3 exploited vulnerabilities added this week—patch Cisco IOS by July 16
| 3 added to KEV |
0 used in ransomware |
2026-07-13 nearest federal deadline |
CISA added 3 newly exploited vulnerabilities to the Known Exploited Vulnerabilities catalog this week. None carry active ransomware tags, but all three require immediate attention under federal BOD 26-04 patching deadlines.
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery
Cisco IOS 12.4 contains multiple CSRF vulnerabilities that allow remote attackers to execute arbitrary commands. An attacker can craft malicious requests targeting the /level/15/exec/- and /level/15/exec/-/configure/http URIs to escalate privileges and run commands without authentication. If your organization runs Cisco IOS 12.4, apply vendor mitigations immediately. Due date: July 16, 2026. If mitigations are unavailable, discontinue use of the product per BOD 26-04 guidance.
2 other exploited vulnerabilities were added this week:
- Balbooa — Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
- iCagenda — iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
Your immediate question: which of these three vulnerabilities exist in the software your organization actually runs, and which poses the highest risk to remediate first? Start by inventorying Cisco IOS instances and checking your Balbooa and iCagenda deployments against the full CVE list at cisa.gov/known-exploited-vulnerabilities.
You just read what happened. Pro tells you what to do about it.
Every week we get the same question: "Which of these actually affect the software I run?" ClickSecurity Pro answers it — you tell us your stack once, and each week you get only the vulnerabilities that hit your gear, ranked by what to patch first, with the exact fixed version and the federal compliance deadline.
The other 2 this week? Pro members already know which ones they can ignore.
Get stack-filtered alerts — $5/mo or tell us your stack first →