Critical Vulnerabilities and Active Exploitation, July 2026
July closed with Redis, SharePoint, OpenSSH, Ivanti, and Joomla/JCE in focus, plus confirmed active exploitation and regional CERT alerts.
Key findings
- Redis was the month’s most technically complex focus, with public PoCs, multiple CVEs, and regional advisories that widened impact across modules and specific branches.
- SharePoint was again under active exploitation and formally listed in KEV, raising risk to internal collaboration and machine key theft.
- Brazil and Chile concentrated the highest density of verifiable regional alerts, while Bolivia issued a highly specific technical advisory on Redis.
- Perimeter and remote access devices remained critical entry points, with OpenSSH, Ivanti, and Check Point under confirmed active exploitation.
- Balbooa Forms and JCE show that web extensions and third-party plugins remain a path to full compromise in Joomla portals.
- Most of the month’s risk came from vulnerabilities rather than extortion campaigns, and remediation was constrained by patching speed and validation.
- Available evidence requires treating several cases as potentially compromised until persistence, credentials, and web shells have been fully hunted.
Monthly reference modules
These modules are automatically compiled from verified dated events within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month readout; the later analysis develops the cases without repeating this summary.
Indicator window: 189 dated events in July 2026 · 14 from prior months (comparative frame, not current-month volume) · 1 without confirmed date (excluded from the indicators). Events from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary
July 2026 sent a clear signal about the critical vulnerability axis with active exploitation in Latin America, with Redis, Microsoft SharePoint, OpenSSH, Ivanti, and the Joomla ecosystem at the center of operational attention. The month was not driven by a single vector, but by a sequence of advisories, emergency updates, and public confirmations of exploitation that pushed regional CERTs and vendors to accelerate risk communications. The picture is of an attack surface where patching is no longer enough if it arrives late, because in several cases proof-of-concept code was already circulating, there was KEV cataloging, or real compromise was being observed in organizations across the region.
The densest case of the month was Redis. The material brings together technical advisories, warnings from Bolivia, and specialized coverage describing a batch of critical vulnerabilities in Redis OSS, Redis Software, and modules such as RedisTimeSeries and RedisBloom. The flaws combine insecure deserialization through RESTORE, use after free, and memory corruption in replication contexts and Lua scripts, with the potential for remote code execution by authenticated attackers. The release of proof-of-concept code and the vendor response, which issued multiple rounds of fixes in July, show an uncomfortable pattern for defenders: even widely deployed software that has already been patched can remain exposed if review of branches, modules, and endpoints was incomplete.
At the same time, SharePoint again occupied a critical place in the month. CTIR Gov de Brasil published alert 65/2026, with details on vulnerable versions, EPSS metrics, and reference to CISA's KEV catalog. Other sources from the same period add that exploitation could enable machine key theft, persistence, and unauthenticated remote code execution in certain variants. This is not just another Microsoft flaw, but a reminder of how collaboration and document management platforms concentrate high-value assets, with potential impact on confidentiality, integrity, and availability in corporate networks and public agencies.
Latin America also received concrete warnings about other widely used products. CERT.br warned about active exploitation of CVE-2024-24919 in Check Point VPNs, with reports of compromise in Brazilian organizations and impact on critical infrastructure and service companies. Chile's CSIRT, for its part, issued alerts about OpenSSH, Ivanti, and vulnerabilities in perimeter devices, reinforcing the reading that the month was marked by flaws that open initial access, persistence, or lateral movement. In that context, the regional component was more than a simple repetition of global advisories: there was local prioritization of technologies that are truly widespread in the region.
There was also high-risk activity in web applications and extensions. Balbooa Forms for Joomla appeared as an unauthenticated arbitrary file upload issue, with a CVSS score of 10.0, active exploitation, and inclusion in CISA's KEV catalog according to several sources. The JCE component of Joomla was also mentioned by CTIR Gov de Brasil as vulnerable to active exploitation, with a publication date outside the confirmed window in one of the archive records. Taken together, the month reinforces a very concrete lesson for Latin American teams: risk is not concentrated only in perimeter infrastructure or enterprise suites, it also lives in web extensions, CMS platforms, and third-party add-ons that often fall outside the strictest hardening cycles.
The tactical reading of the period is high risk. That assessment does not come from an invented figure or an external aggregation, but from the combination of verified event volume, concentration in widely used technologies, confirmed active exploitation from primary sources, and the speed at which regional alerts propagated. Added to that is a structural weakness: several of the month's most relevant cases required urgent remediation, not long maintenance windows, because PoC code was already circulating or exploitation was already known. In that context, regional exposure depends less on the existence of a new CVE than on how quickly each organization detects assets, prioritizes patches, and verifies that the fix actually closed the attack path.
Regional overview for the month
The month pointed to a clear risk pattern across Latin America. Brazil and Chile accounted for the highest density of alerts from national CERTs, Bolivia issued one of the most specific technical notices on Redis, and Colombia was represented by a ColCERT alert that, while based on aggregated telemetry and not confirmed-impact incidents, helps frame the operational noise security teams are working through. Mexico, Peru, Argentina, and Paraguay did not appear with comparable findings in this period, which should not be read as a lack of exposure, only as a lack of verifiable cases in the July record.
Vulnerabilities, not fraud or extortion, were the dominant signal. That matters because it shifts attention away from classic campaign detection and toward exposure management. When the month’s materials center on Redis, SharePoint, OpenSSH, Ivanti, Balbooa Forms, and JCE, defensive work changes in kind, inventory has to be identified, versions verified, modules reviewed, logs monitored, and the gap between advisory publication and abuse has to be assumed shorter. In other words, the main problem was not a new malware family, but the window of opportunity that opens between an advisory and full patch adoption across the installed base.
The region also showed a recurring operational trait, the use of perimeter or collaboration software as a bridge into internal networks. CERT.br was explicit in saying that CVE-2024-24919 in Check Point VPN was being exploited to access corporate networks, and Chile’s CTIR recommended immediate action on Ivanti and OpenSSH. In both cases, the vulnerability is the first step, not the final incident. That pattern is especially sensitive in Latin American organizations with hybrid architectures, multiple sites, and third-party administered devices, where delayed patching in a single layer can compromise entire domains.
The qualitative risk reading for July is high. That is due not only to the number of verified events in the period, but also to the quality of the sources and the type of software affected. Redis and SharePoint concentrate data and integrations, OpenSSH and VPNs control remote access, Joomla and related extensions support exposed portals, and Ivanti sits at the edge of administration and security. When several of those layers appear at once with active exploitation, the result is more than a simple sum. It creates cumulative pressure on response teams, which must close initial access paths while checking for persistence and abuse of prior credentials.
Period indicators
| Indicator | Value |
|---|---|
| Verified events in the period (basis for all indicators) | 187 |
| Indicator time window | 189 events dated in July 2026, 14 from prior months (comparative frame, not monthly volume), 1 with no confirmed date (excluded from indicators) |
| Unclassified incidents (breaches or outages) | 3 |
| Cases with ransomware or extortion as the primary focus | 4 |
| Ransomware breakdown by impact type: Confirmed asset encryption | 1 |
| Ransomware breakdown by impact type: Cannot be determined from the material | 3 |
| Documented fraud or phishing cases | 2 |
| Documented regulatory moves | 0 |
| Critical CVEs mentioned | 48 |
| Sectors with at least one documented event | 5 |
| Dominant threat of the month | Vulnerabilities (143 of 187 events) |
| Events with direct source confirmation | 95% |
| Aggregated telemetry figures excluded from volume | 2 (aggregated attempts or blocks, not incidents with confirmed impact) |
The table shows a signal in which vulnerabilities clearly dominated, without erasing the presence of other themes. The ransomware and extortion figure should be read carefully, because the material does not always make it possible to distinguish confirmed encryption, plain extortion, or a mere mention on a leak site. That is why the indicator breaks down only what the file allows to be classified, and nothing more. The same applies to the 48 critical CVEs mentioned, they indicate presence in the material, not an exploitation rate or an exhaustive list of what happened in the region.
The time window also matters. The file contains 189 events dated in July 2026, 14 from previous months used only as a comparative frame, and one event with no confirmed date, excluded from the indicators. That mix requires strict editorial discipline: no adding months together, no treating late coverage as if it were monthly volume, and no extrapolating aggregated telemetry into incidents with impact. The two telemetry records are useful for context, but they do not change the intrusion count or the month’s severity.
Relevant Incidents
Redis and the cluster of vulnerabilities with public PoC
Redis was the most persistent technical case in July. The record brings together several pieces that, taken together, point to a broad risk for Redis OSS, Redis Software, Redis Cloud, and modules such as RedisTimeSeries and RedisBloom. The CGII advisory in Bolivia was especially relevant for the region because it elevated the issue to a local warning, classified the severity as high, and said exploitation can lead to memory corruption and remote code execution in scenarios where the attacker has an authenticated account and specific permissions, especially to use RESTORE or to operate in master-replica replication contexts.
The set of CVEs cited in the material, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23479 and CVE-2026-23631, is not uniform. Some flaws are tied to insecure deserialization, others to use after free, and others to memory corruption in specific modules. That makes remediation harder, because identifying one vulnerable version is not enough. The main branch, modules, replication policies, and exposure of administrative commands all need review. The Bolivian advisory even calls out specific RedisTimeSeries and RedisBloom versions, extending the scope beyond the product core.
The other important reading is practical exploitation. SecurityLab reported that proof-of-concept exploit chains achieved remote execution even in versions already patched, such as 6.2.22, 7.4.9 and 8.6.4. The Hacker News and Ingeniería Telemática also pointed to the circulation of authenticated PoCs, while Redis responded with seven additional security releases in a single day, on July 23. That sequence suggests the initial fix process did not close off the full attack surface. For a CISO, that means an emergency patch is not the end of the job, it is the start of broader verification of coverage and exposure.
Operationally, Redis deserves a two-layer reading. First, because it is widely used for caches, queues, sessions, and temporary data, which makes it a component with broad horizontal exposure. Second, because the material shows that abuse requires authentication in several scenarios, which changes the control profile. This is not a case of a simple indiscriminate internet scan in all instances, but a vulnerability that can go unnoticed if there is any prior access vector or reused credentials. That raises the importance of reviewing service accounts, segmentation, and command permissions.
SharePoint and pressure on internal collaboration
SharePoint returned to the center of the regional conversation through alert 65/2026 from CTIR Gov in Brazil. The notice identifies vulnerable versions in SharePoint Server 2016, 2019 and Subscription Edition, and adds that the flaw can affect confidentiality, integrity and availability. It also includes an EPSS of 5,06% and a 91,41% percentile, along with a reference to CISA's KEV catalog. That combination matters because it shows the issue was not framed as a simple lab vulnerability, but as a case with enough likelihood of abuse to justify immediate remediation.
Other sources from the same period add technical depth. They mentioned possible theft of machine keys, persistence and unauthenticated remote execution. The appearance of a public proof-of-concept was also cited as a factor accelerating exploitation. All of this places SharePoint in a sensitive spot, not only as a productivity app, but as a piece that often stores sensitive content, integrates authentication, and serves as an interface between users, processes and internal repositories. When a critical vulnerability appears at that point, the potential damage goes beyond a single server.
The regional implication is significant because SharePoint is present in governments, education, financial services and large Latin American corporations. The Brazilian alert also came with concrete recommendations to inventory versions and apply vendor fixes. There is no room here for purely perimeter-based defense. If the system is used as a collaboration portal, the priority should include account review, checks for signs of persistence, and searches for anomalies in logs, since the exploitation described allows access that may survive patching if the response is limited to updating binaries.
OpenSSH, Ivanti, and the perimeter that remains an entry point
Chile provided several high-value operational signals. CSIRT published an advisory on the critical CVE-2024-6387 in OpenSSH, known as regressh, and said confirmed active exploitation exists. It also issued an alert on Ivanti with multiple CVEs, including CVE-2023-46805 and CVE-2024-21887, which, according to the notice itself, were used in combination to compromise Ivanti Connect Secure devices. That combination is important because it marks two distinct but connected realities, exposed remote access and security devices turned into intrusion vectors.
The fact that Ivanti is treated as an active exploitation target in campaigns against security devices underscores a persistent trend in the region, where equipment installed for protection ends up becoming part of the attack surface. This is not a minor detail. If a VPN or access gateway is compromised, the attacker no longer necessarily needs to find an alternate entry path. Instead, they can expand reach, obtain credentials, or move laterally from a point organizations usually consider trusted.
CERT.br added to that reading from Brazil, warning that CVE-2024-24919 in Check Point VPN devices was being used to read sensitive information from the memory of affected gateways. The notice also highlighted reports of compromise in Brazilian organizations and the need to apply vendor patches immediately. When several regional authorities agree that exploitation is happening and the vector touches access infrastructure, the priority stops being theoretical. It becomes a continuity and exposure management issue.
Balbooa Forms and the quiet risk of web extensions
Balbooa Forms for Joomla drew an unusual amount of technical coverage for a third-party extension. The official CVE-2026-56291 record says all versions earlier than 2.4.1 were vulnerable to an unauthenticated arbitrary file upload that allowed executable uploads and full RCE. The technical material adds more troubling details, including the lack of a CSRF token, the absence of an allowlist for extensions, and reliance on the user-provided filename. In other words, the flaw was not subtle. It was a combination of missing controls at a highly exposed entry point.
The problem grows because several sources agree there was active exploitation. CTI Pilot and SentinelOne described the case as a zero-day already being exploited, while Devel Group said CISA added it to the KEV catalog and recommended isolation, immediate patching and threat hunting in HTTP POST logs toward Joomla extension paths. TechConsulting added a useful technical reading by summarizing that the frontend upload handler accepted files without authentication and allowed .php uploads to a public directory. The defensive counterpart is clear, any site that ran the vulnerable extension should be treated as potentially compromised until proven otherwise.
The regional significance of the finding does not depend on a specific victim. It depends on Joomla's wide use in portals, intranets and citizen-facing sites across Latin America, where third-party extensions are often installed to quickly meet business needs. The risk is not just in the CMS, but in the long tail of add-on components that do not always go through the same secure development controls as the core. The month showed that this neglect can end in web shells, persistence and full server compromise in a matter of seconds.
JCE in Brazil and the file that confirms active exploitation
The Joomla Content Editor case, identified as CVE-2026-48907, appears in the archive with an editorial particularity, a Brazilian government source confirmed it as an alert about active exploitation, but the associated date remained unconfirmed in one of the archived records. Even so, the rest of the material for the period places the issue clearly. SonicWall describes it as unauthenticated remote RCE, IntelSecLab published a PoC for the vector through profiles.import, and dbugs, linked to Positive Technologies, presented it as a flawed access control issue that allowed unauthenticated users to create editor profiles and execute arbitrary PHP.
What stands out here is the convergence between the technical detail and the institutional response. This was not just a theoretical vulnerability, it was a flaw that had already prompted a public alert and practical research activity. For security teams, that means checking not only the component version, but also the presence of anomalously created profiles, strange PHP files, and any trace of abuse in import paths. When the vulnerable point is a content editor, compromise can go unnoticed for some time if monitoring is limited to the CMS core.
Active Threats and Campaigns
Ransomware and Extortion
This month’s file includes four cases where ransomware or extortion is the main focus, but only one clearly confirms encrypted assets. In the other three, the material does not specify whether there was encryption, exfiltration without encryption, or only a claim on a leak site. That distinction matters. For a response team, it changes containment priorities, the kind of legal negotiation involved, and how urgently recovery from backups must happen.
A careful reading means not forcing uniformity where none exists. When the source does not confirm encryption, the report should say so. The lack of documentary precision does not reduce the risk, but it does prevent a generic mention from being turned into a verified operational incident. In the month under review, the value of the material lay less in the extortion narrative and more in the initial access vectors that, in practice, often feed these campaigns later.
Fraud and Phishing
The period’s material documents two fraud or phishing cases. There is not enough detail to build a unified campaign or attribute a common method, so the record has to stay at that level. The signal is still useful, because it overlaps with the rest of the risk surface and suggests that credential abuse, impersonation, or social engineering remained a complementary layer for access or monetization.
In a month so heavy with critical vulnerabilities, phishing does not disappear. It becomes the lubricant for other attacks, especially when a stolen credential, a compromised account, or a deceptive interaction lets an attacker get past controls that a vulnerability alone might not have broken. So even though the material does not describe a larger campaign, the data should be read as a reminder that technical exposure and human exposure reinforce each other.
APT and Hacktivism
There is not enough material in this file to build a strong attribution of APT or hacktivism as the month’s dominant themes. There are, however, patterns consistent with actors seeking persistent access or lateral movement through perimeter software and collaboration platforms. The reference to active exploitation in VPNs, SharePoint and OpenSSH aligns with high-value initial access tactics, but the material does not support attribution to specific groups in this section.
Critical vulnerabilities
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-23479 | Redis OSS/CE, Redis Software, RedisTimeSeries | PoC circulating, authenticated exploitation, and multiple fixes in July | CGII Bolivia, CyberPress, The Hacker News |
| CVE-2026-25243 | Redis OSS/CE, Redis Software | Unsafe deserialization via RESTORE, PoC, and multiple fixes | CGII Bolivia, Rescana, CyberPress |
| CVE-2026-25588 | Redis OSS/CE, Redis Software, RedisTimeSeries | PoC circulating, authenticated exploitation | CGII Bolivia, Ingeniería Telemática |
| CVE-2026-25589 | RedisBloom | PoC circulating, buffer overflow or memory corruption with possible RCE | CGII Bolivia, Stingrai, CyberPress |
| CVE-2026-23631 | Redis OSS/CE, Redis Software | Use after free in replication and Lua scripts, PoC circulating | CGII Bolivia, The Hacker News |
| CVE-2024-24919 | Check Point VPN | Active exploitation confirmed in the wild | CERT.br, Check Point, Convergência Digital |
| CVE-2026-56291 | Balbooa Forms for Joomla | Active exploitation, CVSS 10.0, added to KEV | CTI Pilot, SentinelOne, Devel Group, CVEfeed |
| CVE-2026-48907 | Joomla Content Editor, JCE | Active exploitation confirmed by regional alert and technical PoC | Portal Gov.br, IntelSecLab, SonicWall, dbugs |
| CVE-2026-50522 | Microsoft SharePoint Server | Active exploitation, KEV, impact on machine keys | CTIR Gov Brasil, Security Affairs, Datawiza, Zetik |
| CVE-2024-6387 | OpenSSH | Active exploitation confirmed | CSIRT Chile |
| CVE-2023-46805 | Ivanti Connect Secure | Active exploitation in chain with CVE-2024-21887 | CSIRT Chile |
| CVE-2024-21887 | Ivanti Connect Secure | Active exploitation in chain with CVE-2023-46805 | CSIRT Chile |
The table reflects 48 critical CVEs mentioned in the source material, but not all are broken out here because the file groups repeated references and advisories together. What matters most for the region is that several of the highest-impact CVEs were concentrated in remote access, collaboration, and web extension components. That matches a familiar defensive pattern, attackers favor the pieces that handle authentication, visibility, or external publishing, because a single flaw in those layers offers far greater returns than an isolated vector on an internal endpoint.
Regulation and Compliance
No documented regulatory moves were recorded in the month’s material. That does not mean compliance activity has stopped, only that the file contained no verifiable facts to describe new regulatory frameworks, sanctions, or specific compliance obligations for July 2026.
Even without formal regulatory changes, there are still operational compliance implications. CTIR Gov notices in Brazil, along with CERT.br and CSIRT Chile, serve as urgency signals for public and private entities that manage critical infrastructure or essential services. In practice, these advisories often lead to internal requirements for review, asset inventory, patching evidence, and, in some cases, notice to third parties or contractors. The issue is not regulatory in the strict sense, but risk governance.
Latin America’s most affected countries
Brazil
Brazil recorded the highest density of verifiable events during the period. CTIR Gov published alert 65/2026 on Microsoft SharePoint, including affected versions, EPSS, and a KEV reference. CERT.br issued an alert on active exploitation in enterprise VPNs, focused on CVE-2024-24919 and real compromise in Brazilian organizations. Local media also reported incidents tied to Check Point, and the CSIRT of Chile logged an Ivanti alert, which is also relevant for environments with shared regional operations from Brazil.
The Brazilian case reflects a common pattern in Latin American risk, heavy reliance on corporate suites and perimeter devices, plus an institutional sense of urgency that arrives just as the patch is already circulating across the global ecosystem. The quality of the official material is high and points to significant defensive pressure on service companies, critical infrastructure, and public-sector organizations. In practical terms, Brazil concentrated both alert production and regional media amplification.
Chile
Chile was the second major source of documentation during the month because of its CSIRT activity. The agency published an alert on OpenSSH with confirmed active exploitation, another on Ivanti vulnerabilities, and a reference to actively exploited perimeter devices. Chile’s presence in the archive is notable because it shows a national authority addressing remote access and perimeter vulnerabilities with an operational lens, not just an informational one.
The Chilean signal is clear: external exposure gets priority, access devices are reviewed, and patches are applied immediately. That suggests an environment where perimeter failures remain a real concern for organizations with distributed operations, connected vendors, and remote users. The lack of other mentions should not be read as lower risk, only as a lower density of verifiable facts in the archived material.
Bolivia
Bolivia contributed one of the month’s most detailed technical advisories through the CGII. The agency issued a warning about a set of Redis vulnerabilities, with a high severity classification, affected versions, and a technical explanation of the exploitation mechanisms. Beyond its local value, the document matters regionally because it turns a global issue into a concrete recommendation for administrators in the area.
Bolivia’s contribution shows that national alerts can be as useful as vendor advisories, especially when they spell out modules, versions, and mitigation steps. In environments where Redis is used as a high-performance internal service, the risk is not only public exposure but also persistent replication settings or overly broad permissions. In that sense, Bolivia was a strong example of operationalizing risk.
Colombia
Colombia did not record incidents with confirmed impact in the core of this report, but it did contribute aggregated telemetry through ColCERT. The alert on the CHARLIE/ORB3/SPACEHOP network reported at least 16 confirmed nodes carrying out large-scale scanning and brute-force activity against SSH, PostgreSQL, and Apache Tomcat. That data is not counted as an incident, but it does help show that Colombian organizations operate in an environment with constant automated pressure.
Colombia’s July profile is therefore one of exposure to mass noise rather than a single standalone case. The editorial value of the data is contextual and should not be confused with confirmed impact. Even so, scans at this scale show that access controls and service exposure remain basic hygiene priorities.
Mexico
The month’s material did not include verifiable facts that would allow Mexico to be assigned a concrete incident or alert within this axis. That does not reduce the country’s risk, but it does limit what can be documented. The archive does not include a Mexican alert comparable to those from Brazil, Chile, or Bolivia for July 2026.
Argentina
No verifiable facts were recorded for Argentina in this axis during the period. The absence of material should not be read as the absence of exposure, only as the lack of documented cases in the available archive.
Peru
No verifiable facts were recorded for Peru in this axis during the period. The material reviewed does not provide a concrete alert or incident dated July 2026.
Paraguay
No verifiable facts were recorded for Paraguay in this axis during the period. The archive also does not contain a comparable advisory that would support a country-specific assessment.
United States
Although this report prioritizes Latin America, several events during the period frame regional exposure because they involve global vendors and known exploit catalogs. In particular, CISA added SharePoint to KEV, and the Balbooa Forms case is also referenced. These are not Latin American incidents in themselves, but they do shape how quickly teams in the region need to respond.
Trends and signals to monitor
There is no month-over-month comparison baseline in this archived format for Latin America, so it would be wrong to invent percentage changes or a quantified trend from one month to the next. What July did show was a clear pattern of pressure across three fronts, perimeter exposure, internal collaboration, and web extensions. Redis, SharePoint, VPNs, OpenSSH, Ivanti, JCE, and Balbooa Forms make up a software chain that mixes access, authentication, publishing, and administration. That mix is highly valuable to intruders because it can let them move from an external flaw to persistence or lateral movement at relatively low cost.
A second signal to monitor is the acceleration between PoC and effective mitigation. The material shows cases where public exploitation was already underway, KEV catalogs, regional CERT advisories, and multiple vendor patch rounds. When that happens, the question is no longer whether the vulnerability is serious, but whether the organization closed the gap before it was exploited in its environment. That shift in the question, from abstract severity to remediation speed, is probably the month’s most important trend.
The third signal is the persistence of vulnerabilities in products that are often managed by different teams. Redis may sit with data platforms, SharePoint with workplace or collaboration teams, VPNs and gateways with infrastructure or security, Joomla with web or marketing, Ivanti with operations or security. Risk appears when no one has the full picture. July left the impression that fragmented ownership remains a more serious regional weakness than the lack of patches itself.
Security team recommendations
First, build or update an exposure inventory that goes beyond core software. This month showed that Redis modules, Joomla extensions, and add-ons such as Balbooa Forms can have as much impact as a flaw in the main product. The inventory should include branches, plugins, modules, minor versions, and exposed admin points.
Second, prioritize patch validation with real verification, not just closed tickets. Several cases this month show that an initial fix did not necessarily close the full attack surface. It is worth checking versions, endpoint behavior, and signs of exploitation, especially in Redis, SharePoint, VPNs, and Joomla. If the vendor issued several security rounds within a few days, assume the first remediation may have been incomplete or insufficient for the local installation.
Third, urgently review remote access services and edge devices. OpenSSH, Ivanti, and Check Point were confirmed under active exploitation. That means looking for anomalies in authentications, persistent sessions, new accounts, altered rules, and any sign of lateral movement after the initial entry. On security devices, the audit should also include configuration, logs, and the possibility of compromise before patching.
Fourth, treat SharePoint and other collaboration platforms as high-sensitivity assets. Exposure of machine keys, the possibility of persistence, and the impact on confidentiality and integrity require more than a patch. Credentials, keys, associated services, and signs of abuse need to be reviewed. If the platform serves as a business portal or intranet, the potential damage expands to entire processes.
Fifth, apply specific hardening to web applications and CMS extensions. The Balbooa Forms case is a direct example of why forms, upload handlers, and import endpoints must be secured. Temporarily disabling critical components, restricting by IP where possible, blocking PHP execution in upload directories, and reviewing HTTP POST logs are reasonable measures when the time between disclosure and abuse is short.
Sixth, assume compromise when the scenario warrants it. If a Joomla site ran vulnerable Balbooa Forms, or if a SharePoint instance was exposed with the July CVE, updating is not enough. Teams need to review accounts, look for web shells, rotate credentials, validate backups, and analyze events from before remediation. The logic in July was not isolated patching, but persistence hunting.
Seventh, coordinate security, infrastructure, and application owners. This month made clear that organizational fragmentation worsens risk. Redis, SharePoint, VPNs, and CMS platforms often have different owners, but attackers do not respect those boundaries. Prioritization should be cross-functional and on short timelines.
Material limitations
This report was prepared exclusively from the material provided for July 2026, without internet access and without adding sources outside the authorized list. The scope is Latin America, although several facts from global vendors or outside organizations were used only when they helped frame risks that did have regional impact or triggered alerts.
The time window for the indicators is the one stated at the beginning: 189 facts dated in July 2026, 14 from earlier months as a comparative frame, and 1 fact without a confirmed date, excluded from the indicators. Facts from earlier months do not count toward the period volume and may only be cited if their month is made explicit. The record without a confirmed date is also excluded from the counts, and when it is used as context, it must be stated that the date is not confirmed.
The indicator for critical CVEs mentioned should not be confused with a lack of vulnerabilities in the region if any section appears at zero in another period. This month, the material did record critical CVEs, but the methodological principle remains the same, a zero value would mean only that none appeared in the material reviewed, not that no real activity existed in the region.
Aggregate telemetry was not added to incidents either. ColCERT and Semana records are cited only as attempts, blocks, or volume measurements, not as intrusions with confirmed impact. Likewise, ransomware or extortion cases were kept distinct according to the available evidence, and when the source did not allow a determination of whether assets were encrypted, that was stated explicitly. Social media and excluded content were not used, and trends were not based on promotional material.
Finally, some items in the file have inconsistent dates or records without complete time confirmation. In those cases, the priority was not to force an artificial chronology. The goal was to preserve traceability and avoid turning a technically interesting fact into a claim that the material did not support.
Sources
- Kimi K3 AI Agent Finds Redis RCE Vulnerabilities in Just 27 MinutesCyberPress
- Aviso de seguridad: Circulación de pruebas de concepto para el lote de vulnerabilidades que afecta a servidores RedisCentro de Gestión de la Información e Informática (CGII) - Gobierno de Bolivia
- nuevos exploits vuelven a vulnerar la seguridad de RedisSecurityLab
- Kimi K3 Agents Found Redis Zero-Days and Built RCE ...The Hacker News
- Vulnerabilidades Zero-Day Críticas en Redis Permiten Ejecución Remota de CódigoIngeniería Telemática
- Critical Redis Vulnerability CVE-2024-27348 Enables Remote Code Execution via RESTORE Command: Risk Analysis and Mitigation StrategiesRescana
- Redis RCE 2026: Five Patched CVEs and an AI DiscoveryStingrai
- CVE-2026-56291: RCE no Balbooa Forms com Exploração AtivaDFT Info / JRT Technology Solutions
- CISA Agrega Vulnerabilidades Críticas de Extensiones Joomla iCagenda y Balbooa Forms al catálogo KEVDevel Group
- Vulnerabilidad crítica en Balbooa Forms para JoomlaTechConsulting
- CVE-2026-56291 — Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-dayCTI Pilot
- CVE-2026-56291: Balbooa Forms Joomla Extension RCESentinelOne
- CVE-2026-56291 - Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1CVEfeed
- CVE-2026-56291 - Kritische RCE-Lücke in Balbooa FormsCyberwald
- New exploits for JoomShaper SP Page Builder, Splunk, Cisco UCM, JCE, and many more - Initial AccessVulnCheck
- Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907) · PoC ArchiveIntelSecLab
- Joomla Content Editor Remote Code ExecutionSonicWall
- ALERTA 56/2026Portal Gov.br
- CVE-2026-48907 - Joomla · Jce Editor - dbugsdbugs / Positive Technologies
- ALERTA 56/2026 - Portal Gov.brPortal Gov.br
- ALERTA 65/2026 – Vulnerabilidade crítica que afeta o SharePointGSI – CTIR Gov (Gobierno de Brasil)
- Vulnerabilidad crítica en OpenSSH (CVE-2024-6387)CSIRT de Gobierno de Chile
- Alerta de seguridad: vulnerabilidades en IvantiCSIRT de Gobierno de Chile
- SharePoint enfrenta una falla crítica de ejecución remota explotada activamenteDiario Bitcoin
- U.S. CISA adds Microsoft SharePoint and Check Point flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
- Critical Unauthenticated Remote Code Execution Vulnerability in Microsoft SharePoint Server CVE-2026-50522SecureVerifyConnect
- CISA Adds SharePoint RCE CVE-2026-50522 to KEV, Orders Fixes by July 25Zetik
- CVE-2026-50522: SharePoint Machine Key TheftDatawiza
- Alerta de seguridad: vulnerabilidades en Citrix NetScaler ADC y GatewayCSIRT de Gobierno de Chile
- INCIBE alerta de dos vulnerabilidades críticas en SonicWall SMA1000Moncloa.com
- 102 Alerta Red de Retransmisión Operativa CHARLIEColCERT
- Al-2026-0036 – Ransomware WallstreetECUCERT
- Weekly Threat Landscape Digest - Week 28 - HawkEyeHawkEye
- OpenSSH - CVE-2026-60002French CERT / cyberveille.e-santé
- El INCIBE alerta de una vulnerabilidad crítica de Path Traversal en Adobe ColdFusion (CVE-2026-48282) que ya está siendo explotada activamenteMoncloa.com / INCIBE-CERT
- APSB26-68 - Adobe Security BulletinAdobe
- CVE-2026-48282: Mitigating a Critical Vulnerability in Adobe ColdFusionAkamai
- Attackers exploit critical Adobe ColdFusion vulnerability (CVE-2026-48282)Help Net Security
- Vulnerability Intelligence Report — July 7, 2026Threat Modeling
- INCIBE alerta de seis vulnerabilidades en NetScaler ADC y Gateway de CitrixMoncloa.com
- Múltiples vulnerabilidades en NetScaler de CitrixINCIBE-CERT
- Colombia registró 10,9 billones de intentos de ciberataques y concentra el 8 % de los incidentes de América LatinaSemana
- El «Patch Tuesday» de julio de 2026 corrige 622 Microsoft CVEs incluyendo tres zero-daysMalwarebytes
- Patch Tuesday de Microsoft de julio de 2026: 622 CVESplashtop
- Microsoft corrige vulnerabilidades críticas en el Patch Tuesday de julio de 2026Telconet CSIRT
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- Microsoft's 622-CVE Patch TuesdayOrca Security
- SharePoint Server Actively Exploited: CISA Orders Patch Before Ransomware Actors StrikeTechTimes
- AL26-017 - Critical vulnerabilities impacting Microsoft SharePoint ServerCanadian Centre for Cyber Security
- SharePoint CVEs FAQ: CVE-2026-56164 ...Tenable
- CiberPlaneta - Blog de Ciberseguridad y TecnologíaCiberPlaneta
- Top Exploited CVEs This MonthSecurityOnline
- CISA Urges SharePoint Hardening After New ExploitationsCISA
- Microsoft publica récord de 622 CVEs en Patch Tuesday; CISA acelera alerta para SharePointThe New Times
- Cómo la filtraciones de datos puede acabar con una empresa: el temor del que todos deben protegerseInfobae
- Panorama De Ciberseguridad: Semana Del 20 Al 24 De Julio De 2026CronUP
- CISA Warns of Actively Exploited WordPress FlawsCyberPress
- Día: 21 julio, 2026devel.group
- 20th July – Threat Intelligence ReportCheck Point Research
- Cyber Threat Brief - July 20, 2026RadioCSIRT
- Technical Advisory: wp2shell — Unauthenticated Remote Code Execution / Full Site Takeover in WordPress CoreBitdefender
- Cadena de explotación crítica wp2shell en WordPress Core CVE-2026-63030 y CVE-2026-60137Centro de Gestión de la Información e Infraestructura (CGII) Bolivia
- Ep.697 - RadioCSIRT Flash info cybersécurité du jeudi 16 juillet 2026RadioCSIRT
- Actualizaciones de seguridad de Microsoft – Julio 2026CERTuy / gub.uy
- 570 fallas en un martes: el Patch Tuesday más grande de julio 2026CodigoVigia
- Ep.696 - RadioCSIRT Édition Spéciale Patch Tuesday 14 juillet 2026RadioCSIRT (YouTube)
- CISA warns that multiple vulnerabilities in SharePoint are being exploitedCybersecurity Dive
- Microsoft Patch Tuesday, July 2026 Security Update ReviewQualys
- Microsoft July 2026 Security Updates — Record 570 vulnerabilities including two actively exploited zero-daysGMCSIRT
- Microsoft corregge 570 falle nel Patch Tuesday, 622 nel conteggio estesoMatrice Digitale
- CISA urges immediate SharePoint hardening as exploits mountComputerworld
- CISA Warns of Active Exploitation of Three Microsoft SharePoint Server Vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)Threadlinqs Intelligence
- CISA Says Three SharePoint Flaws Are Being Chained Right Now. We Wrote the Hunt for One of Them in May.DugganUSA
- Critical Patches Issued for Microsoft Products, July 14, 2026Center for Internet Security
- Microsoft Patch Tuesday | Threat Intel Reports – July 2026Smarttech247
- CVE-2026-56164: SharePoint Missing Authentication for Critical FunctionPenligent AI
- Patch Tuesday - July 2026Kirin
- Multiples vulnérabilités dans Microsoft Windows (incluant mention de CVE-2026-56155)Vulnerability-Lookup
- Actividad Maliciosa Activa en GlobalProtect y Nuevos CVEs en Infraestructura Perimetral de Palo AltoDevel Group
- Vulnerability Database — EPSS, CISA KEV & exploit statuso3.security
- Resumen vulnerabilidades críticas – 27 elementos (09 jul 2026 Europe/Madrid)Iurlek Blog
- Alertan explotación activa de falla crítica en Microsoft SharePoint (CVE-2026-45659)Nivel 4
- CVE-2026-45659: SharePoint en KEV y ransomware WarlockHard2Bit
