Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Report: Exploit of high-impact vulnerabilities soared in July, with older flaws still all too prevalent

Researchers tracked 85 actively exploited CVEs impacting more than 60 vendors last month, with one at least 18 years old!

Thu, 13 Aug 2026
Report: Exploit of high-impact vulnerabilities soared in July, with older flaws still all too prevalent

July saw a sizeable increase in the number of high-impact vulnerabilities reported, with a 44 per cent increase over the prior month.

According to the cyber security firm Recorded Future’s Insikt Group, 85 serious vulnerabilities were reported in July, 36 of which were rated Very Critical.

Microsoft accounted for 12 per cent of all those reported, but overall, 61 vendors were represented in the list.

 
 

Alexander Leslie, Senior Government Affairs Advisor at Recorded Future, said the increase in serious vulnerabilities in a wider range of technologies was making patching ever more challenging.

"We identified 85 vulnerabilities to prioritise for remediation, up from 59 in June. Of those, 57 enabled remote code execution, and 60 had public proof-of-concept code or scanners available. This gives threat actors more opportunities to target exposed systems and leaves security teams with less time to assess which vulnerabilities are relevant to their environment,” Leslie told Cyber Daily.

“One of the more concerning findings is the speed at which some vulnerabilities are being exploited. The shortest observed period between public disclosure and reported exploitation was less than one day.”

Leslie was also concerned about the impact of older vulnerabilities. 14 of July’s vulnerabilities were at least five years old, while one dated back about 18.

“Organisations are therefore managing newly disclosed vulnerabilities alongside flaws that have remained unpatched for years,” Leslie said.

“This makes it important to review risk continuously as new evidence of exploitation becomes available.”

Every vulnerability researched by the Insikt Group was exploited or operationally weaponised, with China-linked actors paying particular attention to CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus Ethernet devices. Email, document, and collaboration platforms were also targeted for more focused espionage and payload delivery.

Leslie also noted that CVE-2026-48907, a critical remote code execution flaw in an extension for the Joomla content management system, was of particular concern for ANX organisations.

“Our honeypot data identified related activity 21 days before the vulnerability was flagged in an Australian Cyber Security Centre warning,” Leslie said.

“This shows how direct observations of exploitation can provide earlier indications of risk and support remediation decisions before a vulnerability is reflected in formal guidance. That additional time can be significant for internet-facing systems that may already be receiving attention from threat actors."

A full list of July's exploited vulnerabilities can be found here.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: