What to patch now — 3 August 2026
Source: CISA Known Exploited Vulnerabilities (KEV) catalog — the most recently added entries as of today. Every vulnerability below has been confirmed by CISA as actively exploited in the wild, meaning attackers are already using it, not just researching it. If you (or a supplier) run any of this software, treat it as urgent.
1. Cisco Secure Firewall Management Center — a built-in password lets anyone log in (CVE-2026-20316)
🛠️ Cisco Secure Firewall Management Center (FMC) · added 29 Jul 2026 · CISA fix-by date 1 Aug 2026 (already passed)
What it is: "Use of a hard-coded password" means the software ships with a built-in login that's the same on every installation and can't be changed by the customer. Here, that fixed credential lets anyone on the internet log in to FMC — the console businesses and IT providers use to manage their Cisco firewalls — using a low-privileged account, and from there reach sensitive configuration data on the box.
Who's affected: Any business, or the IT/security provider that manages their network, running Cisco Secure FMC (formerly Firepower Management Center) to administer their firewalls.
What to do: Apply Cisco's fix now — CISA's federal deadline was only 3 days after the flaw was added, and it's already gone. If a provider manages your Cisco firewalls, ask them today whether the management console itself (not just the firewalls it controls) has been patched.
2. Fortinet FortiOS — a way back in even after you've been patched (CVE-2025-68686)
🛠️ Fortinet FortiOS · added 27 Jul 2026 · CISA fix-by date 10 Aug 2026
What it is: This one only matters if an attacker already got a foothold on your FortiGate device through a separate, earlier flaw. Fortinet had previously shipped a fix designed to remove a "symbolic link" trick attackers used to quietly keep read access to the file system even after being cleaned up. This new flaw is a way to sidestep that fix — using ordinary-looking web requests — and re-establish that same persistence.
Who's affected: Businesses running Fortinet FortiGate firewalls (FortiOS), particularly anyone whose device was ever flagged in the earlier "symlink" incident reported through 2024–2025.
What to do: Apply Fortinet's update. If your FortiGate was ever named in that earlier incident or you're not sure, this is a good reason to have your IT provider check the device for signs of lingering access rather than assuming the original clean-up was final.
3. Arista VeloCloud Orchestrator — one flaw takes over the box managing your whole SD-WAN (CVE-2026-16812)
🛠️ Arista VeloCloud Orchestrator (on-prem) · added 27 Jul 2026 · CISA fix-by date 30 Jul 2026 (already passed)
What it is: "OS command injection" means an attacker can smuggle their own operating-system-level commands into a request the software processes, so the server ends up running commands it was never meant to accept from an outsider. Here it hits the Orchestrator — the central control point for a VeloCloud SD-WAN — giving an attacker privileged access to the box that manages the network links between a business's sites.
Who's affected: Businesses (typically multi-site or franchise operations) running their own on-prem VeloCloud Orchestrator to connect offices or shops together, rather than a version fully hosted by Arista.
What to do: Apply Arista's fix immediately — CISA gave this just 3 days, another sign of severity. If a network provider set up your SD-WAN, ask them directly whether the on-prem orchestrator (not the individual site devices) has been patched.
4. Check Point SmartConsole — attackers get full admin login tokens with no password (CVE-2026-16232)
🛠️ Check Point SmartConsole · added 22 Jul 2026 · CISA fix-by date 25 Jul 2026 (already passed)
What it is: "Improper authentication" means the system doesn't correctly verify who's asking before handing something sensitive over. Here, SmartConsole — the console admins use to configure Check Point security devices — can be tricked into handing out valid login tokens to an attacker who never logged in, and those tokens carry full administrator rights.
Who's affected: Businesses (or their IT/security provider) that manage Check Point firewalls or other security appliances through SmartConsole — the very tool meant to configure and protect the network perimeter.
What to do: If this hasn't been applied yet, treat it as overdue — CISA's window was only 3 days. Ask whoever manages your Check Point kit to confirm today; a compromised management console can mean a compromised firewall.
5. Microsoft SharePoint — a third confirmed flaw in this run (CVE-2026-50522)
🛠️ Microsoft SharePoint · added 22 Jul 2026 · CISA fix-by date 25 Jul 2026 (already passed)
What it is: "Deserialization of untrusted data" means the software unpacks incoming data as if it were safe, structured content, but a crafted package can make it run as code instead — handing an attacker the ability to execute their own commands on the server. This is a distinct bug from the SharePoint flaw further down this list; fixing one does not cover the other.
Who's affected: Businesses running an on-premises SharePoint Server. Cloud "SharePoint Online" inside Microsoft 365 is patched centrally by Microsoft and isn't affected.
What to do: If your organisation runs SharePoint on its own server, confirm with whoever manages it that every SharePoint security update released this year has been applied — not just the most recent one, given how many separate fixes have landed in a short space of time.
6–7. WordPress Core — two flaws that chain into a takeover with no login needed (CVE-2026-60137, CVE-2026-63030)
🛠️ WordPress Core · added 21 Jul 2026 · CISA fix-by dates 4 Aug / 24 Jul 2026
What it is: "SQL injection" means an attacker sneaks database commands into a form field or web-address parameter the site wasn't expecting, tricking the database into running them. The second flaw, an "interpretation conflict," is a separate quirk that lets that injected command be read differently by WordPress than intended — and CISA confirms the two can be chained together into full remote code execution, without ever logging in.
Who's affected: Any business running a self-hosted WordPress website — a huge share of small-business sites, whether it's the main site, a blog, or a customer-facing shop.
What to do: Update to WordPress 7.0.2 or later now — this patches both flaws. If a web designer or agency manages your site, confirm the update is live; many hosts apply WordPress core updates automatically, but it's worth checking rather than assuming.
8. Langflow — a flaw in a popular AI workflow-builder lets outsiders run their own code (CVE-2026-0770)
🛠️ Langflow · added 21 Jul 2026 · CISA fix-by date 24 Jul 2026 (already passed)
What it is: "Inclusion of functionality from an untrusted control sphere" is the formal way of saying the software will load and run functionality handed to it from a source it shouldn't trust — in effect, letting an outsider supply code that then executes as if it were part of the trusted application.
Who's affected: Businesses that have set up their own Langflow instance to build internal AI chatbots or automation workflows — increasingly common as small businesses experiment with in-house AI tools, usually self-hosted on a cloud server by a developer or technical staff member rather than rolled out by a formal IT department.
What to do: Update to Langflow 1.9.0 or later. If someone on your team, or a contractor, set up an AI tool using Langflow, check with them directly — this is exactly the kind of fast-moving, developer-installed tool that doesn't get automatic updates the way mainstream business software does.
9. DD-WRT router firmware — a 15-year-old bug just confirmed under attack (CVE-2021-27137)
🛠️ DD-WRT · added 21 Jul 2026 · CISA fix-by date 24 Jul 2026 (already passed)
What it is: A "stack-based buffer overflow" happens when a program tries to cram more data into a fixed-size piece of memory than it was built to hold, spilling into space it doesn't own — which an attacker can exploit to make the device run their own code instead of its own. This one sits in UPnP, the feature that lets devices on a network automatically open ports for themselves (used by some game consoles, smart-home gear, and video-calling apps).
Who's affected: Businesses or tech-savvy owners running DD-WRT, a free, open-source alternative firmware some people install on their own router in place of the manufacturer's software — more common on older or budget hardware repurposed to add features it didn't originally have.
What to do: Update to a DD-WRT build that includes this fix. If you're not sure whether your router runs DD-WRT, check its admin page (often at an address like 192.168.1.1) for the firmware name. As an immediate mitigation either way, turning off UPnP in your router settings closes this specific door — most small businesses don't need it switched on.
10. Microsoft SharePoint — the flaw that started the run (CVE-2026-58644)
🛠️ Microsoft SharePoint · added 16 Jul 2026 · CISA fix-by date 19 Jul 2026 (already passed)
What it is: The same "deserialization" flaw type as entry #5 above — SharePoint unpacks crafted data as if it were legitimate content, but it's actually instructions, which then run as code on the server. This is the earliest of the confirmed SharePoint flaws in this stretch; it's a separate bug from #5, so patching one does not cover the other.
Who's affected: Businesses running an on-premises SharePoint Server, the same audience as entry #5.
What to do: As above — confirm with whoever manages your SharePoint server that this specific update, and every SharePoint fix since, has actually been applied, not assumed.
11–12. Fortinet FortiSandbox — two flaws let an outsider run commands with no login (CVE-2026-25089, CVE-2026-39808)
🛠️ Fortinet FortiSandbox · added 16 Jul 2026 · CISA fix-by date 19 Jul 2026 (already passed)
What it is: Two separate "OS command injection" flaws — an attacker sends a crafted web request that gets treated as an operating-system command instead of ordinary data, letting them run their own commands on the device with no login required. FortiSandbox is the appliance some businesses use to detonate and analyse suspicious files before they reach staff inboxes.
Who's affected: Businesses running FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS as part of their email/file security setup — usually set up by an IT provider rather than run day-to-day by the business itself.
What to do: Ask your IT provider or managed security service whether FortiSandbox is in use and, if so, whether both fixes have been applied — they're two distinct bugs in the same product, so one patch alone isn't enough.
This is an awareness summary of public CISA KEV data, not professional security advice. CISA "fix-by" dates are US federal deadlines; for everyone else they're a strong urgency signal, not a legal obligation. Always confirm the affected versions and the fix against the vendor's own advisory.