed-security provider runs FortiSandbox on your behalf, ask them directly to confirm it's patched.


4. Oracle E-Business Suite — a payments flaw needs no login (CVE-2026-46817)

🛠️ Oracle E-Business Suite · added 15 Jul 2026 · CISA fix-by date 18 Jul 2026

What it is: "Improper privilege management" means the system doesn't properly check what someone is allowed to do before letting them do it. Here, an attacker on the network — no account needed — can use that gap to compromise the Oracle Payments module.

Who's affected: Businesses running Oracle E-Business Suite as their finance/ERP system, particularly if the Payments module handles invoicing, supplier payments, or payroll-adjacent finance data.

What to do: Apply Oracle's Critical Patch Update now. If an accountant, bookkeeper, or IT provider manages your Oracle EBS instance, get written confirmation it's patched — this touches how money moves.


5. KNX building-automation devices — attackers can lock you out of your own lighting and heating controls (CVE-2023-4346)

🛠️ KNX Protocol devices · added 15 Jul 2026 · CISA fix-by date 29 Jul 2026

What it is: KNX is a wiring standard used to network lighting, heating/cooling, blinds, and access controls in a building. This flaw lets an attacker purge (wipe) devices or lock the security keys protecting them — without needing any extra security option turned on — cutting the legitimate owner out of their own system.

Who's affected: Offices, shops, cafés, or hotels fitted with KNX-based smart-building controls, usually installed by a specialist electrician or building-automation contractor rather than the business itself.

What to do: This is an older flaw (from 2023) only just confirmed as actively exploited, so ask whoever installed your building-automation system whether a fix or configuration change is available. The near-term risk here is being locked out of your own lighting/heating controls, not a data breach — still disruptive enough to be worth chasing.


6. Microsoft ADFS — a logged-in user can grant themselves more access (CVE-2026-56155)

🛠️ Microsoft Active Directory Federation Services · added 14 Jul 2026 · CISA fix-by date 28 Jul 2026

What it is: Active Directory Federation Services (ADFS) is what lets one company login work across several connected systems — a form of single sign-on. "Insufficient granularity of access control" means the permission checks aren't fine-grained enough, so someone who already has a valid account can exploit that to gain higher privileges than they were given.

Who's affected: Businesses using ADFS to let staff sign into cloud apps or partner portals with one company login — common where a firm manages its own on-premises Active Directory rather than relying purely on cloud sign-in.

What to do: Apply Microsoft's fix. Because this needs an existing account to exploit, it's also worth reviewing who has accounts on your ADFS server and removing any that shouldn't be there.


7. Microsoft SharePoint Server — a second flaw skips the login check entirely (CVE-2026-56164)

🛠️ Microsoft SharePoint Server · added 14 Jul 2026 · CISA fix-by date 17 Jul 2026

What it is: "Missing authentication for a critical function" means a part of SharePoint that should check who you are — before letting you do something sensitive — doesn't check at all. An outsider can use it to gain elevated access over the network.

Who's affected: The same audience as the deserialization flaw above — businesses running SharePoint Server on their own infrastructure. Two separate, serious SharePoint bugs landing in the same week is a signal to prioritise this platform if you run it.

What to do: Apply Microsoft's update for this CVE as well — it's a different bug from the one above, so patching one does not cover the other.


8–9. SonicWall SMA1000 remote-access gateways — two flaws, one needs no login (CVE-2026-15409, CVE-2026-15410)

🛠️ SonicWall SMA1000 · added 14 Jul 2026 · CISA fix-by date 17 Jul 2026

What it is: The SMA1000 is a gateway many businesses use to let staff connect securely to office systems from home or on the road. One flaw ("server-side request forgery") lets an outsider with no account trick the gateway into making requests on the attacker's behalf; the other lets someone who already has an admin login run their own commands on the underlying operating system.

Who's affected: Small businesses using SonicWall SMA1000 appliances for staff remote access — common wherever a company supports remote or hybrid work through a dedicated gateway rather than a cloud VPN service.

What to do: Apply SonicWall's fix for both — treat the no-login one as the more urgent of the two. If an IT provider manages your SonicWall gateway, ask them to confirm both are patched.


10. Cisco IOS routers — a 17-year-old bug is suddenly being exploited (CVE-2008-4128)

🛠️ Cisco IOS · added 13 Jul 2026 · CISA fix-by date 16 Jul 2026

What it is: "Cross-site request forgery" tricks someone already logged into the router's admin page — often sitting open in another browser tab — into unknowingly submitting a command on an attacker's behalf, like clicking a bad link that quietly reconfigures the router. This bug was documented back in 2008; CISA is only now confirming it's being actively exploited.

Who's affected: Businesses still running very old Cisco routers on IOS 12.4 — hardware Cisco itself now lists as obsolete, often left running for years because "it still works."

What to do: There's no new patch coming — Cisco has marked this software obsolete, so replacing the router is the real fix. In the meantime, don't leave the router's admin page open in a browser tab while browsing elsewhere, and restrict who and what can reach that admin page at all.


This is an awareness summary of public CISA KEV data, not professional security advice. CISA "fix-by" dates are US federal deadlines; for everyone else they're a strong urgency signal, not a legal obligation. Always confirm the affected versions and the fix against the vendor's own advisory.

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Compiled from CISA's public Known Exploited Vulnerabilities catalog. This briefing is for awareness purposes only and does not constitute professional security advice; always confirm affected versions and the fix against the vendor's own advisory.