3 exploited vulnerabilities due in 2 days, starting with Cisco IOS
| 3 added to KEV |
0 used in ransomware |
2026-07-13 nearest federal deadline |
This week, CISA added 3 new exploited vulnerabilities to the federal patching deadline list. The nearest due date is July 16, 2026—in 2 days. None have known ransomware exploitation yet, but all are actively weaponized.
This Week's Showcase Vulnerability
CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability
What it is: Cisco IOS 12.4 contains multiple cross-site forgery flaws in its web interface.
Who it affects: Organizations running Cisco IOS 12.4.
What an attacker gets: Remote execution of arbitrary commands on the device via crafted requests to the /level/15/exec/- URI (for privilege escalation) or the /level/15/exec/-/configure/http URI (for configuration changes).
Required action: Apply vendor mitigations immediately and verify compliance with the federal patching deadline. If mitigations are unavailable, discontinue use of the product.
2 Other Exploited Vulnerabilities Added This Week
- Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
- iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
The question now is: which of these three run in your environment, and which one poses the greatest risk to your operations?
You just read what happened. Pro tells you what to do about it.
Every week we get the same question: "Which of these actually affect the software I run?" ClickSecurity Pro answers it — you tell us your stack once, and each week you get only the vulnerabilities that hit your gear, ranked by what to patch first, with the exact fixed version and the federal compliance deadline.
The other 2 this week? Pro members already know which ones they can ignore.
Get stack-filtered alerts — $5/mo or tell us your stack first →