The Signal, An Offensive Intelligence Digest (Volume 001)

By
Team Evolve Security
,
Contents

Welcome to the 1st edition of The Signal, a newsletter designed to improve your signal-to-noise ratio. A monthly digest curated by our Offensive Security Operations Center (OSOC), delivering timely insights into emerging vulnerabilities, threat trends, and the exposures that matter most.

Bottom Line Upfront:

As part of Evolve Security's mission to keep focus on the most impactful threats, our August 2026 monthly digest provides the following analysis specific to activity observed and reported during July 2026.

In July 2026, CISA added 17 new entries to the Known Exploited Vulnerabilities (KEV) catalog, including 6 Critical-severity additions. Evolve Security's Offensive Security Operations Center (OSOC) has identified 5 vulnerabilities actively exploited in the wild during July 2026 – 2 rated Critical and 3 High. 3 distinct threat actors were tracked this month and 2 ransomware operators. Review the sections below, assess your exposure, and prioritize patching per the recommended actions provided.

By The Numbers:

  • 5 vulnerabilities confirmed exploited in the wild: 2 Critical, 3 High
  • 17 new CISA KEV additions: 6 of them Critical
  • 10.0: the highest CVSS score of the month (Adobe ColdFusion RCE)
  • 3 distinct threat actors tracked, including 2 ransomware operators

Threat Actors To Watch:

Storm-2603 (aka Warlock Group / GOLD SALEM) · Ransomware

China-nexus actor, tracked with moderate confidence. Resumed its SharePoint-focused campaign this month, exploiting CVE-2026-45659 to deploy Warlock ransomware against on-prem SharePoint farms across North America and Europe. Same playbook as its 2025 campaigns: steal the MachineKey, forge a ViewState payload, drop an ASPX webshell, dump LSASS credentials, move laterally, exfiltrate, then encrypt.

INC Ransomware · Ransomware

Became the dominant actor exploiting SonicWall SMA1000 this month, chaining CVE-2026-15409 and CVE-2026-15410 for remote command execution, then harvesting credentials, session databases, and TOTP MFA seeds to secure long-term access. The group has claimed 885 victims to date across a geographically diverse target set, reinforced with pressure-call extortion tactics.

Opportunistic Mass-Exploitation Clusters · Cybercriminal

Unattributed actors weaponized public proof-of-concept code for CVE-2026-48282 (ColdFusion) and CVE-2026-50522 (SharePoint) within hours of release, automating exploitation at scale to grab footholds before organizations could patch broadly. That access then gets resold to ransomware affiliates.

Top 5 Actively Exploited Vulnerabilities:

Active exploitation in the wild, not disclosure alone, was the bar for this list.

1. CVE-2026-48282: Adobe ColdFusion | CVSS 10.0 | Critical

Unauthenticated path traversal leading to remote code execution. Exploitation began within roughly two hours of public disclosure. An estimated 800 internet-exposed ColdFusion instances remained unpatched as of early July.

Action: Apply Adobe's patch (APSB26-68) within 72 hours. Take any internet-facing instance offline until it's patched.

2. CVE-2026-50522: Microsoft SharePoint Server | CVSS 9.8 | Critical

The sixth on-prem SharePoint RCE targeted this month alone. Attackers pull machine keys with a single request, then forge ViewState payloads for persistence. No follow-on authentication is required.

Action: Patch immediately. Rotate SharePoint machine keys on any server that was internet-exposed before patching.

3. CVE-2026-45659: Microsoft SharePoint Server | CVSS 8.8 | High

Patched in May with an "exploitation less likely" rating. Now actively used by Storm-2603 to deploy Warlock ransomware.

Action: Patch immediately, rotate MachineKeys, and hunt for ASPX webshells (e.g., spinstall0.aspx) and LSASS credential access.

4. CVE-2026-20316: Cisco Secure Firewall Management Center | CVSS 5.3 | High

A static, low-privileged credential built into Cisco FMC lets an attacker log in directly and pull sensitive configuration and licensing data. CISA rates it chainable to escalate privileges further.

Action: Apply Cisco's hotfixes across affected versions (7.0, 7.2, 7.4, 7.6, 7.7, 10.0) and check logs for the /var/tmp/license.tmp indicator of compromise.

5. CVE-2025-68686: Fortinet FortiOS | High

Lets an attacker with prior filesystem-level access bypass an earlier patch meant to remove symlink-based persistence. A device patched for an old CVE can still carry an attacker's foothold underneath.

Action: Apply Fortinet's update and audit any previously compromised FortiOS device for lingering symlink persistence — don't assume the earlier patch fully remediated it.

CISA KEV: The rest of July's Additions:

Beyond the five above, CISA added 12 more entries to the KEV catalog in July, including Critical-severity flaws in JoomShaper SP Page Builder, Joomlack Page Builder CK, and two in Langflow, the AI agent orchestration platform (CVE-2026-55255, CVE-2026-0770). High-severity additions spanned WordPress Core (two separate CVEs), Microsoft AD FS, Check Point SmartConsole, Arista VeloCloud Orchestrator, and a 2021-vintage DD-WRT router firmware flaw still being actively exploited five years after disclosure.

Federal agencies face binding remediation deadlines on every entry. Every organization, regardless of mandate, should treat KEV inclusion as a high-priority remediation signal.

What Actually Moves Your Risk:

Exposure to July's activity isn't uniform. The variables that determine yours:

Asset exposure: internet-facing systems versus internal infrastructure. Patch cadence: the time from disclosure to remediation. EDR coverage and how current your detection rules are for these techniques. Whether the affected vendor products are actually running in your environment. And whether compensating controls exist for anything you can't patch immediately.

The Takeaway:

Exploit timelines keep compressing. ColdFusion went from public disclosure to active exploitation in about two hours. Waiting for the next scheduled patch cycle isn't a strategy, it's an exposure window.

Continuous Penetration Testing validates whether your compensating controls actually hold between patch cycles, not just whether a box got checked at the last audit.

Questions about your exposure to any of the CVEs above? Contact Evolve Security here.

Are you ready to evolve?

Published:
August 12, 2026
About the Author,

Team Evolve Security

Evolve Security is an offensive cybersecurity solution, delivering continuous penetration testing with the optimal blend of AI automation and human expertise, providing peace of mind through greater cyber resiliency.

Learn more about
Team Evolve Security

What is EPSS?

The Exploit Prediction Scoring System (EPSS) is a data-driven risk model maintained by FIRST that predicts the likelihood of vulnerability being exploited in the wild within the next 30 days. It complements CVSS by focusing on real-world exploitability.
For example, a CVSS 9.8 vulnerability with an EPSS of 0.1% may pose less immediate risk than a CVSS 7.5 vulnerability with a 75% EPSS.
EPSS updates daily and is publicly accessible at https://www.first.org/epss/.