By Jordan Polasek · July 19, 2026

Good morning. This past week was a busy one at CISA, with ten new entries landing on the Known Exploited Vulnerabilities (KEV) catalog. That's the list of flaws attackers are actively using in the wild right now, not theoretical risks. If your business runs any of the products below, I want you to take a hard look today. Federal agencies had deadlines this week to fix several of these, and while those deadlines don't legally bind a private Texas small business, they're a loud signal about how urgent these are.

Let me walk you through what matters, in plain English, and what to actually do about it.

Microsoft SharePoint: Two Serious Problems

Two SharePoint flaws made the list. CVE-2026-56164 is a "Missing Authentication for Critical Function" vulnerability in SharePoint Server, and CVE-2026-58644 is a deserialization flaw. In plain terms: the first one lets an attacker access something they shouldn't have to log in for, and the second lets an attacker feed the server malicious data that it blindly trusts and executes. Both are the kind of thing that leads to full server takeover.

If you run an on-premises SharePoint Server, apply Microsoft's latest security updates immediately. If you're not sure whether you're on-prem or on Microsoft 365 (cloud), that's a five-minute question for your IT provider, and worth asking today. Cloud SharePoint is patched by Microsoft; on-prem is your responsibility.

Fortinet FortiSandbox: Two Command Injection Flaws

CVE-2026-25089 and CVE-2026-39808 are both OS command injection vulnerabilities in Fortinet FortiSandbox. Command injection means an attacker can trick the device into running their own commands on the underlying operating system, which is about as bad as it gets for a security appliance. Check your FortiSandbox version against Fortinet's advisory and update the firmware. Don't leave the management interface exposed to the internet.

SonicWall SMA1000: Patch These Now

Two SonicWall SMA1000 appliance flaws are on the list: CVE-2026-15409 (server-side request forgery) and CVE-2026-15410 (code injection). SMA1000 devices are remote-access appliances, so they sit right at your network edge, which makes them a prime target. The federal deadline for these was July 17. If you use SonicWall SMA1000 for remote access, treat this as an emergency and apply the vendor updates today.

Oracle, Microsoft ADFS, and the Older Entries

CVE-2026-46817 is an improper privilege management flaw in Oracle E-Business Suite, which can let a user gain permissions they shouldn't have. CVE-2026-56155 affects Microsoft Active Directory Federation Services (ADFS) with insufficient access control granularity, relevant if you use ADFS for single sign-on.

Two older CVEs also appeared, which is a reminder that attackers still exploit ancient bugs: CVE-2023-4346 in KNX building-automation protocol devices (an account lockout weakness), and CVE-2008-4128, a cross-site request forgery flaw in Cisco IOS that's nearly two decades old. If you're running Cisco gear that old, replacing it should already be on your roadmap.

Your Action List for Today

Most Texas small businesses I talk to won't run all ten of these products, and that's good news. But you almost certainly run one or two. Ten minutes of checking now beats a ransomware call later. If you'd like help sorting out what applies to your environment, reach out to us at BVTech and we'll walk through it with you.

Stay safe out there.
— Jordan Polasek, BVTech LLC