Bastion Codex – Weekly Defender Brief (2026-07-20)
This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.
The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.
Bastion Codex – Weekly Defender Brief
Week of 2026-07-20
Executive Snapshot
- 2567 CVEs observed in the last 7 days
- 226 Critical
- 1132 High
- 5 KEV-listed vulnerabilities in last 30 days
Week-over-Week Movement
- Total CVEs: 922 (from 1645 to 2567, 56.0%)
- Critical: 111 (from 115 to 226, 96.5%)
- High: 536 (from 596 to 1132, 89.9%)
- Medium: 24 (from 653 to 677, 3.7%)
- Low: 7 (from 72 to 79, 9.7%)
- Unknown: 244 (from 209 to 453, 116.7%)
Defender Takeaways
- Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
- Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
- High severity volume suggests increased patch workload. Focus on internet-exposed services first.
Severity Breakdown (7 Days)
- Critical: 226
- High: 1132
- Medium: 677
- Low: 79
- Unknown: 453
Top Vendors (30 Days)
- Microsoft: 3
- SonicWall: 2
Top Products (30 Days)
- SMA1000 Appliances: 2
- Active Directory Federation Services: 1
- SharePoint: 1
- SharePoint Server: 1
Priority Watchlist (Top 10)
- CVE-2024-1212 | CVSS: 10.0 | KEV: True | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execut
- CVE-2026-15409 | CVSS: 10.0 | KEV: True | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticat
- CVE-2024-11680 | CVSS: 9.8 | KEV: True | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit
- CVE-2025-3248 | CVSS: 9.8 | KEV: True | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated atta
- CVE-2025-10585 | CVSS: 9.8 | KEV: True | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted
- CVE-2026-39808 | CVSS: 9.8 | KEV: True | A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 4.4.0 th
- CVE-2026-42208 | CVSS: 9.8 | KEV: True | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a datab
- CVE-2026-46817 | CVSS: 9.8 | KEV: True | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecte
- CVE-2026-25089 | CVSS: 9.8 | KEV: True | A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 5.0.0 th
- CVE-2026-58644 | CVSS: 9.8 | KEV: True | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Generated via Bastion Codex pipeline at 2026-07-20T16:46:31.780748+00:00