3 exploited vulnerabilities due in 2 days—one in Cisco IOS

Share
3
added to KEV
0
used in ransomware
2026-07-13
nearest federal deadline

This week, 3 new vulnerabilities entered the federal patching deadline list. The nearest due date is July 16, 2026—two days away. One affects Cisco network infrastructure directly. The others target web applications. None have known ransomware use yet, but all are actively exploited in the wild.

Showcase Vulnerability

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

What it is: Cisco IOS 12.4 contains multiple cross-site request forgery (CSRF) flaws in the web-based management interface.

Who it affects: Any organization running Cisco IOS 12.4 with HTTP management enabled.

What an attacker gets: Remote execution of arbitrary commands on the device—including privilege escalation to level 15 (administrative access) and configuration changes.

Required action: Apply vendor mitigations immediately. If mitigations are unavailable, discontinue use of the product or isolate it from untrusted networks. Evaluate internet exposure of each affected asset.

Due date: July 16, 2026.

Other Exploited Vulnerabilities Added This Week

2 other exploited vulnerabilities were added this week:

  • Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
  • iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

The question you now face: Do any of these run in your environment, and in what order should your team address them before the federal deadline passes?


Before you go — here's the 30-second version for your stack.

Everything CISA flagged this week fell into just a few buckets: 2 web & CMS (Balbooa, iCagenda) and 1 network & perimeter (Cisco).

So if you don't run web & CMS or network & perimeter, this week is a no-op for you. Close this email and get on with your day — nothing here is yours. If you do run one of them, the deadline is 2026-07-16.

That paragraph you just read — "this week is a no-op for you" — is the entire product. Most weeks, most of the catalog isn't yours. Knowing which part is, in 30 seconds, without reading a vulnerability database, is what you're actually short of.

ClickSecurity Pro does it precisely instead of roughly: you tell us your stack once, and each week you get only what touches your gear — ranked by what to fix first, with the fixed version and the federal deadline. No triage, no catalog, no guessing.

Filter next week to my stack — $5/mo

Not ready? Tell us what you run and we'll at least stop sending you things that aren't yours.

Read more

Federal Contract Alert: Next Generation Ammunition & Munitions Equipment (NGAME) for MMHE RFP/Solicitation — DEPT OF DEFENSE.DEPT OF THE AIR FORCE.AIR FORCE MAT

NGAME MMHE RFP: What This Opportunity Actually Is The Air Force Life Cycle Management Center (AFLCMC) is seeking Next Generation Ammunition & Munitions Handling Equipment (NGAME) for Munitions Maintenance & Handling Equipment (MMHE). This is a production and/or engineering contract aimed at modernizing how the Air Force stores, transports,

By abdul wahib

Federal Contract Alert: J--Landing craft rehabilitation, Lake Roosevelt NRA. — INTERIOR, DEPARTMENT OF THE.NATIONAL PARK SERVICE.PWR OLYM MABO(83000)

What You're Looking At: Landing Craft Rehab at Lake Roosevelt The National Park Service (Power, Olympics & Mountaineer Area Office) is seeking a contractor to rehabilitate landing craft operated at Lake Roosevelt National Recreation Area in Washington State. This is straightforward marine vessel maintenance and repair work—hull

By abdul wahib