Critical CVE Live Watch for July 28, 2026: Exploited and High-Risk Vulnerabilities

Critical CVE Live Watch for July 28, 2026: Exploited and High-Risk Vulnerabilities

A live vulnerability watch focused on exploited flaws, critical and high-severity records, remediation deadlines, and practical patch priority.

Live verification: This briefing was assembled from public CISA, NIST NVD, GitHub, Ubuntu, Microsoft, and other official publisher feeds checked on July 28, 2026 at 6:34 am IST. Existing posts are preserved and repeated source IDs are deduplicated.

Executive summary

The current source set produced 10 relevant updates for this briefing. It includes 5 CISA Known Exploited Vulnerabilities, 5 critical records, 0 high-severity records, and 0 official publisher updates. Severity alone is not treated as proof of exposure: teams should verify products, versions, reachability, privileges, and available mitigations.

The fastest way to reduce vulnerability risk is to combine exploitation evidence with your own exposure. This briefing separates CISA KEV entries from newly published high-severity records so patch teams can see which signals carry the strongest urgency.

Top verified developments

CVE-2026-55255: Langflow cross-user flow authorization bypass

NIST NVD and CISA KEV | July 7, 2026 | Known Exploited | CVSS 8.4 | Langflow Langflow before 1.9.1

Source summary: Before version 1.9.1, an authenticated attacker could specify another user's flow ID and execute that flow. The CNA rates the…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-10. Apply the current Langflow fix and follow CISA KEV remediation guidance.

Critical CVE review: Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.

Read the current source record

CVE-2025-68686: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

CISA Known Exploited Vulnerabilities | July 27, 2026 | Known Exploited | Fortinet FortiOS

Source summary: Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-08-10. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Critical CVE review: Map the affected product to asset owners and set a validation deadline before closing remediation.

Read the current source record

CVE-2026-16812: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

CISA Known Exploited Vulnerabilities | July 27, 2026 | Known Exploited | Arista VeloCloud Orchestrator

Source summary: Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-30. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Critical CVE review: Look for exploitation indicators while patching, especially where the service was publicly reachable.

Read the current source record

CVE-2026-16232: Check Point SmartConsole Improper Authentication Vulnerability

CISA Known Exploited Vulnerabilities | July 22, 2026 | Known Exploited | Check Point SmartConsole

Source summary: Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login…

CISA lists this issue in the Known Exploited Vulnerabilities catalog, which makes confirmed exploitation the leading prioritization signal. Review the catalog due date and required action, then identify exposed assets before normal severity-only backlog work.

CISA due date: 2026-07-25. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance…

Critical CVE review: Check internet-facing and administrative instances first, then confirm the fixed version from the vendor.

Read the current source record

CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation

NIST NVD and Microsoft | July 15, 2026 | CRITICAL | CVSS 9.9 | Microsoft Windows VMSwitch

Source summary: Microsoft describes a network-reachable VMSwitch use-after-free that lets an authorized attacker elevate privileges. The Microsoft CNA rates it 9.9 Critical.

This record is a current vulnerability or package advisory. Confirm the affected version range and vendor fix before deployment, then prioritize instances that are public, privileged, or connected to sensitive data and production workflows.

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus