Nearly a third of July's exploited bugs predate 2025

Recorded Future's Insikt Group has published its monthly rundown of the vulnerabilities defenders should fix first, and the most striking thing about July 2026 is how old much of the list is. Of the 81 flaws the firm published, 25 predate 2025 and 21 date from 2021 or earlier. The oldest, a Cisco IOS flaw first catalogued in 2008, sits in the report's top risk band alongside brand new Microsoft SharePoint and Langflow bugs.

Insikt Group identified 85 high-impact vulnerabilities that should be prioritized for remediation in July, 36 of which carried what the firm calls a Very Critical Recorded Future Risk Score, which it says is a 44 percent increase from the previous month. Twenty-six were surfaced through the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four came primarily from Recorded Future's own honeypot data. Those four are held back for the firm's customers, which is why the public table lists 81 rather than 85.

Old kit, still worth attacking

Recorded Future says all 81 vulnerabilities in the published table were actively exploited or operationally weaponized during July. A large share of them are in consumer and small-office hardware that in many cases is long past end of life: Huawei's HG532 router, DD-WRT, several Linksys and Tenda models, DrayTek Vigor gateways, TOTOLINK routers, a Shenzhen Aitemi Wi-Fi repeater, and digital video recorders from MVPower and UNIMO. Ruckus wireless kit, Cambium cnPilot access points and ASUSTOR storage appliances also appear.

That pattern is the practical takeaway. A bug does not stop being useful to an attacker because it is old. It stops being useful when the vulnerable device is gone. Kit that nobody inventories, nobody patches and nobody has replaced keeps these entries alive year after year. It also fits what other researchers have reported about how fast attackers pick up whatever is available, including CrowdStrike's finding that most public exploits are weaponized within 48 hours.

What's affected

The 85 vulnerabilities span products from 61 vendors, with Microsoft accounting for approximately 12 percent of them. Beyond the aging home gear, the enterprise side of the list includes Microsoft SharePoint, Exchange Server and Active Directory Federation Services, Apache Tomcat, Oracle E-Business Suite, Adobe ColdFusion, Fortinet FortiOS and FortiSandbox, SonicWall SMA1000 appliances, Check Point SmartConsole, Palo Alto Networks PAN-OS and Prisma Access, NetScaler ADC and Gateway, ServiceNow AI Platform, WordPress core, a cluster of Joomla extensions, and Langflow, which we covered when CISA added it to the KEV catalog. SharePoint's presence follows our earlier reporting that attackers can keep access to SharePoint servers after patching.

What you should do

The report is a prioritization list rather than a technical teardown, so treat each vendor's advisory as the authority on what a given flaw does and how to fix it. Cross-check the list against your own asset inventory, and pay particular attention to network edge devices and DVRs, where the fix is often replacement rather than a patch. Recorded Future also flags public proof-of-concept code for many entries and warns that those PoCs were not tested for accuracy or efficacy, so verify them before running anything in a live environment.

The full table, including risk scores and per-entry notes, is in Insikt Group's July 2026 CVE Landscape report.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions