← All briefings

Fortinet FortiSandbox · Microsoft SharePoint · Zoom Workplace for Windows

Daily Threat Intelligence Briefing

Date: 2026-07-17 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

Three new CISA KEV entries demand immediate attention: two unauthenticated OS command injection flaws in Fortinet FortiSandbox (CVE-2026-25089, CVE-2026-39808) and a Microsoft SharePoint deserialization RCE (CVE-2026-58644), all with a federal patch deadline of 2026-07-19. The BSI has updated its SonicWall SMA1000 advisory (Version 1.1) confirming a public PoC for CVE-2026-15409 significantly raises exploitation risk. Cisco Talos disclosed a new financially motivated Russian-speaking threat actor (UAT-11795) deploying a novel RAT via trojanized WebEx and Zoom installers, with European targets confirmed.


Critical Vulnerabilities

CVE-2026-25089 / CVE-2026-39808 — Fortinet FortiSandbox (OS Command Injection, KEV)

  • Severity: Critical (CVSS not yet published)
  • EPSS: Not yet scored
  • Technical detail: Both CVEs are OS command injection flaws (CWE-78) in Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS. CVE-2026-25089 allows an unauthenticated attacker to execute arbitrary OS commands via crafted HTTP requests; CVE-2026-39808 is a closely related variant affecting the same product line. Both are network-exploitable with no authentication required, making them high-priority targets in enterprise security infrastructure. FortiSandbox is commonly deployed as a network-edge inspection component, meaning compromise could allow an attacker to intercept or manipulate sandboxed file analysis.
  • Exploitation status: Actively exploited in the wild; added to CISA KEV 2026-07-16.
  • Remediation: Apply Fortinet’s patches immediately. CISA KEV deadline for federal agencies: 2026-07-19. Restrict management interface access to trusted IPs as an interim control. Review FortiSandbox logs for anomalous HTTP requests.

CVE-2026-58644 — Microsoft SharePoint (Deserialization RCE, KEV)

  • Severity: Critical (CWE-502, deserialization of untrusted data)
  • EPSS: Not yet scored
  • Technical detail: An unauthenticated attacker can execute arbitrary code over the network by exploiting unsafe deserialization in Microsoft SharePoint. Deserialization RCE in SharePoint has historically been chained with privilege escalation flaws (cf. CVE-2026-56164 from the prior cycle) to achieve full farm compromise. On-premises SharePoint deployments in European enterprise environments are the primary risk surface; SharePoint Online (Microsoft 365) may have separate mitigations applied by Microsoft.
  • Exploitation status: Actively exploited in the wild; added to CISA KEV 2026-07-16.
  • Remediation: Apply the relevant SharePoint cumulative update immediately. CISA KEV deadline: 2026-07-19. Verify SharePoint is not directly internet-exposed; enforce network segmentation. This is a separate CVE from CVE-2026-56164 (also KEV) — both require patching.

CVE-2026-53412 — Zoom Workplace for Windows (Account Takeover)

  • STATUS CHANGE: CVE ID now confirmed (previously listed as “CVE pending” in yesterday’s report).
  • Severity: CVSS 9.8
  • Update: CVE assigned and confirmed as improper input validation enabling unauthenticated network-based account takeover. Affects Zoom Desktop Client for Windows, VDI Client, and Meeting SDK for Windows versions prior to 7.0.0. Heise Security and The Hacker News both confirmed the CVSS 9.8 rating. No exploitation confirmed in the wild, but the unauthenticated network vector and high CVSS score warrant urgent patching.
  • Remediation: Update all Zoom Windows clients and SDKs to version 7.0.0 or later immediately.

CVE-2026-44182 / CVE-2026-44181 / CVE-2026-44180 — Jupyter Enterprise Gateway (RCE Cluster, CVSS 10.0 / 9.8)

  • Severity: CVSS 10.0 (CVE-2026-44182, CVE-2026-44181); CVSS 9.8 (CVE-2026-44180)
  • EPSS: 0 (newly published)
  • Technical detail: Three critical vulnerabilities in Jupyter Enterprise Gateway affect versions prior to 3.3.0. CVE-2026-44182 and CVE-2026-44181 involve server-side interpolation of untrusted environment variables into kernel launch commands, enabling unauthenticated RCE in distributed compute environments (Apache Spark, Kubernetes, Docker Swarm). CVE-2026-44180 is a related prohibited-access flaw. These are particularly relevant for data science and ML infrastructure in enterprise and research environments, which are common in European academic and financial institutions.
  • Exploitation status: No confirmed exploitation; EPSS 0 (newly published).
  • Remediation: Upgrade Jupyter Enterprise Gateway to 3.3.0 or later. Restrict gateway access to authenticated internal networks; do not expose the gateway endpoint to the internet.

CVE-2026-63087 — Grafana OnCall (Unauthenticated Token Disclosure, CVSS 9.3)

  • Severity: CVSS 9.3
  • EPSS: Not yet scored
  • Technical detail: Grafana OnCall through version 1.16.11 exposes an internal plugin install endpoint that returns a valid PluginAuthToken to unauthenticated remote attackers via a POST request. This token can be used to authenticate to OnCall’s internal API, potentially enabling unauthorized access to on-call schedules, alert routing, and integrated monitoring data. Grafana is widely deployed in European enterprise and cloud-native environments.
  • Exploitation status: No confirmed exploitation.
  • Remediation: Update Grafana OnCall to a version beyond 1.16.11. Restrict the OnCall API endpoint to internal networks; review access logs for unexpected POST requests to the plugin install route.

ONGOING:

  • CVE-2026-15409 / CVE-2026-15410 (SonicWall SMA1000): public PoC now available (see BSI update below); treat unpatched appliances as compromised — patch or re-image immediately.
  • CVE-2026-56164 (SharePoint EoP, KEV): actively exploited; patch now.
  • CVE-2026-56155 (AD FS EoP, KEV): actively exploited; CISA deadline 2026-07-28 — patch now.
  • CVE-2026-46817 (Oracle E-Business Suite): actively exploited; CISA deadline passed — patch immediately.
  • CVE-2026-55255 (Langflow): actively exploited; patch immediately.
  • CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
  • CVE-2026-44747 (SAP NetWeaver ABAP, CVSS 9.9): patch immediately.
  • CVE-2026-48318 cluster (Adobe ColdFusion): patch to ColdFusion 2023 Update 22 / 2025 Update 11.

European Advisories

BSI [Version 1.1 update] SonicWall SMA1000 (2026-271845-1032): BSI updated its critical advisory on 2026-07-16 to incorporate Rapid7’s technical disclosure. A public PoC exploit for CVE-2026-15409 is now available, enabling unauthenticated RCE on SMA1000 models 6210, 7210, and 8200v. BSI explicitly calls for immediate forensic investigation. Covered in detail in yesterday’s Critical Vulnerabilities section; the PoC publication is a material status change — exploitation by additional threat actors is now highly probable.

BSI [WID-SEC-2026-2384](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2384) — FreeRDP (NEU, hoch): Multiple vulnerabilities enabling RCE, security bypass, information disclosure, data manipulation, and DoS. Apply current FreeRDP updates; relevant for VDI and remote desktop environments.

BSI [WID-SEC-2026-2383](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2383) — NGINX Plus (NEU, hoch): Multiple vulnerabilities enabling RCE, DoS, data manipulation, and information disclosure. Apply NGINX Plus updates; review exposure of management interfaces.

BSI [WID-SEC-2026-2377](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2377) / [WID-SEC-2026-1829](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1829) — Wazuh (NEU + UPDATE, kritisch/hoch): New advisory covers privilege escalation, DoS, information disclosure, and security bypass across Wazuh components. The existing critical advisory for Wazuh Manager privilege escalation was also updated. Patch Wazuh deployments promptly; Wazuh is widely used as a SIEM/XDR platform in European SOC environments.

BSI [WID-SEC-2026-2370](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2370) — Splunk Enterprise (NEU, hoch): Multiple vulnerabilities enabling security bypass, data manipulation, and information disclosure. Apply current Splunk Enterprise updates.

BSI [WID-SEC-2026-2380](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2380) — LiteLLM (NEU, hoch): Authenticated RCE with service-level privileges. Relevant for organizations deploying LiteLLM as an LLM proxy gateway. Apply available patches and restrict authenticated access.

BSI updates (hoch) — GNU libc (WID-SEC-2026-1190), Linux Kernel (WID-SEC-2025-2868), Apache Tomcat (WID-SEC-2026-1514), Golang Go (WID-SEC-2026-0345, WID-SEC-2026-1006), Red Hat (multiple components), VMware Tanzu Spring Security, Ruby (WID-SEC-2026-2379): All updated. Apply current distribution and vendor patches.


Active Threats and Campaigns

NEW — UAT-11795 / Starland RAT (Russian-speaking, financially motivated, Europe-targeted): Cisco Talos disclosed UAT-11795, a sophisticated Russian-speaking financially motivated threat actor active since at least June 2025. The group trojanizes legitimate WebEx and Zoom installers to deliver a novel backdoor called Starland RAT alongside a bespoke C2 implant called WLDR. Targets include users in the U.S. and Europe. The use of trojanized conferencing software is particularly relevant given Zoom’s current high-profile patching cycle. IOCs are available in the Talos blog post. Verify software download sources; enforce application allowlisting and hash verification for conferencing tools.

NEW — TELEPUZ Malware (ClickFix distribution, modular): Elastic Security Labs identified TELEPUZ, a modular malware spreading via ClickFix-laced websites since late April 2026. Full-featured with data theft and remote command execution capabilities. C2 infrastructure currently small but growing. Block ClickFix-style social engineering lures via browser policy; monitor for unexpected PowerShell/script execution.

NEW — Spirals Ransomware (sub-24-hour encryption): A new ransomware actor completed a full intrusion cycle — initial access, data exfiltration, and network encryption — in under 24 hours. Operational speed leaves minimal detection window. Ensure EDR telemetry and backup integrity checks are functioning; validate incident response runbooks for rapid-onset ransomware scenarios.

NEW — PhantomEnigma Campaign (Brazilian government website hijacking): Over 20 Brazilian government websites were compromised and used as malware delivery channels. Previously undocumented backdoor behavior identified. Low direct relevance to European enterprises but indicative of ongoing government-site abuse patterns.

ONGOING — OkoBot framework: hardware wallet seed-phrase theft active; enforce application allowlisting on endpoints with crypto wallet software.


Security News and Context

Scattered Spider sentencing: Two members (Owen Flowers, 18; Thalha Jubair, 20) received 5.5-year sentences at Woolwich Crown Court for the 2024 Transport for London hack, which rendered 148 systems inoperable and affected all 27,000 TfL employees. (Bleeping Computer)

Fairlife ransomware attack: Coca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary that has temporarily halted US production — a notable example of ransomware causing direct operational disruption to food supply chains. (Bleeping Computer)

Mandiant M-Trends 2026 — Mean Time-to-Exploit now -7 days: Mandiant reports the average TTE has dropped to negative seven days, meaning vulnerabilities are frequently exploited before patches exist. (Google Cloud Blog)

Rapid7 sunsetting AttackerKB: The public AttackerKB platform will be retired on August 18; vulnerability intelligence migrates to the Rapid7 blog and Vulnerability & Exploit Database. Update any automated integrations using the public AttackerKB API. (Rapid7)


  1. Patch Fortinet FortiSandbox (CVE-2026-25089, CVE-2026-39808) immediately — unauthenticated RCE, CISA KEV deadline 2026-07-19. Restrict management interfaces to trusted IPs.
  2. Patch Microsoft SharePoint (CVE-2026-58644) immediately — unauthenticated deserialization RCE, CISA KEV deadline 2026-07-19. Verify on-premises deployments are not internet-exposed.
  3. Re-assess SonicWall SMA1000 posture — public PoC for CVE-2026-15409 now available; treat any unpatched appliance as compromised. Re-image if exploitation is suspected; rotate all credentials and TOTP seeds.
  4. Update Zoom Windows clients and SDKs to version 7.0.0+ (CVE-2026-53412, CVSS 9.8). Verify via software inventory; prioritize VDI environments.
  5. Upgrade Jupyter Enterprise Gateway to 3.3.0+ (CVE-2026-44182/44181/44180, CVSS 10.0). Restrict gateway endpoints to authenticated internal networks.
  6. Update Grafana OnCall beyond 1.16.11 (CVE-2026-63087); restrict API endpoint exposure.
  7. Patch Wazuh, Splunk Enterprise, NGINX Plus, FreeRDP, and LiteLLM per new BSI advisories (WID-SEC-2026-2377/2370/2383/2384/2380).
  8. Validate conferencing software integrity against UAT-11795/Starland RAT campaign — enforce hash verification or signed installer policies for WebEx and Zoom; review Talos IOCs.
  9. Test incident response runbooks for sub-24-hour ransomware scenarios (Spirals); verify backup integrity and EDR coverage.
  10. Continue remediation of previously reported items: CVE-2026-56164 / CVE-2026-56155 (SharePoint/AD FS KEV), CVE-2026-46817 (Oracle EBS), CVE-2026-55255 (Langflow), CVE-2026-8037 (Kemp LoadMaster), CVE-2026-44747 (SAP NetWeaver), CVE-2026-48318 cluster (ColdFusion).