Back to Blog

The most hyped CVEs of July 2026: what made noise, what's being exploited

Key Points

TL;DR

  • Two vulnerabilities mattered most in July and both landed in CISA KEV: the wp2shell WordPress chain (CVE-2026-63030 + CVE-2026-60137) and a SharePoint deserialization bug (CVE-2026-50522). 
  • The rest of July's KEV additions sat in specific enterprise and appliance kit: Oracle E-Business Suite, SonicWall SMA1000, Adobe ColdFusion, Arista VeloCloud, FortiSandbox, Joomla add-ons, and on-prem SharePoint.
  • The loudest vuln that wasn't exploitable from remote: Windows AppLocker (CVE-2024-21338) trended, but it needs local access first.

July saw a familiar pattern in vulnerability tracking: mass-market software bug chains drew huge attention, while critical remote code execution flaws in enterprise appliances quietly landed on active exploitation lists. If you haven't reviewed your external perimeter updates from earlier this month, here is what trended across the security community, and what entered CISA's Known Exploited Vulnerabilities (KEV) catalog this month.

CVE-2026-63030 and CVE-2026-60137: WordPress core, unauthenticated RCE (wp2shell)

What is wp2shell?

wp2shell is the nickname for a two-bug chain in WordPress core, CVE-2026-63030 and CVE-2026-60137, that lets an unauthenticated attacker take over a stock WordPress site.

What happened

wp2shell lit up security feeds in mid-July, with hype peaking at 32, unusually low for a bug of this size but likely a quirk of the algorithm prioritising activity mentioning CVEs, not vulns with nicknames. The chain is rated critical (CVSS 9.8), and both CVEs were added to the CISA KEV catalog on 21 July 2026 after widespread active exploitation was detected. WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are affected.

Intruder's verdict

wp2shell chains two WordPress core bugs into unauthenticated remote code execution on a stock install. CVE-2026-63030, a route confusion bug in the REST API batch endpoint, bypasses authentication; CVE-2026-60137, a WP_Query SQL injection that has limited impact on its own, becomes essential in the full RCE chain as it gets used to poison a cache. Together the two bugs alongside some other WordPress quirks allow an  exploit chain to achieve code execution. No plugins or configuration required, on software running roughly 43% of the web.

Read more

Our full breakdown, what wp2shell teaches us about vulnerability management, or the live status on cvemon (CVE-2026-63030, CVE-2026-60137).

CVE-2026-50522: Microsoft SharePoint, unauthenticated RCE

What is CVE-2026-50522?

CVE-2026-50522 is a deserialization flaw in on-premises Microsoft SharePoint Server that lets an unauthenticated attacker reach code execution over the network.

What happened

Following Microsoft's July 2026 Patch Tuesday release, public exploit code surfaced for a critical deserialization flaw in SharePoint Server (CVSS 9.8). The flaw allows network-based code execution without prior credentials and was subsequently added to the KEV catalog (22 July). This bug stands out for another reason, because it got published on NVD almost a year to the day since ToolShell, another unauthenticated deserialisation bug in the same product allowing RCE from remote.

Intruder's verdict

This vulnerability allows an unauthenticated attacker who can access a Sharepoint instance to gain code execution. A patch has been available since July 14th in Microsoft's 'Patch Tuesday' security rollup. A proof of concept exploit has recently been published and this makes patching more urgent as attacks have now been seen in the wild.

Read more

Full activity history on cvemon.

More CISA KEV additions from July 2026

Everything below was added to CISA KEV in July, which means confirmed active exploitation. Unlike wp2shell, these live in specific enterprise and appliance kit, so how much they matter depends on your stack.

Another handful hit KEV in July too (Cisco Secure FMC, Check Point SmartConsole, Langflow, Fortinet FortiOS, Microsoft AD FS, KNX, and a 2008 Cisco IOS CSRF, CVE-2008-4128). The full month is on cvemon.

Loud, but you need a foothold first

An older Windows AppLocker vulnerability (CVE-2024-21338) re-trended on social feeds with a hype score of 30, but a patch has long since been available and it requires low-privileged local code execution first to escalate privileges. It's also a February 2024 bug that CISA added to KEV on 4 March 2024.

The takeaway

Only one new bug this month was both loud and actually being exploited: wp2shell. The rest of the exploited criticals showed up quietly, in SD-WAN orchestrators, ERP suites, and appliance management consoles, the kind of infrastructure that more rarely trends but is very much worth watching. That's the gap continuous exposure management is built to close: emerging threats get flagged across your attack surface as checks become available, without waiting for someone to spot the headline and kick off a scan. See what's trending now on cvemon.

Get our free

Ultimate Guide to Vulnerability Scanning

Learn everything you need to get started with vulnerability scanning and how to get the most out of your chosen product with our free PDF guide.