Bastion Codex – Weekly Defender Brief (2026-07-27)


This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.

The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.


Bastion Codex – Weekly Defender Brief

Week of 2026-07-27

Executive Snapshot

  • 2784 CVEs observed in the last 7 days
  • 420 Critical
  • 1066 High
  • 7 KEV-listed vulnerabilities in last 30 days

Week-over-Week Movement

  • Total CVEs: 217 (from 2567 to 2784, 8.5%)
  • Critical: 194 (from 226 to 420, 85.8%)
  • High: -66 (from 1132 to 1066, -5.8%)
  • Medium: 84 (from 677 to 761, 12.4%)
  • Low: 25 (from 79 to 104, 31.6%)
  • Unknown: -20 (from 453 to 433, -4.4%)

Defender Takeaways

  • Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
  • Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
  • High severity volume suggests increased patch workload. Focus on internet-exposed services first.

Severity Breakdown (7 Days)

  • Critical: 420
  • High: 1066
  • Medium: 761
  • Low: 104
  • Unknown: 433

Top Vendors (30 Days)

  • WordPress: 2
  • Balbooa: 1
  • Check Point: 1
  • DD-WRT: 1
  • Joomlack: 1
  • Microsoft: 1

Top Products (30 Days)

  • Core: 2
  • DD-WRT: 1
  • Forms: 1
  • Page Builder: 1
  • SharePoint: 1
  • SmartConsole: 1

Priority Watchlist (Top 10)

  • CVE-2026-34908 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
  • CVE-2026-34909 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u
  • CVE-2026-34910 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a
  • CVE-2026-10520 | CVSS: 10.0 | KEV: True | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
  • CVE-2026-0770 | CVSS: 9.8 | KEV: True | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allow
  • CVE-2026-35616 | CVSS: 9.8 | KEV: True | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unau
  • CVE-2026-9082 | CVSS: 9.8 | KEV: True | Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Drupal Drupal core allows SQL Injectio
  • CVE-2026-48172 | CVSS: 9.8 | KEV: True | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detectio
  • CVE-2026-45247 | CVSS: 9.8 | KEV: True | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticat
  • CVE-2026-46817 | CVSS: 9.8 | KEV: True | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecte

Generated via Bastion Codex pipeline at 2026-07-27T14:59:50.668887+00:00