Protecting 75,000+ users across Europe
Learn more →
Protecting 75,000+ users across Europe
Learn more →
Close icon to dismiss modals, popups and notifications
← back to regulation postsJuly - Top 5 vulnerabilities
Threat Intelligence
September 5, 2026

July - Top 5 vulnerabilities

Vulnerability Intelligence

The CISA Known Exploited Vulnerabilities (KEV) catalog added 26 new entries in July 2026, up from 22 in June, a continued acceleration in how quickly adversaries weaponize newly disclosed flaws. Several of this month's additions were only fully exploitable once chained with a second CVE, a pattern that is becoming the rule rather than the exception.

Below, we detail the top 5 critical vulnerabilities that demand immediate patching priority in July, ranked by CVSS severity and EPSS (Exploit Prediction Scoring System) probability of near-term exploitation.

1. WordPress Core

CVE:  CVE-2026-63030 | Severity: Critical | EPSS: 97.3% | Exploitation Status: Actively exploited, chained with CVE-2026-60137 for full RCE

WordPress Core 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch-endpoint route-confusion flaw that, combined with the SQL injection covered in CVE-2026-60137 (also in this month's top 5, below), lets an unauthenticated attacker escalate from SQL injection to full remote code execution on default installations.

WordPress powers a significant share of client-facing web properties across Switzerland and the EU. With an EPSS score above 97%, this pairing is effectively guaranteed to see continued mass exploitation: unpatched WordPress cores below 6.9.5 / 7.0.2 should be treated as an active incident, not a maintenance backlog item.

2. Fortinet FortiSandbox

CVE:  CVE-2026-39808 | Severity: Critical | EPSS: 92.8% | Exploitation Status: Actively exploited

FortiSandbox appliances and the FortiSandbox PaaS service (versions 4.4.0 through 4.4.8) are exposed to an OS command injection vulnerability that lets an unauthenticated attacker execute arbitrary commands via a crafted HTTP request.

Sandboxing appliances typically sit deep inside the malware-analysis pipeline, with access to quarantined samples and internal network segments; a compromise here can hand an attacker a foothold that bypasses the very detection layer meant to stop them. This is Fortinet's second FortiSandbox KEV entry within the month (CVE-2026-25089, also OS command injection, added July 16), reinforcing a pattern seen across recent Fortinet KEV cycles.

3. Microsoft SharePoint

CVE:  CVE-2026-50522 | Severity: Critical | EPSS: 84.6% | Exploitation Status: Actively exploited

A deserialization-of-untrusted-data flaw in Microsoft SharePoint Enterprise Server 2016, Server 2019, and Server Subscription Edition allows an unauthorized attacker to execute code over the network.

SharePoint was the single most represented product in July's KEV additions, with three separate deserialization and authentication CVEs affecting on-premises deployments (CVE-2026-50522, CVE-2026-56164, and CVE-2026-58644). Organizations still running on-prem SharePoint, common among Swiss public-sector and financial-services clients, should treat this as a coordinated patching wave rather than a single fix.

4. SonicWall SMA1000 Appliances

CVE:  CVE-2026-15409 | Severity: Critical (CVSS 10.0) | EPSS: 83.7% | Exploitation Status: Actively exploited, CISA remediation deadline July 17, 2026

An unauthenticated SSRF vulnerability in the SMA1000 Work Place interface lets a remote attacker force the appliance to issue requests to arbitrary internal locations, scoring the maximum possible CVSS base score of 10.0.

SMA1000 appliances are secure remote-access gateways, often placed at the network perimeter for VPN-less access. A successful SSRF here can be used to pivot into internal services that were never meant to be internet-reachable. SonicWall disclosed a second SMA1000 flaw the same week (CVE-2026-15410, code injection), so both should be patched together.

5. WordPress Core

CVE:  CVE-2026-60137 | Severity: Critical (CISA-ADP CVSS 9.1) | EPSS: 78.3% | Exploitation Status: Actively exploited, chained with CVE-2026-63030 (above)

The second half of the WordPress pairing: an improperly sanitized author__not_in parameter in WP_Query allows SQL injection when a plugin or theme passes untrusted input to it, affecting WordPress Core 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2.

On its own this is a high-severity SQL injection; chained with the route-confusion issue above (CVE-2026-63030), it becomes a full remote-code-execution path on default WordPress installations. Patch to 6.8.6, 6.9.5, or 7.0.2, whichever branch applies, as a single coordinated update alongside CVE-2026-63030.

Key Takeaways

Vulnerability chaining is now the norm: Both WordPress CVEs and the two FortiSandbox CVEs this month only reach their full impact when combined, meaning single-CVE patch tracking under-states real risk.

On-prem enterprise platforms remain prime targets: SharePoint, WordPress, and SonicWall SMA1000 combined account for 4 of the top 5 critical CVEs, reflecting attacker focus on widely deployed, internet-facing infrastructure.

EPSS scores above 75% across the board: every vulnerability in July's top 5 carries an EPSS score above 75%, indicating near-certain continued mass exploitation rather than isolated, targeted attacks.

References
# CVE Vendor / Product NVD Link
1 CVE-2026-63030 WordPress Core https://nvd.nist.gov/vuln/detail/CVE-2026-63030
2 CVE-2026-39808 Fortinet FortiSandbox https://nvd.nist.gov/vuln/detail/CVE-2026-39808
3 CVE-2026-50522 Microsoft SharePoint https://nvd.nist.gov/vuln/detail/CVE-2026-50522
4 CVE-2026-15409 SonicWall SMA1000 Appliances https://nvd.nist.gov/vuln/detail/CVE-2026-15409
5 CVE-2026-60137 WordPress Core https://nvd.nist.gov/vuln/detail/CVE-2026-60137

You can also check the vendor's official security advisory or the CISA KEV catalog directly for exploitation status

Arrow left navigation icon
See More

See more. Stay ahead.

VOC Services
Keep reading

More resources about Threat Intelligence

Cyber threats evolve fast. Our experts share the latest thinking on cybersecurity trends, regulatory changes and operational best practices — so your organization stays one step ahead.

Threat Intelligence
September 5, 2026

August - Top 5 vulnerabilities

Vulnerability Intelligence

Threat Intelligence
August 17, 2026

The Minnesota water stations attacks: lessons learned from the field

Published: August 5, 2026 | Stéphane Rabette | Reading Time: ~7 minutes