Recorded Future’s Insikt Group has released its CVE report for July 2026, identifying 85 high-impact vulnerabilities that it says Australia and New Zealand organisations should prioritise for remediation. The group said 36 of the 85 received a “Very Critical” Recorded Future Risk Score.
Insikt Group said the July total represented a 44% increase from the previous month. It said the vulnerabilities listed were “actively exploited or operationally weaponised” during July and affected products from 61 vendors, with Microsoft accounting for about 12% of the vulnerabilities.
The report also pointed to ongoing exploitation of older vulnerabilities, with 14 of the 85 at least five years old and the oldest approximately 18 years old. Insikt Group said the fastest observed time from public disclosure to reported exploitation was less than one day.
Among the trends highlighted, Insikt Group said “China-nexus activity” showed interest in turning edge infrastructure into operational relay capacity. It cited activity involving the exploitation of vulnerabilities including CVE-2020-22653, CVE-2020-22658, and CVE-2023-25717 to compromise Ruckus devices and expand a relay network, alongside the use of compromised devices as relay infrastructure in other campaigns.
The report said email, document and collaboration platforms were targeted for espionage and payload delivery, describing activity involving vulnerabilities including CVE-2018-0802 and CVE-2024-42009, and attempts to exploit CVE-2025-49113. It also referenced campaigns abusing CVE-2025-66376, CVE-2026-42897 and CVE-2025-9491 to deliver malware and execute post-exploitation activity.
Insikt Group said 57 of the 85 vulnerabilities enabled remote code execution, including flaws affecting Microsoft, Fortinet, Langflow, ServiceNow, and WordPress and Joomla ecosystems, as well as internet-facing security appliances and embedded network devices. It also said it identified public proof-of-concept exploits and scanners for 60 of the 85 vulnerabilities.

