(TLP:CLEAR) Weekly Vulnerabilities to Prioritize – July 23, 2026
Created: Thursday, July 23, 2026 - 16:22
Categories: Cybersecurity, Security Preparedness
The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical vulnerabilities that affect widely used products and may be under active exploitation. WaterISAC draws additional awareness in alerts and advisories when vulnerabilities are confirmed to be impacting, or have a high likelihood of impacting, water and wastewater utilities. Members are encouraged to regularly review these vulnerabilities, many of which are often included in CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVSS v3.1: 9.8
CVE: CVE-2026-50522
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50522
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
CVSS v3.1: 9.8
CVE: CVE-2026-58644
Description: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Original Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58644
Fortinet FortiSandbox OS Command Injection Vulnerability
CVSS v3.1: 9.1
CVE: CVE-2026-25089
Description: A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Original Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-141
Fortinet FortiSandbox OS Command Injection Vulnerability
CVSS 3.1: 9.1
CVE: CVE-2026-39808
Description: A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Original Source: https://fortiguard.fortinet.com/psirt/FG-IR-26-100
Check Point SmartConsole Improper Authentication Vulnerability
CVSS v3.1: 9.1
CVEs: CVE-2026-16232
Description: An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://support.checkpoint.com/results/sk/sk185169/
WordPress Core Interpretation Conflict Vulnerability
CVSS v3.1: 9.8
CVE: CVE-2026-63030
Description: WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Original Source: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q
WordPress Core SQL Injection Vulnerability
CVSS 3.1: 5.9
CVE: CVE-2026-60137
Description: WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Original Source: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
CVSS v3.0: 9.8
CVE: CVE-2026-0770
Description: Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325. CISA added this vulnerabilities to its Known Exploited Vulnerability Catalog.
Source: https://www.zerodayinitiative.com/advisories/ZDI-26-036/
