July 2026 CVE Landscape
Insikt Group identified 85 high-impact vulnerabilities in July 2026, a 44% increase from the prior month, with 57 enabling RCE and 60 having public PoC exploits. Threat actors including the Dysphoria botnet, Cloud Atlas, Armored Likho, UAT-7810, and TA488 actively exploited vulnerabilities across IoT devices, email platforms, enterprise applications, and security appliances. Common weakness classes included OS command injection (CWE-78), unrestricted file upload (CWE-434), code injection (CWE-94), and deserialization flaws (CWE-502). Fourteen vulnerabilities were at least five years old, demonstrating continued exploitation of legacy flaws in unpatched environments.
Detection / Hunteropenrouter
What Happened
In July 2026, researchers identified 85 serious security flaws in widely used software and devices, a 44% increase from the previous month. More than half of these flaws allow attackers to remotely run code on affected systems, and public exploit code was available for most of them. Attackers targeted a wide range of systems including internet routers and cameras (to build botnets), email platforms (to steal information), and enterprise software like Microsoft Exchange and SharePoint. Several of the exploited flaws are years old, showing that many organizations still have not applied available fixes. Organizations should review the full vulnerability list, prioritize patching based on exploit likelihood (not just severity scores), and pay special attention to any internet-facing devices or email systems in their environment.
Key Takeaways
- 85 high-impact vulnerabilities identified in July 2026, a 44% increase from the prior month, with 36 rated Very Critical (Risk Score 99).
- 57 of the 85 vulnerabilities enabled remote code execution (RCE), affecting Microsoft, Fortinet, Langflow, ServiceNow, WordPress, Joomla, and IoT/embedded devices.
- Public proof-of-concept exploits were available for 60 of the 85 vulnerabilities, and the fastest observed disclosure-to-exploitation window was less than one day.
- The Dysphoria botnet and China-nexus UAT-7810 actor exploited legacy IoT/router CVEs to build DDoS and relay infrastructure (LapDogs ORB network).
- Email and collaboration platforms were targeted for espionage: Cloud Atlas exploited CVE-2018-0802, UNK_MassTraction exploited Roundcube CVEs, and TA488 exploited Exchange CVE-2026-42897 to deploy OWAReaper.
Affected Systems
- Microsoft Office Equation Editor
- Microsoft SharePoint Server
- Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM
- Microsoft Active Directory Federation Services
- Microsoft Windows
- Fortinet FortiOS
- Fortinet FortiSandbox
- Langflow
- SonicWall SMA1000 Appliances
- Cisco IOS
- Cisco Secure Firewall Management Center (FMC)
- ServiceNow AI Platform
- WordPress Core
- Roundcube Webmail
- Zimbra Collaboration
- Various IoT devices (Huawei HG532, Linksys routers, Tenda routers, TOTOLINK routers, Ruckus APs, DVRs, Wi-Fi repeaters)
- Adobe ColdFusion
- Apache Tomcat
- Palo Alto Networks PAN-OS and Prisma Access
- NetScaler ADC and Gateway
- Oracle E-Business Suite
- Check Point SmartConsole
- Craft CMS
- Alibaba Nacos
- Alibaba Fastjson
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2017-17215 | Huawei HG532 Firmware | 99 (Very Critical) | RCE in embedded Linux devices exploited by Dysphoria botnet to build DDoS and relay infrastructure. |
| CVE-2018-0802 | Microsoft Office Equation Editor | 99 (Very Critical) | RCE exploited by Cloud Atlas via malicious Office documents to deliver CloudAtlasGo. |
| CVE-2025-3248 | Langflow | 89 | RCE in Langflow for which Insikt Group created a Nuclei detection template available to Recorded Future customers. |
| CVE-2025-9491 | Microsoft Windows | 89 | Vulnerability abused by Armored Likho via malicious Windows shortcut to execute obfuscated PowerShell and deploy BusySnake Stealer. |
| CVE-2024-42009 | Roundcube Webmail | 79 | Vulnerability exploited by UNK_MassTraction for initial access, followed by IceCube post-exploitation. |
| CVE-2025-49113 | Roundcube Webmail | 89 | Vulnerability attempted by UNK_MassTraction during post-exploitation via IceCube malware. |
| CVE-2026-42897 | Microsoft Exchange Server 2016 CU23 and Subscription Edition RTM | 89 | Vulnerability exploited by TA488 to deploy OWAReaper malware. |
| CVE-2025-66376 | Zimbra Collaboration | 89 | Vulnerability abused by CL-STA-1114 for espionage and payload delivery. |
| CVE-2020-22653 | Ruckus APs, SmartZone, and ZoneDirector | 79 | Vulnerability exploited by UAT-7810 to compromise Ruckus devices and expand LapDogs ORB network. |
| CVE-2020-22658 | Ruckus APs, SmartZone, and ZoneDirector | 79 | Vulnerability exploited by UAT-7810 to compromise Ruckus devices and expand LapDogs ORB network. |
| CVE-2023-25717 | Ruckus Wireless Admin | 79 | Vulnerability exploited by UAT-7810 to compromise Ruckus devices and expand LapDogs ORB network. |
| CVE-2020-8515 | DrayTek Vigor2960, Vigor300B, and Vigor3900 firmware | 79 | RCE in DrayTek firmware exploited by Dysphoria botnet for IoT device compromise. |
| CVE-2025-28137 | TOTOLINK A810R firmware | 79 | RCE in TOTOLINK firmware exploited by Dysphoria botnet for IoT device compromise. |
| CVE-2025-55182 | Meta React Server Components | 99 (Very Critical) | RCE linked to Dysphoria botnet exploitation activity. |
| CVE-2026-0770 | Langflow | 99 (Very Critical) | RCE in Langflow with public PoC available. |
| CVE-2026-15409 | SonicWall SMA1000 Appliances | 99 (Very Critical) | Vulnerability in SonicWall SMA1000 with public PoC available. |
| CVE-2026-15410 | SonicWall SMA1000 Appliances | 99 (Very Critical) | RCE in SonicWall SMA1000 with public PoC available. |
| CVE-2026-48282 | Adobe ColdFusion | 99 (Very Critical) | RCE in Adobe ColdFusion with public PoC available. |
| CVE-2026-50522 | Microsoft SharePoint | 99 (Very Critical) | RCE in Microsoft SharePoint with public PoC available. |
| CVE-2026-6875 | ServiceNow AI Platform | 89 | RCE in ServiceNow AI Platform with public PoC available. |
| CVE-2026-34486 | Apache Tomcat | 99 (Very Critical) | RCE in Apache Tomcat. |
| CVE-2026-0257 | Palo Alto Networks PAN-OS and Prisma Access | 89 | Vulnerability in PAN-OS and Prisma Access with public PoC available. |
| CVE-2026-3055 | NetScaler ADC and Gateway | 89 | Vulnerability in NetScaler ADC and Gateway with public PoC available. |
| CVE-2025-32432 | Craft CMS | 89 | RCE in Craft CMS with public PoC available. |
| CVE-2021-4034 | Polkit | 99 (Very Critical) | Privilege escalation vulnerability (PwnKit) with public PoC available. |
| CVE-2021-3156 | Sudo | 89 | Heap-based buffer overflow in Sudo (Baron Samedit) with public PoC available. |
Attack Chain
- Initial Access: Threat actors exploit public-facing vulnerabilities (e.g., CVE-2017-17215 in Huawei HG532, CVE-2024-42009 in Roundcube, CVE-2026-42897 in Exchange) or use malicious documents/shortcuts for client-side exploitation (CVE-2018-0802, CVE-2025-9491)
- Execution: Malicious Office documents deliver CloudAtlasGo; obfuscated PowerShell deploys BusySnake Stealer; IceCube used post-exploitation via Roundcube compromise
- Persistence and Relay: Compromised IoT devices enrolled into Dysphoria DDoS/relay infrastructure or LapDogs ORB network (UAT-7810) using weak Telnet/SSH credentials
- Lateral Movement and Collection: Email/collaboration platform access used for espionage and sensitive information theft
- Impact: Data theft, extortion, and encryption of exposed AI and product-lifecycle platforms by JADEPUFFER and Cl0p
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: Yes
- Platforms: Nuclei templates (Recorded Future Intelligence Platform)
Insikt Group created a Nuclei template to detect CVE-2025-3248 (Langflow), available to Recorded Future customers via the Intelligence Platform. No YARA, Sigma, Snort, or Suricata rules are provided in the article.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | EDR can detect obfuscated PowerShell execution and malicious shortcut files associated with Armored Likho's BusySnake Stealer deployment, but exploitation of public-facing vulnerabilities on network appliances and IoT devices typically occurs outside EDR coverage. |
| Network Visibility | Medium | Network monitoring can detect C2 traffic from compromised IoT devices enrolled in Dysphoria relay infrastructure and UAT-7810 LapDogs ORB network, but initial exploitation of public-facing services may blend with legitimate traffic. |
| Detection Difficulty | Hard | The breadth of 85 vulnerabilities across 61 vendors, combined with exploitation of legacy IoT devices that often lack endpoint telemetry, makes comprehensive detection challenging. Many affected systems (network appliances, IoT devices) have limited logging capabilities. |
Required Log Sources
- Web application firewall logs
- Network appliance syslog
- Email gateway logs
- EDR process execution logs
- DNS resolution logs
- CISA KEV catalog feed
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Consider hunting for devices in your environment communicating with known relay proxy infrastructure, which may indicate compromise by IoT-focused botnets like Dysphoria or LapDogs ORB network. | Network flow data, DNS logs, proxy logs | Command and Control | Medium — legitimate relay or proxy services may generate similar traffic patterns. |
| Consider hunting for obfuscated PowerShell execution originating from Windows shortcut files, consistent with Armored Likho's BusySnake Stealer delivery method. | EDR process execution logs, command-line logging (Event ID 4688), Sysmon Event ID 1 | Execution | Low — obfuscated PowerShell launched from .lnk files is uncommon in normal operations. |
| Consider hunting for exploitation attempts against email and collaboration platforms (Roundcube, Zimbra, Exchange) by monitoring for anomalous authentication patterns or unexpected webmail session activity. | Web application logs, authentication logs, email gateway logs | Initial Access | Medium — legitimate users may exhibit unusual access patterns during travel or when using new devices. |
| Consider hunting for exploitation of public-facing applications by correlating web server logs with known CVE indicators for the 85 vulnerabilities listed, focusing on systems running unpatched versions. | WAF logs, reverse proxy logs, web server access logs | Initial Access | Low to Medium — vulnerability scanners and security testing tools may generate similar patterns. |
| Consider hunting for post-exploitation activity following email platform compromise, such as IceCube malware execution or OWAReaper deployment, by monitoring for unusual process creation or mailbox access patterns on Exchange servers. | EDR logs on mail servers, Exchange audit logs, Windows Event logs | Persistence and Collection | Low — these malware families are not associated with legitimate administrative activity. |
Control Gaps
- IoT and embedded devices (routers, cameras, DVRs) typically lack endpoint detection capabilities, creating blind spots for Dysphoria and UAT-7810 compromise detection
- Network appliances running FortiOS, SonicWall, NetScaler, and PAN-OS may not generate logs compatible with standard SIEM ingestion without additional configuration
- Legacy vulnerabilities (5-18 years old) may persist in environments where asset inventory is incomplete or patching is deprioritized for older systems
- Public PoC availability for 60 of 85 vulnerabilities reduces the barrier to exploitation, potentially overwhelming signature-based detection
Key Behavioral Indicators
- Obfuscated PowerShell execution spawned from a Windows shortcut (.lnk) file
- Unusual outbound proxy or relay traffic from IoT/embedded devices
- Exploitation attempts targeting Equation Editor (CVE-2018-0802) in Office documents
- Anomalous authentication or session activity on Roundcube, Zimbra, or Exchange webmail interfaces
- Unexpected file uploads or code injection attempts against web applications (CWE-434, CWE-94 patterns)
- Deserialization exploitation attempts against Java-based applications (Fastjson, Apache Tomcat, ColdFusion)
False Positive Assessment
Low — the vulnerabilities and threat actor campaigns are corroborated by multiple intelligence sources including CISA KEV, vendor reports, honeypot data, and Insikt Group's validated intelligence events. However, PoC efficacy was not tested by Insikt Group, so defenders should validate PoC accuracy before testing.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Cross-reference the 85 CVEs listed in this report against your asset inventory and prioritize patching for any matches, especially those with public PoC exploits and Risk Score 99.
- If your organization uses any of the affected IoT/embedded devices (Huawei HG532, Linksys, Tenda, TOTOLINK, Ruckus, DrayTek), consider isolating or updating them immediately, as these are actively targeted by the Dysphoria botnet and UAT-7810.
- Consider applying vendor patches for Microsoft Exchange (CVE-2026-42897), SharePoint, and Active Directory Federation Services if these services are exposed, given active exploitation by TA488 and others.
- If you have Langflow deployments, consider applying patches for CVE-2025-3248 and CVE-2026-0770 and reviewing the Nuclei template available via Recorded Future for detection.
Infrastructure Hardening
- Evaluate whether internet-facing security appliances (Fortinet, SonicWall, Palo Alto, NetScaler, Cisco FMC) are running current firmware versions, and consider restricting management interfaces to internal networks or VPN-only access where supported.
- Consider disabling or restricting Telnet on all IoT and network devices, as the Dysphoria botnet combined weak Telnet/SSH credentials with known RCE flaws for compromise.
- If applicable, consider deploying WAF rules or virtual patching for web application vulnerabilities (WordPress, Joomla, Craft CMS, Adobe ColdFusion) where immediate patching is not feasible.
- Evaluate whether your email platform (Roundcube, Zimbra, Exchange) has adequate logging and alerting for anomalous session activity or exploitation attempts.
User Protection
- Consider enabling enhanced exploit protection for Microsoft Office (e.g., disabling Equation Editor) if not already configured, given Cloud Atlas's active exploitation of CVE-2018-0802.
- If your EDR supports it, consider enabling detection rules for obfuscated PowerShell execution originating from shortcut files, consistent with Armored Likho TTPs.
- Consider reviewing email security controls to detect malicious attachments and links targeting collaboration platforms, especially if Roundcube or Zimbra are in use.
Security Awareness
- Consider incorporating guidance on the risks of unpatched legacy systems into existing awareness programs, emphasizing that 14 of the 85 exploited vulnerabilities are at least 5 years old.
- Where applicable, remind users to report suspicious emails and unexpected Office document attachments, as threat actors continue to target document workflows for initial access.
- Consider briefing IT and network teams on the active targeting of IoT and edge devices by botnets, and the importance of changing default credentials on all network equipment.
MITRE ATT&CK Mapping
Initial Access
Execution
Persistence
Stealth
Collection
Command and Control
Exfiltration
Impact
Additional IOCs
- Command Lines:
- Purpose: Execution of obfuscated PowerShell via malicious Windows shortcut to deploy BusySnake Stealer | Tools:
powershell.exe,Windows Shortcut (.lnk)| Stage: Execution |powershell.exe -e
- Purpose: Execution of obfuscated PowerShell via malicious Windows shortcut to deploy BusySnake Stealer | Tools: