Bastion Codex – Weekly Defender Brief (2026-07-27)
This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.
The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.
Bastion Codex – Weekly Defender Brief
Week of 2026-07-27
Executive Snapshot
- 2784 CVEs observed in the last 7 days
- 420 Critical
- 1066 High
- 7 KEV-listed vulnerabilities in last 30 days
Week-over-Week Movement
- Total CVEs: 217 (from 2567 to 2784, 8.5%)
- Critical: 194 (from 226 to 420, 85.8%)
- High: -66 (from 1132 to 1066, -5.8%)
- Medium: 84 (from 677 to 761, 12.4%)
- Low: 25 (from 79 to 104, 31.6%)
- Unknown: -20 (from 453 to 433, -4.4%)
Defender Takeaways
- Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
- Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
- High severity volume suggests increased patch workload. Focus on internet-exposed services first.
Severity Breakdown (7 Days)
- Critical: 420
- High: 1066
- Medium: 761
- Low: 104
- Unknown: 433
Top Vendors (30 Days)
- WordPress: 2
- Balbooa: 1
- Check Point: 1
- DD-WRT: 1
- Joomlack: 1
- Microsoft: 1
Top Products (30 Days)
- Core: 2
- DD-WRT: 1
- Forms: 1
- Page Builder: 1
- SharePoint: 1
- SmartConsole: 1
Priority Watchlist (Top 10)
- CVE-2026-34908 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi OS devices to make unauth
- CVE-2026-34909 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the u
- CVE-2026-34910 | CVSS: 10.0 | KEV: True | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a
- CVE-2026-10520 | CVSS: 10.0 | KEV: True | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
- CVE-2026-0770 | CVSS: 9.8 | KEV: True | Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allow
- CVE-2026-35616 | CVSS: 9.8 | KEV: True | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unau
- CVE-2026-9082 | CVSS: 9.8 | KEV: True | Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Drupal Drupal core allows SQL Injectio
- CVE-2026-48172 | CVSS: 9.8 | KEV: True | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detectio
- CVE-2026-45247 | CVSS: 9.8 | KEV: True | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticat
- CVE-2026-46817 | CVSS: 9.8 | KEV: True | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecte
Generated via Bastion Codex pipeline at 2026-07-27T14:59:50.668887+00:00