Skip to content

Commit 3640bfb

Browse files
Update KEV: Sat Jul 11 00:26:57 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent b5f17e5 commit 3640bfb

1 file changed

Lines changed: 33 additions & 3 deletions

File tree

known_exploited_vulnerabilities.json

Lines changed: 33 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,39 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2026.07.07",
4-
"dateReleased": "2026-07-07T18:28:17.8926Z",
5-
"count": 1635,
3+
"catalogVersion": "2026.07.10",
4+
"dateReleased": "2026-07-10T17:00:25.7327Z",
5+
"count": 1637,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2026-56291",
9+
"vendorProject": "Balbooa",
10+
"product": "Forms",
11+
"vulnerabilityName": "Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
12+
"dateAdded": "2026-07-10",
13+
"shortDescription": "Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.",
14+
"requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
15+
"dueDate": "2026-07-13",
16+
"knownRansomwareCampaignUse": "Unknown",
17+
"notes": "https:\/\/www.balbooa.com\/joomla-forms ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-56291",
18+
"cwes": [
19+
"CWE-434"
20+
]
21+
},
22+
{
23+
"cveID": "CVE-2026-48939",
24+
"vendorProject": "iCagenda",
25+
"product": "iCagenda",
26+
"vulnerabilityName": "iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability",
27+
"dateAdded": "2026-07-10",
28+
"shortDescription": "iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.",
29+
"requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
30+
"dueDate": "2026-07-13",
31+
"knownRansomwareCampaignUse": "Unknown",
32+
"notes": "https:\/\/www.icagenda.com\/#download ; BOD 26-04: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https:\/\/www.cisa.gov\/news-events\/directives\/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-48939",
33+
"cwes": [
34+
"CWE-434"
35+
]
36+
},
737
{
838
"cveID": "CVE-2026-48908",
939
"vendorProject": "JoomShaper",

0 commit comments

Comments
 (0)