Threat and Vulnerabilities Report - July 2026

August 3, 2026

Executive Summary

July 2026 closed out as a month defined by relentless pressure on internet-facing infrastructure, where attackers continued to favor known weaknesses in edge appliances, collaboration platforms, and enterprise software over novel techniques. The month's activity reinforced a familiar but sharpening reality, that the gap between disclosure and exploitation keeps narrowing, and that both state-aligned actors and financially motivated crews are moving faster to weaponize flaws before organizations can remediate.

CISA added 26 vulnerabilities to its Known Exploited Vulnerabilities catalog through July, spanning a broad cross-section of enterprise vendors. Microsoft led the additions with five entries, followed by Fortinet with three, and two apiece from SonicWall, WordPress, Cisco, and Langflow, alongside further entries affecting major vendors including Adobe, Check Point, and Oracle. The spread underscored that exploitation was not concentrated in any single technology, but distributed across operating systems, firewalls, VPN gateways, content management systems, and AI development frameworks, reflecting the widening attack surface defenders were forced to cover.

Beyond the KEV additions, active exploitation surfaced across a wide range of additional products throughout the month. Threat actors were observed targeting Citrix, Alibaba Fastjson, and multiple WordPress plugins, along with ASUS devices, Synacor Zimbra, and Ruckus Wireless products, demonstrating sustained interest in both widely deployed enterprise platforms and open-source components. This activity highlighted that exploitation extended well beyond cataloged vulnerabilities, with adversaries probing edge services and web-facing software for any foothold that could enable initial access or persistence.

The ransomware landscape remained highly active in July 2026, with Qilin emerging as the most prolific operation, claiming 124 victims over the month. TheGentlemen followed with 104 victims, and DragonForce accounted for 41, together reflecting a concentration of impact among a handful of aggressive, high-volume groups. The scale of these figures reinforced that ransomware continued to represent the most immediate and disruptive threat to organizations, with established operators maintaining steady operational tempo across multiple sectors.

Download Report

Subscribe to our Newsletter