(TLP CLEAR) Weekly Vulnerabilities to Prioritize – July 30, 2026
Created: Thursday, July 30, 2026 - 14:40
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
CVSS v3.1: 5.3
CVEs: CVE-2026-20316
Description: A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
CVSS v4.0: 10.0
CVEs: CVE-2026-16812
Description: VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. This functionality was intended to be for internal use only and is not intended to be remotely accessible. Hosted and Dedicated versions of VCO have already been patched in advance of this notice going out. This issue was discovered externally and is known to be actively exploited. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.arista.com/en/support/advisories-notices/security-advisory/24364-security-advisory-0144
Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVSS v3.1: 5.3
CVEs: CVE-2025-68686
Description: An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in some post-exploit cases, via crafted HTTP requests. An attacker would need first to have compromised the product via another vulnerability, at filesystem level. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://fortiguard.fortinet.com/psirt/FG-IR-25-934
Microsoft Exchange Server Spoofing Vulnerability
CVSS 3.1: 8.1
CVEs: CVE-2026-42897
Description: Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
VMware ESX VMXNET3 out-of-bounds write vulnerability
CVSS v3.1: 9.3
CVEs: CVE-2026-47876
Description: VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.
Source: https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
