| Technology Fortinet FortiOS · CVE-2025-68686[1][24][25]First cited source Jul 24, 2026 · Latest cited source Current definition checked 2026-07-28 Exploitable conditionFortinet says a remote unauthenticated attacker can bypass a fix for symbolic-link persistence after the device was already compromised at filesystem level through another vulnerability. CVSS is 5.9 Medium; CWE-200 captures the confidentiality consequence but is a broad classification. | Which companies should care Organizations and service providers operating affected FortiOS 7.6.0–7.6.1, 7.4.0–7.4.6, 7.2.0–7.2.13, 7.0.0–7.0.19, or 6.4.0–6.4.16 devices. Business riskAttacker persistence can survive an incomplete remediation, leaving perimeter trust, administrator credentials, configuration, sessions, routing, and connected networks at risk. | What to monitor Move 7.6 to 7.6.2+ and 7.4 to 7.4.7+; obtain supported migration guidance for listed older branches; preserve evidence; review filesystem and configuration integrity, accounts, sessions, credential use, outbound traffic, and downstream access. IntelliOS coverage |
| Technology SonicWall SMA1000 6210, 7210, 8200v · CVE-2026-15409 / CVE-2026-15410[1][2][3][4][18]First cited source May 2026 · Latest cited source Jul 24, 2026 Exploitable conditionUnauthenticated SSRF/WebSocket proxy access can reach an appliance workflow where the second, authenticated-admin flaw enables path traversal and command execution. The chain can end in root-level appliance control. | Which companies should care Organizations using SMA1000 for enterprise remote access, including managed and distributed environments. Business riskCredential, session, and TOTP theft; appliance malware; lateral movement; ransomware initial access; prolonged identity and network-trust recovery. | What to monitor Owned models and fixed releases; historical WorkPlace/local-control activity; configuration changes; new users; credential access; outbound traffic; appliance-sourced lateral movement. IntelliOS coverage |
| Technology Microsoft SharePoint Server (on premises) · CVE-2026-50522 / 58644 / 56164 / 45659[1][14][15][20]First cited source Jul 14, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionCurrent exploited vulnerabilities affect on-premises SharePoint trust and code-execution paths; Microsoft and partner advisories control applicability. | Which companies should care Organizations running on-premises SharePoint for collaboration, records, intranet, or business workflows. Business riskWeb-shell persistence, credential theft, document exposure, lateral movement, interruption, privacy response, and recovery of a highly trusted collaboration service. | What to monitor Exact on-premises versions; emergency updates; web-shell and child-process evidence; credential use; configuration and service changes; outbound traffic; cloud/on-prem boundary accuracy. IntelliOS coverage |
| Technology Oracle PeopleSoft PeopleTools · CVE-2026-35273[1][6][7]First cited source Jun 10, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionUnauthenticated network exploitation of affected PeopleTools versions; CISA marks known ransomware use. | Which companies should care Higher education, government, healthcare, and enterprises using PeopleSoft for HR, payroll, student, finance, or administrative processes. Business riskExtortion, regulated-data theft, payroll or administrative disruption, credential exposure, notification, litigation, and restoration cost. | What to monitor Affected versions; exploitation requests; unexpected processes and files; PeopleSoft administrative activity; data export; identity changes; extortion contact. IntelliOS coverage |
| Technology Check Point Security Gateway IKEv1 remote access · CVE-2026-50751[1][8][19]First cited source Jun 8, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionAuthentication bypass affects deprecated IKEv1 VPN configurations and is actively exploited. | Which companies should care Organizations retaining legacy Check Point remote-access configurations. Business riskUnauthorized perimeter access, credential or session abuse, internal reconnaissance, data theft, ransomware deployment, and emergency VPN disruption. | What to monitor IKEv1 configuration; hotfix status; unusual VPN authentications; new source geography; privileged access; lateral movement; Qilin-linked downstream behavior. IntelliOS coverage |
| Technology PTC Windchill / FlexPLM · CVE-2026-12569[1][9]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionRemote code execution against affected PLM systems; vendor guidance includes web-shell hunting and CISA marks known ransomware use. | Which companies should care Manufacturers, engineering firms, product companies, and suppliers using PLM for designs, bills of material, and collaboration. Business riskIntellectual-property theft, web-shell persistence, engineering outage, supplier compromise, contractual harm, and ransomware. | What to monitor Versions and patches; vendor IOCs; web shells; unusual Java/process activity; new admin actions; bulk design export; supplier-account use. IntelliOS coverage |
| Technology Palo Alto PAN-OS GlobalProtect · CVE-2026-0257[1][11]First cited source Jun 3, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionAuthentication bypass affects specified GlobalProtect configurations; the vendor reports limited exploitation and CISA marks known ransomware use. | Which companies should care Organizations using PAN-OS or Prisma Access for remote workforce access. Business riskUnauthorized access at the identity/network boundary, internal movement, data theft, ransomware, and loss of confidence in remote-access logs. | What to monitor Affected versions and configuration; fixes; historical VPN sessions; impossible travel; new users/tokens; configuration drift; internal access from the appliance. IntelliOS coverage |
| Technology Langflow AI workflow servers · CVE-2026-0770[1][5]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionUnauthenticated code execution through exec_globals handling can run in the server's root context. | Which companies should care AI teams, developers, integrators, consultants, and organizations self-hosting Langflow to connect models, data, APIs, and agents. Business riskRoot takeover, model/API secret theft, connected-service access, data exposure, workflow manipulation, lateral movement, and loss of trust in AI outputs. | What to monitor Internet exposure; version and mitigation; validate-endpoint requests; child processes; secret reads; outbound connections; flow changes; downstream API activity. IntelliOS coverage |
| Technology SimpleHelp remote support · CVE-2026-48558[1][10]First cited source Jun 29, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionOIDC authentication bypass affects specified 5.5 and pre-release 6.0 versions. | Which companies should care Internal IT teams and MSPs using SimpleHelp to administer endpoints and customer systems. Business riskRemote administration takeover, multi-customer blast radius, tool-assisted persistence, credential access, ransomware, and service-provider liability. | What to monitor Public servers; exact versions; OIDC configuration; administrative logins; newly enrolled devices/users; remote sessions; client-wide unusual commands. IntelliOS coverage |
| Technology Nx Console for VS Code · CVE-2026-48027 / malicious v18.95.0[1][12][13]First cited source May 21, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionA malicious marketplace release compromised developer workstations and could expose GitHub and CI/CD trust. | Which companies should care Software developers and organizations using Nx, VS Code, GitHub, package registries, and automated build/deploy systems. Business riskDeveloper-machine compromise, repository and CI/CD secret theft, malicious code changes, software supply-chain propagation, and downstream customer impact. | What to monitor Extension history; affected workstation inventory; repository tokens; GitHub activity; CI/CD secret use; package publication; code changes; rebuilt endpoints. IntelliOS coverage |
| Technology FortiSandbox · CVE-2026-25089 / CVE-2026-39808[1][16]First cited source Jul 16, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionActively exploited vulnerabilities affect a security-analysis appliance; Fortinet controls affected versions and fixes. | Which companies should care Enterprises, MSSPs, and security operations teams using FortiSandbox for malware analysis and security integration. Business riskCompromise of a trusted security control, analysis data exposure, management access, detection impairment, and a foothold inside the security stack. | What to monitor Models and versions; management exposure; administrative changes; child processes; new integrations; outbound traffic; altered analysis or detection behavior. IntelliOS coverage |
| Technology WebPros cPanel & WHM · CVE-2026-41940[1]Evidence dated Jul 24, 2026 Exploitable conditionAuthentication bypass in a hosting control plane; CISA marks known ransomware campaign use. | Which companies should care Hosting providers, web agencies, MSPs, and companies administering multiple sites and mail services through cPanel. Business riskMulti-tenant website and email compromise, credential theft, data destruction, ransomware, customer notification, and correlated portfolio loss. | What to monitor Control-panel versions; admin authentications; new accounts/API tokens; site and mail configuration changes; backup access; cross-tenant activity. IntelliOS coverage |
| Technology Ivanti EPMM · CVE-2026-6973[1][17][21]First cited source May 7, 2026 · Latest cited source Jul 24, 2026 Exploitable conditionA serious flaw with an administrative-authentication prerequisite; Ivanti reports very limited known exploitation. | Which companies should care Organizations using EPMM to manage mobile devices, policies, certificates, and enterprise access. Business riskPrivileged mobile-management compromise, policy and certificate abuse, device fleet disruption, credential access, and difficult trust recovery. | What to monitor Affected versions; admin account history; fixes; unexpected policy/certificate changes; enrollment activity; configuration exports; managed-device anomalies. IntelliOS coverage |