Jump to the main content block

【Vulnerability Alert】CISA Added 10 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/13-2026/07/19)

publish date : 2026-07-24 update date : 2026-07-24

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026072305072222 Publication Time 2026-07-23 17:06:24
Incident Type ANA-Vulnerability Alert Discovery Time 2026-07-23 17:06:24
Impact Level Low  
[Subject]
【Vulnerability Alert】CISA Added 10 Known Exploited Vulnerabilities to the KEV Catalog (2026/07/13-2026/07/19)
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202607-00000011

【CVE-2008-4128】Cisco IOS Cross-Site Request Forgery Vulnerability (CVSS v3.1: 4.3)
【Whether exploited by ransomware: Unknown】The HTTP Administration component of Cisco IOS 12.4 used by the Cisco 871 Integrated Services Router contains multiple cross-site request forgery vulnerabilities. A remote attacker may induce a user to send specially crafted requests, thereby executing arbitrary commands on the affected device.

【CVE-2026-56155】Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability (CVSS v3.1: 7.8)
【Whether exploited by ransomware: Unknown】Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability, allowing an authorized attacker to elevate privileges locally.

【CVE-2026-56164】Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability (CVSS v3.1: 5.3)
【Whether exploited by ransomware: Unknown】Microsoft SharePoint Server contains a missing authentication for critical function vulnerability, allowing an unauthorized attacker to elevate privileges over a network.

【CVE-2026-15409】SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVSS v3.1: 10.0)
【Whether exploited by ransomware: Unknown】SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability, which may allow an unauthenticated remote attacker to cause the device to send requests to unintended locations.

【CVE-2026-15410】SonicWall SMA1000 Appliances Code Injection Vulnerability (CVSS v3.1: 7.2)
【Whether exploited by ransomware: Unknown】SonicWall SMA1000 Appliances contain a code injection vulnerability. Under specific conditions, this vulnerability may allow an authenticated remote attacker with administrator privileges to execute arbitrary operating system commands.

【CVE-2026-46817】Oracle E-Business Suite Improper Privilege Management Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Oracle E-Business Suite contains an improper privilege management vulnerability, allowing an unauthenticated attacker with HTTP access to the system to compromise Oracle Payments. Successful exploitation of this vulnerability may result in the takeover of Oracle Payments.

【CVE-2023-4346】KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability (CVSS v3.1: 7.5)
【Whether exploited by ransomware: Unknown】KNX Association KNX Protocol Connection Authorization Option 1 contains an improper account lockout mechanism vulnerability, which may allow an attacker to erase all devices that do not have additional security options enabled and set a BCU key to lock the devices.

【CVE-2026-58644】Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability, which may allow an unauthorized attacker to execute code over a network.

【CVE-2026-25089】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】The Web UI of Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contains an operating system command injection vulnerability, which may allow an unauthenticated attacker to execute unauthorized commands through specially crafted HTTP requests.

【CVE-2026-39808】Fortinet FortiSandbox OS Command Injection Vulnerability (CVSS v3.1: 9.8)
【Whether exploited by ransomware: Unknown】An API endpoint in Fortinet FortiSandbox contains an operating system command injection vulnerability, which may allow an unauthenticated attacker to execute unauthorized code or commands through specially crafted HTTP requests.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2008-4128】Cisco IOS 12.4 used by the Cisco 871 Integrated Services Router, involving the HTTP Administration component.

【CVE-2026-56155】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155

【CVE-2026-56164】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

【CVE-2026-15409】Please refer to the affected versions listed by the official vendor https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-15410】Please refer to the affected versions listed by the official vendor https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-46817】Please refer to the affected versions listed by the official vendor https://www.oracle.com/security-alerts/cspumay2026.html

【CVE-2023-4346】Please refer to the listed affected versions https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01

【CVE-2026-58644】Please refer to the affected versions listed by the official vendor https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-25089】Please refer to the affected versions listed by the official vendor https://fortiguard.fortinet.com/psirt/FG-IR-26-141

【CVE-2026-39808】Please refer to the affected versions listed by the official vendor https://fortiguard.fortinet.com/psirt/FG-IR-26-100

[Recommended Actions]

【CVE-2008-4128】The affected product may have reached the End-of-Life (EoL) and/or End-of-Support (EoS) stage. Users are advised to discontinue use of the product. https://www.cisco.com/c/en/us/obsolete/ios-nx-os-software/cisco-ios-software-releases-12-4-mainline.html

【CVE-2026-56155】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155

【CVE-2026-56164】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164

【CVE-2026-15409】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-15410】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

【CVE-2026-46817】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://www.oracle.com/security-alerts/cspumay2026.html

【CVE-2023-4346】The official vendor has released mitigation measures for the vulnerability https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01

【CVE-2026-58644】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644

【CVE-2026-25089】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-141

【CVE-2026-39808】The official vendor has released a remediation update for the vulnerability. Please update to the relevant version https://fortiguard.fortinet.com/psirt/FG-IR-26-100

 

[Reference]

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: