3 exploited vulnerabilities due in 2 days—one in Cisco IOS
| 3 added to KEV |
0 used in ransomware |
2026-07-13 nearest federal deadline |
This week, 3 new vulnerabilities entered the federal patching deadline list. The nearest due date is July 16, 2026—two days away. One affects Cisco network infrastructure directly. The others target web applications. None have known ransomware use yet, but all are actively exploited in the wild.
Showcase Vulnerability
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability
What it is: Cisco IOS 12.4 contains multiple cross-site request forgery (CSRF) flaws in the web-based management interface.
Who it affects: Any organization running Cisco IOS 12.4 with HTTP management enabled.
What an attacker gets: Remote execution of arbitrary commands on the device—including privilege escalation to level 15 (administrative access) and configuration changes.
Required action: Apply vendor mitigations immediately. If mitigations are unavailable, discontinue use of the product or isolate it from untrusted networks. Evaluate internet exposure of each affected asset.
Due date: July 16, 2026.
Other Exploited Vulnerabilities Added This Week
2 other exploited vulnerabilities were added this week:
- Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
- iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
The question you now face: Do any of these run in your environment, and in what order should your team address them before the federal deadline passes?
Before you go — here's the 30-second version for your stack.
Everything CISA flagged this week fell into just a few buckets: 2 web & CMS (Balbooa, iCagenda) and 1 network & perimeter (Cisco).
So if you don't run web & CMS or network & perimeter, this week is a no-op for you. Close this email and get on with your day — nothing here is yours. If you do run one of them, the deadline is 2026-07-16.
That paragraph you just read — "this week is a no-op for you" — is the entire product. Most weeks, most of the catalog isn't yours. Knowing which part is, in 30 seconds, without reading a vulnerability database, is what you're actually short of.
ClickSecurity Pro does it precisely instead of roughly: you tell us your stack once, and each week you get only what touches your gear — ranked by what to fix first, with the fixed version and the federal deadline. No triage, no catalog, no guessing.
Filter next week to my stack — $5/mo
Not ready? Tell us what you run and we'll at least stop sending you things that aren't yours.