Date: Monday, July 20, 2026
Audience: Server, infrastructure, security operations, incident response, OT and critical-infrastructure teams
Estimated reading time: 16 minutes
EXECUTIVE ADMIN SUMMARY
The weekend produced no stronger priority than the active campaigns targeting remote-access appliances, on-premises collaboration platforms, identity infrastructure and security-control systems.
Immediate priorities:
• Microsoft SharePoint: Treat exposed, on-premises farms as potentially compromised. The CISA remediation deadline for CVE-2026-58644 expired July 19. Patching does not remove web shells, stolen machine keys or other persistence.
• SonicWall SMA1000: Rapid7 and Huntress report exploitation of the CVE-2026-15409/CVE-2026-15410 chain. Vulnerable appliances should be removed from exposure or upgraded immediately. Preserve logs before reimaging.
• FortiSandbox: CISA added CVE-2026-25089 and CVE-2026-39808 to the Known Exploited Vulnerabilities catalog. The July 19 remediation deadline has passed.
• Microsoft AD FS: July’s update audits dangerous Distributed Key Manager permissions but does not automatically correct them. Administrators must review the new event records and perform remediation.
For systems past a KEV deadline, use an incident-response sequence rather than a patch-only workflow:
Isolate or restrict → preserve evidence → patch or rebuild → hunt for persistence and lateral movement → rotate secrets only after persistence has been removed.
Critical-infrastructure teams should also review the joint advisory on Russian FSB Center 16 exploitation of legacy Cisco router-management weaknesses and the CVSS 10.0 Rockwell Automation 1715-AENTR safety-system vulnerability.
IMMEDIATE ACTION REQUIRED
MICROSOFT SHAREPOINT SERVER — ACTIVE EXPLOITATION
Risk: Critical
CVE: CVE-2026-58644
CISA KEV added: July 16, 2026
CISA deadline: July 19, 2026 — expired
Affected scope: Supported on-premises SharePoint Server 2016, SharePoint Server 2019 and SharePoint Server Subscription Edition
Not affected: SharePoint Online
CVE-2026-58644 is a deserialization vulnerability that can produce remote code execution on vulnerable SharePoint servers. CISA reports active exploitation involving CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644.
Public descriptions disagree about the access prerequisite. Some Microsoft-linked material describes Site Owner privileges, while other technical reporting and scoring information describe an unauthenticated path. Until Microsoft reconciles the advisory language, exposed installations should be handled according to the less restrictive interpretation.
BCG is tracking this discrepancy and will update the feed when Microsoft clarifies the prerequisite or revises the advisory and CVSS information. Administrators should not use the narrower Site Owner description as evidence that an internet-facing farm was safe from exploitation.
Operational action:
• Restrict or remove public access to vulnerable farms until the response is complete.
• Apply the current July security updates to every SharePoint server in the farm. Do not leave search, application or secondary web-front-end nodes behind.
• Complete the required SharePoint configuration upgrade by running the documented SharePoint Products Configuration Wizard or corresponding PowerShell procedure. Installing the package alone may not complete the update.
• Enable Antimalware Scan Interface integration in Full mode where supported.
• Preserve IIS logs, SharePoint ULS logs, Windows event records, EDR telemetry, WAF records and relevant memory or disk evidence before destructive remediation.
• Hunt for machine-key access, unexpected ASPX files, web shells, modified application files, suspicious scheduled tasks and abnormal child processes from SharePoint or IIS workers.
• Review Microsoft Defender alerts, including detections associated with suspicious sign-out request bodies and ToolPane authentication-bypass activity.
• Assume that a successful attacker may retain access after patching. Remove persistence or rebuild affected nodes before rotating SharePoint machine keys, service-account credentials, application secrets and other farm trust material.
• Where compromise is confirmed, examine SQL servers, Active Directory, backup infrastructure, deployment accounts and management systems reachable from the SharePoint farm.
• Begin migration planning for SharePoint Server 2016 and 2019. Both reached end of support on July 14, 2026.
Confidence: High that exploitation is occurring and that immediate response is required. Medium on the exact access prerequisite because the public source language remains inconsistent.
Sources:
CISA — Microsoft SharePoint Vulnerabilities
CISA — Adds Three Known Exploited Vulnerabilities to Catalog, July 16, 2026
Microsoft Security Response Center — CVE-2026-58644
Microsoft — July 2026 SharePoint Server security updates
Tenable — SharePoint vulnerability FAQ
Rapid7 — Technical reporting on the SharePoint exploit chain
SONICWALL SMA1000 — ZERO-DAY CHAIN OBSERVED IN THE WILD
Risk: Critical
CVEs: CVE-2026-15409 and CVE-2026-15410
Disclosure and KEV date: July 14, 2026
CISA deadline: July 17, 2026 — expired
Confirmed exploitation: Rapid7 and Huntress
CVE-2026-15409 permits unauthenticated abuse of the wsproxy component to reach services bound to the appliance’s local interface. CVE-2026-15410 affects an internal hotfix-removal workflow and permits command execution through crafted path input. Chained together, the vulnerabilities can provide unauthenticated operating-system command execution.
Affected products include physical and virtual SMA1000-series appliances, including SMA 6210, SMA 7210 and SMA 8200v deployments.
Known affected builds:
• 12.4.3-03245
• 12.4.3-03387
• 12.4.3-03434
• 12.5.0-02283
• 12.5.0-02624
• 12.5.0-02800
Fixed builds:
• 12.4.3-03453
• 12.5.0-02835
Operational action:
• Remove vulnerable appliances from public exposure or restrict access to explicitly approved management and VPN paths.
• Upgrade to a fixed build immediately.
• Preserve appliance logs before upgrade, reset or reimaging. Relevant files include extraweb_access.log and ctrl-service.log.
• Search extraweb_access.log for unusual /wsproxy requests, HTTP 101 responses, attacker-controlled Host values and abnormal requests to /api/login or /api/logout returning HTTP 200.
• Search ctrl-service.log for hotfix rollback or removal activity containing path traversal, shell metacharacters or unexpected package names.
• Review outbound traffic, DNS requests, created files, command history and connections from the appliance to internal systems.
• If exploitation indicators are found, rebuild or redeploy the appliance from a trusted image. Do not assume an in-place update removes attacker persistence.
• After containment, rotate local and federated credentials exposed to the appliance, including administrator passwords, user passwords where warranted, TOTP seeds and API or integration secrets.
• Examine connected LDAP, Active Directory, RADIUS and management systems for follow-on activity.
Confidence: High. Vendor advisories, independent technical analysis and field observations agree on the affected builds, exploit chain and active abuse.
Sources:
SonicWall — Security Advisory SNWLID-2026-0008
CISA — Adds Four Known Exploited Vulnerabilities to Catalog, July 14, 2026
Rapid7 — CVE-2026-15409 and CVE-2026-15410 technical analysis
Huntress — Field observation of SMA1000 exploitation, July 17, 2026
FORTINET FORTISANDBOX — KEV DEADLINE EXPIRED
Risk: Critical
CVEs: CVE-2026-25089 and CVE-2026-39808
CISA KEV added: July 16, 2026
CISA deadline: July 19, 2026 — expired
FortiSandbox is a security-control platform with access to submitted files, network integrations and surrounding security infrastructure. Compromise should therefore be treated as a control-plane incident even when the appliance does not hold the organization’s primary business data.
CVE-2026-25089 is an operating-system command-injection vulnerability affecting the FortiSandbox administrative interface.
Fortinet-listed affected branches and fixes:
• FortiSandbox 5.0.0 through 5.0.5: upgrade to 5.0.6 or later.
• FortiSandbox 4.4.0 through 4.4.8: upgrade to 4.4.9 or later.
• FortiSandbox Cloud or PaaS 5.0.4 through 5.0.5: upgrade to 5.0.6 or later.
• FortiSandbox 5.2: not affected according to the advisory.
NVD also lists the FortiSandbox 4.2 branch as affected. Because Fortinet’s public solution table does not identify a fixed 4.2 release, organizations still operating that branch should obtain migration or remediation instructions from Fortinet rather than infer that a later 4.2 build is safe.
CVE-2026-39808 is an improper-access-control vulnerability affecting FortiSandbox 4.4.0 through 4.4.8. Upgrade to 4.4.9 or later. Fortinet states that the 5.0 and corresponding PaaS 5.0 branches are not affected by CVE-2026-39808.
Defused Cyber’s June 15 post, “We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities,” reported activity involving CVE-2026-39813, CVE-2026-39808 and CVE-2026-25089. Defused cautioned that one circulating CVE-2026-25089 exploit appeared to be faulty and that it had not identified a working public exploit at that time.
CISA’s subsequent KEV additions establish that the agency has reliable evidence of active exploitation of CVE-2026-25089 and CVE-2026-39808. That does not establish that every exploit sample or claim circulating publicly was functional.
Operational action:
• Restrict the administrative interface to a dedicated management network and approved administrator systems.
• Upgrade all affected appliances and cloud-managed instances.
• Preserve administrative, authentication, system, API and network records before resetting or rebuilding systems.
• Review administrator creation, permission changes, configuration exports, unexpected commands, scheduled activity and outbound connections.
• Examine integrations with FortiGate, FortiManager, FortiAnalyzer, mail gateways, SIEM platforms, file shares and directory services.
• If compromise is suspected, rebuild from trusted media and rotate connected credentials only after removing persistence.
Confidence: High for active exploitation and affected supported branches. Medium on the full historical 4.2 remediation path because the NVD affected-version listing and Fortinet’s solution table are not fully aligned.
Sources:
CISA — Known Exploited Vulnerabilities Catalog, July 16, 2026
Fortinet PSIRT — FG-IR-26-141, published June 9, 2026
Fortinet PSIRT — FG-IR-26-100, published April 14, 2026
Defused Cyber — “We are observing exploitation of multiple Fortinet FortiSandbox vulnerabilities,” June 15, 2026
National Vulnerability Database — CVE-2026-25089 and CVE-2026-39808
MICROSOFT AD FS — DANGEROUS DKM PERMISSIONS REQUIRE MANUAL REMEDIATION
Risk: High
CVE: CVE-2026-56155
Exploitation status: CISA reports active exploitation
Affected role: Active Directory Federation Services
Important limitation: The July security update audits the condition but does not automatically repair it
CVE-2026-56155 concerns excessive permissions on the AD FS Distributed Key Manager container in Active Directory. An attacker with a low-privilege domain foothold may be able to access sensitive AD FS key material when the DKM access-control list is unsafe.
The July update adds auditing and remediation support. Administrators must examine the new events and take the prescribed action.
Relevant event identifiers:
• Event 1132: Unsafe DKM permissions detected.
• Event 1133: DKM permissions are healthy.
• Event 1134: The permissions check could not complete.
• Event 1135: Remediation completed successfully.
• Event 1136: Remediation failed.
Affected or supported platform coverage includes Windows Server 2012 and 2012 R2 under applicable Extended Security Updates, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server version 23H2 and Windows Server 2025.
Operational action:
• Install the July security update on every AD FS node.
• Review AD FS event records on each server. Do not assume a successful update means the DKM permissions are safe.
• On Windows Server 2016 and later, use Microsoft’s documented RemediateDkmAcl procedure when Event 1132 is present.
• Apply Microsoft’s additional permission guidance to Windows Server 2012 and 2012 R2 systems.
• Investigate Event 1134 or 1136 rather than treating an incomplete check as a clean result.
• Review historical directory access, privilege changes and federation-service activity for evidence that DKM material was accessed before remediation.
• If compromise is confirmed or strongly suspected, plan rotation of affected AD FS certificates, token-signing or token-decrypting material and connected trust secrets after containment.
• Review cloud, SaaS and partner federation logs for forged or abnormal tokens.
Confidence: High. The principal operational hazard is misunderstanding the update as an automatic ACL correction.
Sources:
Microsoft — KB5121391: AD FS DKM permissions audit and remediation
Microsoft Security Response Center — CVE-2026-56155
CISA — Known Exploited Vulnerabilities Catalog
PATCH AND UPGRADE WATCH
NGINX — CVE-2026-42533
Priority: High for configurations using map with regular-expression captures
Exploitation status: No confirmed active exploitation found
CVE-2026-42533 is a heap-overflow vulnerability involving NGINX map configurations that use regular expressions. A remote, unauthenticated attacker may be able to trigger worker-process failure with crafted requests. F5 states that code execution may be possible where address-space layout randomization is disabled or can be bypassed.
Affected NGINX Open Source versions: 0.9.6 through 1.31.2
Fixed Open Source versions: 1.30.4 and 1.31.3
Fixed NGINX Plus version: R37 P3, identified as 37.0.3.1
Action:
• Upgrade affected packages.
• Search configuration files for map blocks containing regular expressions and captures.
• Review worker crashes, allocator failures and abnormal restart patterns.
• Named captures may reduce exposure in some configurations but are not a substitute for installing the fixed release.
• Confirm distribution-supplied packages contain the vendor backport rather than relying only on the displayed upstream version.
Sources:
NGINX — Security Advisories
F5 — Security Advisory K000162097
ROCKWELL AUTOMATION 1715-AENTR — CVE-2026-10577
Priority: Critical in deployed safety and process-control environments
CVSS: 10.0 under both CVSS 3.1 and CVSS 4.0
Exploitation status: No known public exploitation reported
CVE-2026-10577 affects the Rockwell Automation 1715-AENTR adapter through firmware 3.003. An unauthenticated remote attacker may be able to invoke exposed debugging functionality to read or delete files, stop tasks, modify memory and affect input/output states.
Fixed firmware: 3.011 or later
The potential consequence extends beyond confidentiality or server availability. In a deployed process environment, unauthorized I/O or memory modification may affect physical operations and safety assurance.
Action:
• Identify every installed 1715-AENTR and verify firmware directly.
• Upgrade to firmware 3.011 or later using the organization’s safety-change process.
• Segment the safety network from enterprise and internet-connected networks.
• Restrict engineering and maintenance access to authorized jump systems.
• Monitor for unexpected task stops, state changes, file operations and engineering connections.
• Coordinate changes with plant engineering, safety and operations personnel.
Sources:
Rockwell Automation — Security Advisory SD1785
CISA ICS Advisory ICSA-26-195-04
OPENSSL “HOLLOWBYTE” — NO CVE, SCANNER BLINDNESS RISK
Priority: High where untrusted clients can repeatedly reach OpenSSL-backed services
Identifier: No CVE assigned at publication time
Okta Red Team named this issue “HollowByte” in its July 16 publication, “OpenSSL HollowByte: A DoS Hiding in 11 Bytes.”
The reported condition can be triggered with an input as small as 11 bytes. Depending on the application and allocator behavior, repeated triggering may cause excessive memory allocation, block workers or produce persistent memory fragmentation. Environments using glibc may not promptly return fragmented memory to the operating system.
Fixed upstream releases:
• OpenSSL 4.0.1
• OpenSSL 3.6.3
• OpenSSL 3.5.7
• OpenSSL 3.4.6
• OpenSSL 3.0.21
Operational risk:
• Vulnerability-management systems that depend on CVE identifiers may not identify this issue.
• A patched shared library may remain ineffective until dependent services or containers are restarted.
• Linux distributions may backport the fix without adopting the upstream version number.
Action:
• Inventory OpenSSL versions in operating-system packages, containers, appliances and statically linked applications.
• Confirm the fix through vendor advisories or backport documentation.
• Restart affected services after updating.
• Monitor resident memory, worker exhaustion, allocator behavior and small malformed requests.
• Rate-limit unauthenticated endpoints where feasible.
No confirmed malicious exploitation was identified in the reviewed sources.
Sources:
Okta Red Team — “OpenSSL HollowByte: A DoS Hiding in 11 Bytes,” July 16, 2026
OpenSSL Project — Fixed releases and pull requests 30792 through 30794
NASA CORE FLIGHT SYSTEM HOUSEKEEPING SERVICE — CVE-2026-15352
Priority: High for exposed or reachable cFS deployments
Affected versions: Earlier than 7.0.1
Fixed version: 7.0.1
A crafted housekeeping request may trigger a NULL-pointer condition and denial of service. The request can be sent without authentication when a network path to the service exists.
No evidence reviewed for this feed establishes exploitation against an operational spacecraft. The defect nevertheless matters for laboratories, simulations, testbeds and mission-support networks running affected cFS components.
Action:
• Upgrade to cFS 7.0.1 or apply the corresponding vendor fix.
• Prevent untrusted networks from reaching housekeeping interfaces.
• Monitor service restarts and malformed or abnormal housekeeping traffic.
• Apply mission-assurance testing before changing operational environments.
Sources:
NASA cFS security advisory
National Vulnerability Database — CVE-2026-15352
CARRY-FORWARD: ORACLE E-BUSINESS SUITE AND KNX INFRASTRUCTURE
Oracle E-Business Suite CVE-2026-46817 affects the Payments File Transmission component in EBS 12.2.3 through 12.2.15. The reported attack path is unauthenticated and reachable over HTTP. Oracle released corrective material on May 28.
Organizations that have not applied the update should restrict exposure, patch immediately and investigate for prior access rather than treating the issue as routine backlog.
CVE-2023-4346 affects KNX devices and can permit configuration erasure followed by BCU-key lockout under relevant network or physical-access conditions. Because a universal software correction is not available across the installed ecosystem, mitigation depends on physical security, network isolation, protected commissioning access, current backups and device-specific vendor guidance.
Sources:
Oracle — E-Business Suite Security Alert for CVE-2026-46817
CISA — Known Exploited Vulnerabilities Catalog
KNX Association and affected-vendor advisories — CVE-2023-4346
DETECTION AND MONITORING PRIORITIES
RUSSIAN FSB CENTER 16 — ROUTER CONFIGURATION COLLECTION
A joint government advisory attributes continuing network-device operations to Russian FSB Center 16. The activity includes abuse of weak or legacy SNMP configurations on Cisco devices and collection of router configuration files.
Observed or relevant behaviors include:
• SNMP Set requests using common, default or exposed community strings.
• Cisco configuration-copy MIB objects in the 1.3.6.1.4.1.9.9.96.1.1 family.
• Configuration filenames such as config.bkp and output.txt.
• TFTP transfer of device configurations.
• Exploitation or scanning related to Cisco Smart Install vulnerability CVE-2018-0171.
• Continued operational relevance of legacy, end-of-life Cisco exposure associated with CVE-2008-4128.
CVE-2008-4128 is old, but the age of a vulnerability does not reduce its relevance when end-of-life equipment remains deployed in telecommunications, energy, military-support or industrial networks.
Defensive action:
• Disable SNMP where it is not required.
• Replace SNMPv1 and SNMPv2c with SNMPv3 using authentication and encryption.
• Remove default or shared community strings.
• Restrict SNMP and TFTP to dedicated management systems.
• Block Cisco Smart Install traffic where it is not explicitly required.
• Monitor UDP 161, UDP 162, UDP 69 and TCP 4786.
• Alert on configuration-copy OIDs and unexpected configuration exports.
• Replace end-of-life routers and switches that cannot receive supported fixes.
• Compare current configurations with trusted baselines and rotate exposed credentials.
• Treat a stolen router configuration as a credential and topology disclosure incident.
Sources:
NSA and partner agencies — Joint cybersecurity advisory on Russian FSB Center 16
Cisco — SNMP configuration-copy MIB documentation
CISA — CVE-2018-0171 guidance
Cisco — Historical advisory relevant to CVE-2008-4128
POST-PATCH MONITORING IS MANDATORY
The four immediate-action vulnerabilities can affect systems that broker trust or provide privileged network access. A successful patch changes future exploitability; it does not prove the system was clean beforehand.
Monitor for:
• SharePoint worker processes spawning command interpreters, scripting engines or unexpected utilities.
• New or modified web-accessible files and unexplained machine-key access.
• SMA1000 wsproxy upgrade requests, API login anomalies and hotfix rollback activity.
• FortiSandbox administrator creation, configuration export and unexpected outbound connections.
• AD FS DKM access, unsafe ACL events, abnormal token issuance and federation changes.
• Unexpected secret, certificate or service-account rotation initiated outside approved response work.
• Lateral movement from appliances that are often excluded from conventional endpoint monitoring.
LOWER-PRIORITY NOTES
KUDANKULAM NUCLEAR POWER PLANT DATA REPORTS
Reuters reported on July 15 that Reliance Group acknowledged a partial breach involving data stored on a server hosted by third-party Indian data-center provider Yotta. Yotta said it detected suspicious activity on May 29 and terminated it. The World Leaks group subsequently claimed to possess approximately 14.3 GB containing about 19,000 files, including alleged blueprints and supplier information.
The Nuclear Power Corporation of India said the public reporting concerned common service facilities and not nuclear-safety or nuclear-security systems. Reuters could not independently establish the authenticity of all material claimed by the attackers, and Yotta said it prevented suspected ransomware execution but could not verify every threat-actor assertion.
The incident is strategically significant because engineering, supplier and facility-support information can assist targeting even when reactor-control networks are not affected. It is not being promoted to the immediate-action section because the reviewed reporting does not establish compromise of operational reactor-control or safety systems.
Source:
Reuters — “Files relating to India’s largest nuclear power plant Kudankulam exposed in data breach,” July 15, 2026
ENDPOINT CARRY-FORWARD
Zoom CVE-2026-53412 and continuing 7-Zip exploitation remain relevant to administrator workstations, engineering endpoints and jump hosts. They are not primarily server vulnerabilities, but compromise of a privileged endpoint can bypass otherwise sound server controls.
ADMIN ACTION CHECKLIST
Within four hours:
• Identify internet-facing SharePoint, SMA1000, FortiSandbox and AD FS systems.
• Remove or restrict vulnerable systems from external exposure.
• Preserve volatile and appliance logs before upgrades or resets.
• Confirm which CISA deadlines have already expired.
• Notify incident response where a vulnerable system remained exposed past its deadline.
Today:
• Patch every SharePoint farm node and complete the configuration upgrade.
• Upgrade SMA1000 appliances to 12.4.3-03453 or 12.5.0-02835.
• Upgrade affected FortiSandbox branches and investigate administrative activity.
• Install the AD FS update, inspect Events 1132 through 1136 and remediate unsafe DKM permissions.
• Inventory affected NGINX, OpenSSL, Rockwell and NASA cFS deployments.
• Search network telemetry for SNMP configuration-copy activity and unauthorized TFTP.
Within 72 hours:
• Complete persistence and lateral-movement hunts.
• Rebuild systems where appliance-level compromise cannot be confidently excluded.
• Rotate secrets only after containment and persistence removal.
• Verify that every cluster, farm, secondary node, container and standby appliance received the fix.
• Test restored services and review monitoring coverage.
• Record accepted exceptions with an owner, compensating controls and an expiration date.
BCG ASSESSMENT
The week’s most serious exposure is concentrated in systems that broker trust: remote-access gateways, collaboration servers, federation services and security-analysis appliances. These systems need not store the organization’s most sensitive payload data to be Tier 0-adjacent. They can hold machine keys, tokens, configuration secrets, directory access and trusted routes into more sensitive environments.
Patch status and compromise status must therefore be tracked separately. A patched SharePoint server can still hold a stolen machine key. An upgraded SMA appliance can still leave compromised credentials behind. A corrected AD FS access-control list cannot retract previously stolen signing material. A repaired FortiSandbox may still have exposed connected security infrastructure.
For critical infrastructure, military-support organizations, chemical facilities, weapons contractors and high-consequence industrial environments, the preferred bias is containment and evidence preservation. Where reliable proof of integrity cannot be established, replacement or trusted rebuild is safer than assuming that an in-place update restored control.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: