Bastion Codex – Weekly Defender Brief (2026-07-20)


This weekly defender brief summarizes vulnerability movement observed over the past 7 and 30 days.

The goal is simple: highlight signal that matters to frontline defenders — patch workload pressure, severity shifts, and KEV movement.


Bastion Codex – Weekly Defender Brief

Week of 2026-07-20

Executive Snapshot

  • 2567 CVEs observed in the last 7 days
  • 226 Critical
  • 1132 High
  • 5 KEV-listed vulnerabilities in last 30 days

Week-over-Week Movement

  • Total CVEs: 922 (from 1645 to 2567, 56.0%)
  • Critical: 111 (from 115 to 226, 96.5%)
  • High: 536 (from 596 to 1132, 89.9%)
  • Medium: 24 (from 653 to 677, 3.7%)
  • Low: 7 (from 72 to 79, 9.7%)
  • Unknown: 244 (from 209 to 453, 116.7%)

Defender Takeaways

  • Elevated volume of Critical vulnerabilities this week. Prioritize external-facing asset review.
  • Recently added KEV vulnerabilities detected. Review CISA remediation timelines.
  • High severity volume suggests increased patch workload. Focus on internet-exposed services first.

Severity Breakdown (7 Days)

  • Critical: 226
  • High: 1132
  • Medium: 677
  • Low: 79
  • Unknown: 453

Top Vendors (30 Days)

  • Microsoft: 3
  • SonicWall: 2

Top Products (30 Days)

  • SMA1000 Appliances: 2
  • Active Directory Federation Services: 1
  • SharePoint: 1
  • SharePoint Server: 1

Priority Watchlist (Top 10)

  • CVE-2024-1212 | CVSS: 10.0 | KEV: True | Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execut
  • CVE-2026-15409 | CVSS: 10.0 | KEV: True | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticat
  • CVE-2024-11680 | CVSS: 9.8 | KEV: True | ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit
  • CVE-2025-3248 | CVSS: 9.8 | KEV: True | Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated atta
  • CVE-2025-10585 | CVSS: 9.8 | KEV: True | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted
  • CVE-2026-39808 | CVSS: 9.8 | KEV: True | A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 4.4.0 th
  • CVE-2026-42208 | CVSS: 9.8 | KEV: True | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a datab
  • CVE-2026-46817 | CVSS: 9.8 | KEV: True | Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecte
  • CVE-2026-25089 | CVSS: 9.8 | KEV: True | A improper neutralization of special elements used in an os command (‘os command injection’) vulnerability in Fortinet FortiSandbox 5.0.0 th
  • CVE-2026-58644 | CVSS: 9.8 | KEV: True | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Generated via Bastion Codex pipeline at 2026-07-20T16:46:31.780748+00:00