Cyber Risk Brief: 20 July 2026
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
This week's register is driven by July Patch Tuesday exploited zero-days and a SharePoint KEV escalation under CCCS AL26-017. Five IMMEDIATE criticals lead it: SharePoint Server CVE-2026-58644 / CVE-2026-56164 / CVE-2026-55040 with KEV deadlines of 17 and 19 July and CCCS fixed builds for Subscription Edition, 2019, and 2016 (T1); SonicWall SMA1000 SSRF and code-injection zero-days with hotfixes for 6210 / 7210 / 8200v (T2); FortiSandbox unauthenticated command injection already on CISA KEV with a 19 July federal due date (T3); AD FS elevation of privilege CVE-2026-56155 exploited as a Patch Tuesday zero-day (T4); and WordPress Core wp2shell with public exploits and early in-the-wild reports (T5). Progress ShareFile Storage Zone Controller path traversal (T6) forced an emergency shutdown with patches 5.12.5 / 6.0.2 and a reserved CVE. Zoom Workplace Windows account takeover CVE-2026-53412 (T7) is CVSS 9.8 without ITW at disclosure. Fairlife / Coca-Cola ransomware (T8) halted US production; Canadian production is not currently affected.
Threat Register: 20/07/2026
| Threat | |||||
|---|---|---|---|---|---|
| T1 | Microsoft SharePoint Server KEV Cluster (CVE-2026-58644 / CVE-2026-56164 / CVE-2026-55040) CISA and CCCS AL26-017 cover actively exploited SharePoint Server flaws: CVE-2026-58644 (deserialization RCE, CVSS 9.8, EPSS 0.01465, KEV due 19 Jul), CVE-2026-56164 (missing authentication → privilege elevation, CVSS 5.3, EPSS 0.05601, KEV due 17 Jul; added 14 Jul), and CVE-2026-55040 (weak authentication / security-feature bypass, CVSS 9.1, EPSS 0.00668). CCCS fixed builds: Subscription Edition 16.0.19725.20434, SharePoint 2019 16.0.10417.20175, SharePoint 2016 16.0.5561.1001. SharePoint 2016 and 2019 are end-of-life as of 14 July 2026 per CCCS. Distinct from prior-brief CVE-2026-45659. | 9.8 | 1.47% | Critical | Immediate |
| T2 | SonicWall SMA1000 Zero-Days (CVE-2026-15409 / CVE-2026-15410) SonicWall warned of active exploitation of two zero-day vulnerabilities in SMA1000 series Secure Mobile Access appliances: CVE-2026-15409 (server-side request forgery, CVSS 10.0, EPSS 0.01266) and CVE-2026-15410 (code injection, CVSS 7.2, EPSS 0.01486). Hotfix: 12.4.3-03453 or 12.5.0-02835 for products 6210, 7210, and 8200v. CISA KEV remediation due 17 July. CCCS published SonicWall AV26-699. | 10.0 | 1.27% | Critical | Immediate |
| T3 | Fortinet FortiSandbox Unauthenticated Command Injection (CVE-2026-39808 / CVE-2026-25089) CISA added FortiSandbox CVE-2026-39808 and CVE-2026-25089 to KEV with a BOD 26-04 remediation deadline of 19 July 2026. Both are CVSS 9.8 unauthenticated command injection; EPSS is 0.84158 and 0.36135 respectively. Fortinet shipped patches on 14 April and 9 June; Defused observed exploitation from about 16 June; CISA KEV confirmation followed on 17 July. | 9.8 | 84.16% | Critical | Immediate |
| T4 | Microsoft AD FS Elevation of Privilege (CVE-2026-56155) CVE-2026-56155 is an elevation-of-privilege vulnerability in Active Directory Federation Services caused by insufficient granularity of access control, allowing an authorized attacker to elevate privileges locally. NVD CVSS 3.1 base is 7.8; EPSS is 0.00379. It was one of the exploited zero-days in Microsoft's July 2026 Patch Tuesday (approximately 570 flaws, three zero-days per BleepingComputer). CISA KEV-listed (added 14 July). Credited to Microsoft DART (Kingston / Clark) — likely found during incident response; no public exploit detail released. | 7.8 | < 1% | Critical | Immediate |
| T5 | WordPress Core wp2shell RCE (CVE-2026-63030 / CVE-2026-60137) WordPress Core wp2shell combines CVE-2026-63030 (REST batch-route confusion enabling unauthenticated RCE, CVSS 9.8, EPSS 0.08946) and CVE-2026-60137 (SQL injection, CVSS 5.9, EPSS 0.04026). Public proof-of-concept exploits are available; watchTowr reported early in-the-wild activity. Fixed in WordPress 7.0.2 and 6.9.5; forced auto-updates were enabled for affected supported installs. | 9.8 | 8.95% | Critical | Immediate |
| T6 | Progress ShareFile Storage Zone Controller Path-Traversal Zero-Day Progress confirmed a high-severity path-traversal zero-day behind the emergency shutdown of ShareFile Storage Zone Controllers. Patches: SZC 5.12.5 and 6.0.2. Exploitation requires authenticated administrator access. A CVE identifier was reserved but not published at source time (CVSS and EPSS unavailable). Progress stated there was no indication of customer account or data compromise at the time of its statement. | — | — | High | Immediate |
| T7 | Zoom Workplace Windows Account Takeover (CVE-2026-53412) CVE-2026-53412 is an unauthenticated account-takeover vulnerability reachable via the network in Zoom Workplace for Windows, scored CVSS 9.8 with EPSS 0.00508. Affected: Zoom Workplace for Windows before 7.0.0; Zoom VDI Client before 7.0.10 / 6.6.15 / 6.5.18; Zoom Meeting SDK before 7.0.0. No in-the-wild exploitation reported at disclosure. Not on CISA KEV. CCCS published Zoom AV26-707. | 9.8 | < 1% | Critical | 7 days |
| T8 | Fairlife / Coca-Cola Ransomware — US Dairy Production Halt The Coca-Cola Company disclosed that a ransomware attack impacting its Fairlife dairy subsidiary disrupted operations and temporarily suspended production of Fairlife products across the United States. Canadian production operations are not currently affected (per BleepingComputer). An SEC Form 8-K (via BleepingComputer) states unauthorized access included production-related systems; product quality and safety were not affected; law enforcement was notified. No attribution and no confirmed data theft have been disclosed. No CVE applies. | — | — | High | Post-incident |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Strategic context
July Patch Tuesday zero-days, SharePoint under CCCS AL26-017, and KEV edge appliances
- Microsoft's July 2026 Patch Tuesday landed with exploited zero-days, including AD FS CVE-2026-56155 (T4), while CCCS AL26-017 and CISA KEV put SharePoint Server CVE-2026-58644 / CVE-2026-56164 / CVE-2026-55040 (T1) on federal clocks of 17 and 19 July — distinct from the prior-brief CVE-2026-45659 cluster. Boards still clearing last week's application KEV backlog now inherit SharePoint build verification and an AD FS role-patch decision in the same window.
- Edge and inspection appliances dominate the remaining IMMEDIATE lane: SonicWall SMA1000 CVE-2026-15409 / CVE-2026-15410 (T2, KEV due 17 Jul) and FortiSandbox CVE-2026-39808 / CVE-2026-25089 (T3, KEV due 19 Jul, EPSS 0.84158 on the lead CVE). WordPress Core wp2shell (T5) adds a public-PoC CMS RCE with early in-the-wild reports, and Progress ShareFile SZC (T6) shows a reserved-CVE path traversal that forced an emergency Storage Zone shutdown.
- Operational and collaboration exposure closes the register without over-claiming Canadian impact. Zoom Workplace Windows CVE-2026-53412 (T7) is CVSS 9.8 unauthenticated account takeover with no ITW at disclosure — a seven-day fleet upgrade. Fairlife / Coca-Cola ransomware (T8) suspended US dairy production; Canadian production is not currently affected per Coca-Cola reporting via BleepingComputer — a continuity peer case for OT and manufacturing boards, not a domestic outage claim.
Threat Actor Profiling
T1–T5 exploitation is unattributed beyond CISA KEV, vendor PSIRT, Defused, and watchTowr campaign reporting. T6 and T7 have no confirmed in-wild adversary (Progress reports no customer-compromise indication for ShareFile SZC; Zoom had no ITW at disclosure). T8 Fairlife ransomware has no public attribution. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed threat actor (SharePoint KEV exploitation) | Enterprise collaboration, On-premises SharePoint | T1190T1059T1505.003 | Internet- or network-reachable SharePoint → CVE-2026-58644 / CVE-2026-56164 / CVE-2026-55040 exploitation → RCE or privilege elevation → persistence on collaboration host. |
| T2 | Unattributed threat actor (SonicWall SMA1000 active exploitation) | Enterprise edge, Remote / mobile access | T1190T1090T1059 | Reachable SMA1000 (6210/7210/8200v) → CVE-2026-15409 SSRF and/or CVE-2026-15410 code injection → admin command path → foothold on remote-access edge. |
| T3 | Unattributed threat actor (FortiSandbox exploitation — Defused / CISA KEV) | Security inspection, Malware analysis infrastructure | T1190T1059 | Unauthenticated command injection against FortiSandbox (CVE-2026-39808 / CVE-2026-25089) → remote command execution → compromise of sandbox trust boundary (exploitation observed ~16 Jun per Defused; CISA KEV 17 Jul). |
| T4 | Unattributed threat actor (AD FS exploited zero-day — DART discovery) | Identity / federation, Enterprise Microsoft | T1068T1078 | Authorized local foothold on AD FS host → CVE-2026-56155 insufficient access-control granularity → local privilege elevation → potential abuse of federation token issuance (exploit detail not public; DART credited). |
| T5 | Unattributed threat actor (wp2shell — public PoC / early ITW per watchTowr) | Web / CMS, Marketing and public sites | T1190T1505.003T1059 | Unauthenticated REST batch-route confusion (CVE-2026-63030) and/or SQLi (CVE-2026-60137) → RCE on WordPress Core → webshell / site takeover (public PoC; early ITW per watchTowr). |
| T6 | No confirmed adversary (ShareFile SZC — Progress reports no customer compromise indication) | File transfer / ShareFile, Enterprise content collaboration | T1078T1083T1005 | Authenticated ShareFile SZC administrator → path-traversal zero-day → unauthorized filesystem access outside intended storage roots (CVE reserved; Progress: no indication of customer compromise at statement time). |
| T7 | No confirmed adversary (Zoom CVE-2026-53412 — no ITW at disclosure) | Enterprise collaboration, Remote work | T1190T1078 | n/a — no ITW at disclosure; hypothetical path is unauthenticated network exploitation of CVE-2026-53412 against Zoom Workplace Windows / VDI / Meeting SDK → account takeover. |
| T8 | Unattributed ransomware operator (Fairlife / Coca-Cola — no public attribution) | Food & beverage manufacturing, OT / production | T1486T1490 | Initial access (vector not publicly confirmed) → unauthorized access including production-related systems → US Fairlife production suspension; product quality/safety not affected; no attribution / no confirmed data theft disclosed. |
▶Table methodology & sourcing notes
- Actors are named only where a source attributes the incident; otherwise “unattributed.” No named ransomware group is attributed for Fairlife (T8). ShareFile SZC (T6) and Zoom (T7) have no confirmed in-wild adversary at source time — additional techniques beyond published reporting would be inference.
- All CVSS, EPSS, and KEV values were verified directly against NVD, the FIRST EPSS API, and the CISA KEV catalog (2026-07-19); they are not carried from secondary reporting. ShareFile SZC (T6) and Fairlife (T8) have no published CVE — cvss and epss are null.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Microsoft SharePoint Server KEV Cluster (CVE-2026-58644 / CVE-2026-56164 / CVE-2026-55040) |
| A.8.8, A.8.9, A.8.20, A.8.16, A.5.15 | ID.AM-01, ID.RA-01, PR.PS-01, PR.PS-02, DE.CM-01 | CIS 1, CIS 7, CIS 12, CIS 13 | — | SI-2, RA-5, SC-7, CM-7 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T2SonicWall SMA1000 Zero-Days (CVE-2026-15409 / CVE-2026-15410) |
| A.8.8, A.8.9, A.8.20, A.5.15, A.8.16 | ID.AM-01, PR.PS-01, PR.AA-01, DE.CM-01, RS.MI-01 | CIS 1, CIS 7, CIS 12, CIS 5 | — | SI-2, RA-5, SC-7, AC-17 | B-13 Patch Mgmt, B-13 Vulnerability Management, B-13 Access Control | — |
T3Fortinet FortiSandbox Unauthenticated Command Injection (CVE-2026-39808 / CVE-2026-25089) |
| A.8.8, A.8.9, A.8.20, A.8.16, A.5.15 | ID.AM-01, ID.RA-01, PR.PS-02, DE.CM-01, RS.MI-01 | CIS 1, CIS 7, CIS 12, CIS 13 | — | SI-2, RA-5, SC-7, SI-4 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T4Microsoft AD FS Elevation of Privilege (CVE-2026-56155) |
| A.8.8, A.5.15, A.5.16, A.8.2, A.8.5 | PR.AA-01, PR.AA-05, PR.PS-02, ID.RA-01, DE.CM-09 | CIS 5, CIS 6, CIS 7, CIS 8 | — | SI-2, AC-6, IA-2, AU-6 | B-13 Patch Mgmt, B-13 Access Control, B-13 Governance | — |
T5WordPress Core wp2shell RCE (CVE-2026-63030 / CVE-2026-60137) |
| A.8.8, A.8.9, A.8.25, A.8.16, A.5.19 | ID.AM-02, PR.PS-01, DE.CM-01, DE.CM-09, RS.MI-01 | CIS 2, CIS 7, CIS 16, CIS 13 | — | SI-2, RA-5, CM-7, SI-3 | B-13 Patch Mgmt, B-13 Vulnerability Management | — |
T6Progress ShareFile Storage Zone Controller Path-Traversal Zero-Day |
| A.8.8, A.5.15, A.5.19, A.8.12, A.8.16 | ID.AM-02, PR.AA-01, PR.PS-02, GV.SC-05, DE.CM-09 | CIS 2, CIS 5, CIS 7, CIS 15 | — | SI-2, AC-3, SA-12, AU-6 | B-13 Third-Party Risk, B-13 Patch Mgmt, B-13 Access Control | — |
T7Zoom Workplace Windows Account Takeover (CVE-2026-53412) |
| A.8.8, A.5.16, A.8.5, A.8.16, A.8.9 | ID.AM-02, PR.PS-02, PR.AA-01, DE.CM-09, ID.RA-01 | CIS 2, CIS 7, CIS 5, CIS 8 | — | SI-2, CM-7, IA-2, AC-17 | B-13 Patch Mgmt, B-13 Access Control | — |
T8Fairlife / Coca-Cola Ransomware — US Dairy Production Halt |
| A.5.24, A.5.29, A.5.30, A.8.13, A.8.22 | RS.MI-01, RC.RP-01, PR.DS-11, ID.RA-01, GV.OC-03 | CIS 11, CIS 17, CIS 12, CIS 6 | — | CP-9, CP-10, IR-4, IR-6 | B-13 Governance, B-13 Access Control | — |
Privacy Act / PIPEDA & OSFI: T8 (Fairlife) has no confirmed personal-data theft disclosed — do not assert PIPEDA notification from this brief alone. T1 SharePoint carries CCCS AL26-017 plus CISA KEV deadlines (17/19 Jul). T2–T4 carry CISA KEV clocks (SonicWall due 17 Jul; FortiSandbox due 19 Jul; AD FS KEV). OSFI B-13 patch and third-party-risk expectations apply to federally regulated financial institutions reviewing SharePoint, SMA1000, FortiSandbox, AD FS, and ShareFile SZC estates (T1–T4, T6).
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1 · T2 · T3SharePoint AL26-017 + SMA1000 + FortiSandbox KEV clocks (17/19 Jul)
CCCS AL26-017 and CISA KEV put SharePoint builds, SonicWall SMA1000 hotfixes, and FortiSandbox April/June patches on dual federal deadlines this window. Boards should treat 17 and 19 July as the external citation for emergency change control on collaboration and edge appliances — not a staggered backlog.
- T4 · T5AD FS exploited zero-day + WordPress wp2shell public PoC
Patch Tuesday zero-day CVE-2026-56155 on AD FS (KEV) and WordPress Core wp2shell with public exploits and early ITW compress identity and CMS estates onto the same IMMEDIATE clock as edge KEV.
- T6ShareFile SZC — reserved CVE, vendor-forced shutdown
Progress halted Storage Zone Controllers then shipped 5.12.5 / 6.0.2. Waiting for CVE publication is not a remediation strategy when the vendor already treated the flaw as production-stopping.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T8Fairlife — US production suspended after ransomware
Coca-Cola disclosed unauthorized access including production-related systems; US Fairlife production halted; product quality/safety not affected. Canadian production not currently affected. No attribution; no confirmed data theft disclosed.
- T2 · T3 · T5Active exploitation confirmed — SMA1000, FortiSandbox, wp2shell
SonicWall PSIRT reports SMA1000 zero-day exploitation; Defused observed FortiSandbox exploitation from ~16 Jun with CISA KEV 17 Jul; watchTowr reported early wp2shell ITW alongside a public PoC.
Structural control deficiencies revealed by the day's threats, independent of any single exploit.
- T1SharePoint 2016/2019 EOL vs KEV build floors
CCCS marks SharePoint 2016/2019 EOL as of 14 Jul 2026 while requiring fixed builds under AL26-017. Patching EOL platforms without a migration decision is temporary risk acceptance — boards need both.
- T6Reserved-CVE zero-days deferred by vulnerability process
ShareFile SZC shows programmes that only act on published CVE IDs miss vendor-forced outages. Emergency authority must attach to credible vendor shutdowns, not only NVD entries.
- T4 · T7Identity and collaboration clients outside OS patch rings
AD FS roles and Zoom VDI/SDK estates often miss workstation Patch Tuesday coverage. Federation servers and collaboration clients need named owners and distinct SLAs.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1 · T4July Patch Tuesday + SharePoint under CCCS AL26-017
Exploited Microsoft zero-days (AD FS) and a three-CVE SharePoint KEV cluster with Canadian advisory AL26-017 define this week's identity and collaboration spine. Boards should demand build evidence for SharePoint and AD FS before the 17/19 July clocks — distinct from prior-brief CVE-2026-45659.
- T8Manufacturing ransomware as continuity — not just IT
Fairlife's US production halt with Canadian ops not currently affected is a peer case for OT segmentation and immutable restore. Product safety preserved does not equal business continuity preserved.
Remediation Actions
Consolidated actions across all eight threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1Apply CCCS AL26-017 fixed builds (SE 16.0.19725.20434 / 2019 16.0.10417.20175 / 2016 16.0.5561.1001); meet KEV deadlines 17 Jul (56164) and 19 Jul (58644) or document exceptions; hunt webshells.
- T2T3Hotfix SMA1000 to 12.4.3-03453 or 12.5.0-02835 (or disconnect); apply FortiSandbox Apr/Jun patches; meet KEV due 17 Jul (SMA) and 19 Jul (FortiSandbox).
- T4T5T6Patch AD FS for CVE-2026-56155; upgrade WordPress to 7.0.2 / 6.9.5; upgrade ShareFile SZC to 5.12.5 / 6.0.2 before restoring services.
7 days
Short-term hardening
- T7Upgrade Zoom Workplace Windows to 7.0.0+; VDI to 7.0.10 / 6.6.15 / 6.5.18+; Meeting SDK to 7.0.0+; inventory VDI/SDK outside desktop auto-update.
- T1Document SharePoint 2016/2019 EOL (14 Jul 2026 per CCCS) migration decisions; remove unnecessary internet exposure; verify every farm against AL26-017 builds.
- T8Peer manufacturing: verify OT/IT segmentation, immutable restore of production-adjacent systems, and MFA on plant remote access — Canada not currently affected is not a deferral.
14 – 30 days
Programme remediation
- T5Inventory all public WordPress estates (including marketing/agency); assign emergency patch owners; audit for webshells and unexpected admins post-wp2shell.
- T6Add ShareFile SZC and peer file-transfer controllers to crown-jewel inventory with MFA-enforced admin access and path-traversal hunt playbooks.
- T4Map every AD FS role to a named owner; rehearse federation-server emergency patch with the same authority as domain controllers.
Ongoing
Structural controls
- T1T2T3Keep SharePoint, SMA1000, and FortiSandbox on the same emergency disconnect-or-patch SLA as VPN concentrators — with CCCS/KEV evidence in change records.
- T6Treat reserved-CVE vendor shutdowns as first-class emergencies: patch on vendor build floors without waiting for NVD publication.
- T7T8Govern Zoom VDI/SDK fleets and OT ransomware readiness with named owners, seven-day client SLAs, and production-halt playbooks evidenced.
Provenance
Intelligence Sources
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →