27 July 2026

ShinyHunters uses healthcare help desks to break into cloud accounts

The group is using phone calls to persuade help desks to reset multifactor authentication, then taking over cloud accounts and stealing data from connected services—often without deploying traditional ransomware.

CISO Quick Read

  1. 01

    Craneware contains an intrusion while assessing stolen data

    Craneware disclosed unauthorized access and data exfiltration but reported no disruption to customer services or company operations.

    The unresolved scope includes some employee data and a subset of customer and partner records tied to a healthcare financial-technology supplier.

    Craneware still has to determine the precise scope of the exfiltrated customer, partner and employee data and identify the affected parties.

    Timing20 July 2026

    Open the supporting record
  2. 02

    Oracle WebCenter Content flaw allows unauthenticated takeover

    An unauthenticated attacker with HTTP network access can exploit affected WebCenter Content versions to take over the platform and potentially affect connected products.

    Where WebCenter Content or a dependent service is deployed, a takeover could expose or alter content and disrupt access to the platform.

    Applicable deployments are self-managed Oracle WebCenter Content releases 12.2.1.4.0 and 14.1.2.0.0 that untrusted parties can reach over HTTP.

    TimingOracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.

    Open the supporting record
  3. 03

    Oracle PeopleSoft flaw exposes critical application data

    An unauthenticated attacker with HTTP network access can exploit PeopleSoft Enterprise CC Common Application Objects 9.2 to read, create, delete or modify critical application data.

    Where the affected PeopleSoft component is deployed, unauthorized data access and modification could undermine records and the business processes that depend on them.

    This applies to Oracle PeopleSoft Enterprise CC Common Application Objects release 9.2 when untrusted parties can reach it over HTTP.

    TimingOracle disclosed the vulnerability on 21 July 2026, in its July Critical Patch Update.

    Open the supporting record
  4. 04

    FDA says affected ENROUTE catheters should not be used

    FDA issued a potentially high-risk Early Alert for Boston Scientific ENROUTE NPS and NPS Plus products and directed affected product to be removed from use and distribution.

    The instruction immediately removes affected transcarotid neuroprotection catheters from procedural inventory.

    Affected ENROUTE inventory should remain segregated and out of use while FDA reviews the potentially high-risk issue and determines its recall classification.

    Timing21 July 2026

    Open the supporting record
  5. 05

    OpenAI reports an incident in a Hugging Face evaluation dependency

    OpenAI disclosed a security incident involving model-evaluation work conducted through Hugging Face infrastructure.

    Healthcare AI programs using comparable external evaluation platforms inherit a dependency path involving credentials, model access and third-party infrastructure.

    External evaluation platforms extend an AI program’s trust boundary to the credentials and model access they handle.

    Timing21 July 2026

    Open the supporting record

Healthcare Incident Watch

Healthcare Incident Watch

Craneware reports data theft but no service disruption

Craneware disclosed unauthorized access to a subset of its data environment and said the incident had been contained. The company reported no disruption to customer services or its operations.

A significant volume of file names was viewed and exfiltrated, together with some employee data and a subset of customer and partner records. The investigation has not resolved the precise nature or scope, including the final population affected; the disclosure neither identifies an attacker nor links the incident to patient harm.

Read Craneware’s incident notice

Healthcare Incident Watch

ShinyHunters uses identity resets to reach health-sector SaaS

Health-ISAC flagged an increase in successful ShinyHunters attacks affecting the health sector and documented the attack pattern: phone-based social engineering persuades help desks to reset multifactor authentication or re-enroll a device, enabling takeover of Microsoft Entra, Okta or Google SSO accounts and access to connected SaaS platforms for data theft and extortion.

The warning is sector-level rather than a comprehensive victim inventory. Its defensive focus is the identity control plane: stronger identity proofing, phishing-resistant MFA, tighter SaaS logging and containment playbooks prepared for rapid account takeover.

Read the Health-ISAC advisory

Healthcare Incident Watch

Malware disruption closes AnMed offices and imaging

AnMed said malware was impacting its network, creating a cybersecurity disruption whose scope beyond the immediate service plan was still developing. The notice did not attribute an attacker or establish ransomware or data exposure.

Medical Group offices and Imaging Services were scheduled to close Monday, July 27, while Urgent Care, Kids Care, Integrated Therapy and Laboratory Services were scheduled to open. Procedure, transfer, diversion and operational decisions were being guided by patient safety, with AnMed coordinating care access with EMS and regional hospitals.

Read AnMed’s systems disruption notice

Regulatory & Privacy

Regulatory & Privacy

Operation Vital Signs tests response across critical health functions

HSCC’s Operation Vital Signs invited all regulated entities to a national virtual exercise on July 21–22 testing enterprise and cross-sector response and recovery, including effects on critical functions and patient safety.

Pairing recovery mechanics with patient safety makes the exercise a test of sector coordination around care-critical functions. After-action results remain the next milestone.

View Operation Vital Signs information

Regulatory & Privacy

Health-ISAC’s first CISO benchmark spans five industry segments

Health-ISAC released its first CISO benchmarking report, drawing on survey input from 76 security leaders across providers, payers, pharmaceutical companies, medical-device organizations and global operations.

The report covers health-sector risks, emerging threats, governance, staffing, budgets, technology investment and CISO priorities for the next 12 to 24 months. Its 76-participant sample offers a peer benchmark across several industry segments, with broader interpretation dependent on the report’s methodology.

Read the CISO Benchmarking Report

Regulatory & Privacy

Health-ISAC puts AI exposure, medical IoT and policy on one agenda

Health-ISAC’s July 22 Quarterly Threat Insights briefing placed AI-server and MCP exposure, patient safety, legacy medical IoT and U.S. critical-infrastructure policy on one health-sector readiness agenda.

The grouping connects emerging AI dependencies, aging connected devices and policy developments within clinical technology planning. The page sets a readiness agenda and creates no new legal duty.

Watch Quarterly Threat Insights

AI & Clinical Automation Watch

AI & Clinical Automation

OpenAI incident exposes a third-party model-evaluation dependency

OpenAI disclosed a security incident in model-evaluation work using Hugging Face infrastructure. The compromise exposed a third-party dependency path spanning external evaluation platforms, credentials and model access.

Evaluation infrastructure therefore belongs inside the AI trust boundary, with credentials and model access as the principal control points. OpenAI reported no healthcare involvement.

Read OpenAI’s disclosure

AI & Clinical Automation

FDA selects Dexcom as the first TEMPO pilot participant

FDA selected Dexcom as the first participant in the TEMPO digital-health devices pilot on July 22, activating the pilot’s first manufacturer participation and FDA’s continuing evaluation of the Dexcom Glucose Health Program.

The selection moves TEMPO into a live test of how digital-health devices can generate real-world evidence for chronic-disease care. Product approval and outcome evidence remain later milestones.

Read the FDA TEMPO announcement

Priority CVEs

CVE-2026-60644Oracle WebCenter ContentNewCritical · CVSS 3.1 10.0 (Oracle/CNA)
Rank 1No confirmed exploitation; not in CISA KEV at cutoffExposure assessment · contain accessReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026
What is it?

An unauthenticated attacker can take over an affected Oracle WebCenter Content server with an HTTP request, potentially affecting connected products as well.

Why should healthcare care?

A hospital using WebCenter Content for policy, intranet or administrative documents could have those documents exposed, altered or made unavailable if the server is taken over.

What is the remediation?

Identify self-managed WebCenter Content 12.2.1.4.0 and 14.1.2.0.0 instances reachable over HTTP from untrusted networks, then remove that reachability with network controls.

Affected versions

12.2.1.4.0 and 14.1.2.0.0

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

CVE-2026-60606Oracle PeopleSoft Enterprise CC Common Application ObjectsNewCritical · CVSS 3.1 9.1 (Oracle/CNA)
Rank 2No confirmed exploitation; not in CISA KEV at cutoffExposure assessment · contain accessReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026
What is it?

An unauthenticated attacker can use HTTP requests to read, create, alter or delete data available through PeopleSoft Common Application Objects 9.2.

Why should healthcare care?

A hospital using PeopleSoft 9.2 for HR, payroll, finance or supply-chain administration could have records and transactions disclosed or changed through the affected component.

What is the remediation?

Identify PeopleSoft Enterprise CC Common Application Objects 9.2 endpoints reachable over HTTP from untrusted networks, then restrict access to trusted networks until the release-specific PUM/PRP custom change package is deployed.

Affected versions

9.2

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

CVE-2026-66040FFmpegNewHigh · CVSS 4.0 8.7 (VulnCheck/CNA)
Rank 3No confirmed exploitation; not in CISA KEV at cutoffInterim containmentReported 21 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026
What is it?

A crafted PNG or APNG eXIf chunk can make FFmpeg write past a heap buffer, crashing the process or potentially running attacker-controlled code.

Why should healthcare care?

Healthcare web, imaging-export or communications systems that encode untrusted PNG or APNG files with FFmpeg could suffer a media-processing outage or code execution under the service account.

What is the remediation?

Disable or isolate FFmpeg PNG/APNG encoding for untrusted input carrying eXIf metadata until a supported fixed release or backport is available.

Affected versions

FFmpeg 8.1.2 and earlier

First reported

21 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Alternative authoritative CVSS

High · CVSS 3.1 8.8 (NVD)

CVE-2026-56167Microsoft Azure AI SearchNewHigh · CVSS 3.1 8.5 (Microsoft/CNA)
Rank 4No confirmed exploitation; not in CISA KEV at cutoffVendor-managed · no customer actionReported 23 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026
What is it?

An authorized attacker could exploit server-side request forgery in Azure AI Search to cross a service boundary and gain additional privileges.

Why should healthcare care?

If Azure AI Search indexes clinical, research or administrative content, an authorized account could reach resources outside its intended search-service boundary.

What is the remediation?

No customer action is required; Microsoft reports Azure AI Search is fully mitigated as a hosted service.

Affected versions

Authoritative record does not specify

First reported

23 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

CVE-2026-10818WPForms ProNewHigh · CVSS 3.1 8.1 (Wordfence/CNA)
Rank 5No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 25 July 2026 · First tracked 27 July 2026Tracker drops 24 August 2026
What is it?

WPForms Pro writes uploaded chunks before checking their file type, allowing an unauthenticated attacker to place a potentially executable file on the WordPress host.

Why should healthcare care?

A healthcare website using WPForms Pro for public appointment, referral or contact forms could have its WordPress host compromised through the upload flaw, disrupting the site or exposing data available to that host.

What is the remediation?

Upgrade WPForms Pro to version 1.10.2 or later.

Affected versions

WPForms Pro 1.10.1.1 and earlier

First reported

25 July 2026

First tracked by CCD

27 July 2026

Tracker drop date

24 August 2026

Clinical Engineering & Medical Device Watch

Immediate stop-use instructionFDA Early Alert — potentially high risk · classification pending

Clinical Engineering

FDA directs removal of affected ENROUTE neuroprotection catheters

The ENROUTE Transcarotid Neuroprotection System and ENROUTE Transcarotid Neuroprotection System Plus reverse blood flow to carry emboli away from carotid circulation before lesion crossing and during lesion manipulation. Specific lots can experience arterial sheath-tip separation or partial separation during use. A retained tip may require endovascular or surgical retrieval and can lead to embolism, stroke, transient ischemic attack, restenosis or thrombosis. Boston Scientific reported one serious injury and no deaths as of July 9.

FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should stop using and segregate affected product, return it and trace units distributed to downstream facilities. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.

Read the FDA ENROUTE Early Alert
Immediate stop-use instructionFDA Early Alert — potentially high risk · classification pending

Clinical Engineering

FDA flags three lots of Baxter Duo-Vent administration sets

Baxter Duo-Vent solution sets deliver fluid into the vascular system. Affected lots can develop air bubbles in the drip chamber and tubing when a pressure cuff is used or the tubing is flushed in the fully open position. Without an air-in-line detector, air can reach the patient; patients with a patent foramen ovale or another right-to-left shunt face the risk of stroke, myocardial ischemia or death. Baxter reported no serious injuries or deaths as of July 15.

FDA identifies this as a potentially high-risk Early Alert, with recall classification pending. Facilities should quarantine and stop using affected lots, return them and obtain replacements. This is a clinical-engineering and inventory-control issue, not a cybersecurity incident.

Read the FDA Baxter Early Alert

CCD CVE Tracker

New, updated and continuing vulnerabilities under active CCD watch.

17Active watch
5New this week
0Updated this week
12Continuing watch
1 Critical2 KEV / known exploited
New this week0 additional new CVEs — 5 shown in Priority CVEs
Updated this week0 updated CVEs
Continuing watch12 continuing CVEs
CVE-2026-8655NetScaler ADCContinuing watchCVSS 9.8
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

Memory-overflow flaws can deny service when NetScaler ADC operates as an Oracle load balancer, DNS proxy or recursive resolver.

Why should healthcare care?

A hospital using an affected NetScaler ADC for Oracle load balancing or DNS could lose application routing or name resolution.

What is the remediation?

Install NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later on affected Oracle load-balancer or DNS appliances, checking the configuration strings listed in CTX696604 to identify applicable systems.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-8452NetScaler ADC and NetScaler GatewayContinuing watchCVSS 9.8
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

A memory-overflow flaw can make an affected NetScaler Gateway or AAA virtual server behave unpredictably or stop serving traffic.

Why should healthcare care?

A hospital using NetScaler for SSL VPN, ICA Proxy, CVPN, RDP Proxy or AAA access could lose remote-access or authentication availability during an attack.

What is the remediation?

Upgrade affected Gateway or AAA appliances to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, using add authentication vserver and add vpn vserver entries to identify applicable configurations.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-8451NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

Insufficient input validation can make a NetScaler appliance configured as a SAML identity provider read past a memory boundary.

Why should healthcare care?

A hospital using a customer-managed NetScaler appliance as its SAML identity provider could have appliance memory exposed or sign-on service interrupted.

What is the remediation?

Upgrade affected NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and identify SAML IdP configurations by checking for add authentication samlIdPProfile entries.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-58014GNOME GLib and Red Hat Enterprise Linux glib2Continuing watchHIGH
No confirmed exploitation; not in CISA KEV at cutoffMitigation availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

An empty value in an untrusted .desktop or .ini key file can trigger a one-byte out-of-bounds access in GLib and, in some cases, cause a denial of service.

Why should healthcare care?

General enterprise exposure—not a healthcare-specific finding—this CVE is retained only for organizations whose application inventory contains the affected GLib parser and a path for untrusted .desktop or .ini key files to reach it.

What is the remediation?

Upgrade upstream GLib to 2.88.1 or later; for affected Red Hat packages without an erratum, allow applications to load only trusted key files or reject empty values before calling g_key_file_get_locale_string_list.

Affected versions

Upstream GLib before 2.88.1; vendor-listed RHEL glib2 packages without an available erratum

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-48558SimpleHelpContinuing watchCritical · CVSS 3.1 10.0 (VulnCheck/CNA)
Known exploited; CISA KEVUpgrade availableDue 2 July 2026Reported 29 June 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

A SimpleHelp server can accept an unsigned OIDC identity token and grant an unauthenticated attacker a technician session, potentially bypassing multifactor authentication.

Why should healthcare care?

A hospital using OIDC for SimpleHelp technician login could give an attacker a trusted remote-support session with access to managed endpoints.

What is the remediation?

Upgrade SimpleHelp 5.5 deployments to 5.5.16 or later and 6.0 prereleases to 6.0 RC2 or later; if the update cannot be completed immediately, disconnect or stop the server until the exposure is resolved.

Affected versions

SimpleHelp 5.5.15 and earlier; SimpleHelp 6.0 prereleases before RC2

Remediation due

2 July 2026

First reported

29 June 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

Alternative authoritative CVSS

Critical · CVSS 4.0 9.5 (VulnCheck/CNA)

CVE-2026-45659Microsoft SharePoint ServerContinuing watchHigh · CVSS 3.1 8.8 (Microsoft/CNA)
Known exploited; CISA KEVPatch available — KB5002868 / KB5002870 / KB5002863Due 4 July 2026Reported 1 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

An authenticated SharePoint site member can send untrusted serialized data to an on-premises server and execute code remotely.

Why should healthcare care?

A hospital running on-premises SharePoint for internal documents or collaboration could have the server taken over and its content exposed or altered by an authenticated site member.

What is the remediation?

Install KB5002868 on SharePoint 2016, KB5002870 on SharePoint 2019 or KB5002863 on SharePoint Subscription Edition, reaching builds 16.0.5552.1002, 16.0.10417.20128 or 16.0.19725.20280 respectively.

Affected versions

SharePoint Server 2016 before build 16.0.5552.1002; SharePoint Server 2019 before 16.0.10417.20128; SharePoint Subscription Edition before 16.0.19725.20280

Remediation due

4 July 2026

First reported

1 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-13784Google ChromeContinuing watchHIGH
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

A second use-after-free in Chrome Views can corrupt heap memory when a user performs specific gestures on a crafted HTML page.

Why should healthcare care?

A healthcare endpoint running an older Chrome build could lose browser integrity or availability when its user interacts with a malicious page.

What is the remediation?

Install Chrome 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-13783Google ChromeContinuing watchHIGH
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

A crafted web page and specific user-interface gestures can trigger a use-after-free in Chrome Views and corrupt heap memory.

Why should healthcare care?

A hospital user browsing external content with an outdated Chrome build could have the browser compromised or crashed after interacting with a crafted page.

What is the remediation?

Update Windows and macOS endpoints to Chrome 150.0.7871.47 or later and Linux endpoints to 150.0.7871.46 or later.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-13774Google ChromeContinuing watchHIGH
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 2 July 2026 · First tracked 2 July 2026Tracker drops 30 July 2026
What is it?

A malicious Chrome extension can trigger a use-after-free in the Extensions component and execute attacker-controlled code.

Why should healthcare care?

On hospital workstations that permit extension installation, a user who installs a malicious Chrome extension could run attacker code in the browser context.

What is the remediation?

Update desktop Chrome to 150.0.7871.47 or later on Windows and macOS or 150.0.7871.46 or later on Linux, and enforce the managed-browser extension allowlist.

Affected versions

Chrome before 150.0.7871.47 on Windows/macOS or before 150.0.7871.46 on Linux

First reported

2 July 2026

First tracked by CCD

2 July 2026

Tracker drop date

30 July 2026

CVE-2026-13474NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5
No confirmed exploitation; not in CISA KEV at cutoffConfiguration change availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026
What is it?

Malformed HTTP/2 requests can exhaust resources on an affected NetScaler virtual server and stop it from serving traffic.

Why should healthcare care?

A hospital using an HTTP/2-enabled NetScaler virtual server for load balancing, content switching or VPN access could lose access to applications or remote connectivity during an attack.

What is the remediation?

Upgrade to NetScaler 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later and, on non-HTTP-Strict profiles, run set ns httpProfile <profile_name> -http2SmallWndTimeout 30.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

CVE-2026-10817NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026
What is it?

Malformed traffic can make a NetScaler TCP profile read past its memory boundary when TCP timestamps are enabled, potentially disclosing appliance memory.

Why should healthcare care?

A hospital virtual server or service using a timestamp-enabled NetScaler TCP profile could expose appliance memory through malformed traffic.

What is the remediation?

Upgrade affected NetScaler services to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, then inventory profiles with TimeStamp ENABLED and map them to virtual servers and services.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

CVE-2026-10816NetScaler ADC and NetScaler GatewayContinuing watchCVSS 7.5
No confirmed exploitation; not in CISA KEV at cutoffUpgrade availableReported 3 July 2026 · First tracked 3 July 2026Tracker drops 31 July 2026
What is it?

An unauthenticated attacker on an adjacent network can read arbitrary appliance files when a NetScaler management address is reachable.

Why should healthcare care?

A hospital with a reachable NetScaler management address could have configuration or other appliance-accessible files disclosed without authentication.

What is the remediation?

Update management-reachable NetScaler appliances to 14.1-72.61, 13.1-63.18, 14.1-72.61 FIPS or 13.1-37.272 FIPS/NDcPP or later, and restrict access to NSIP, Cluster Management IP and management-enabled SNIP addresses.

Affected versions

NetScaler 14.1 before 14.1-72.61; 13.1 before 13.1-63.18; 14.1 FIPS before 14.1-72.61; 13.1 FIPS/NDcPP before 13.1-37.272

First reported

3 July 2026

First tracked by CCD

3 July 2026

Tracker drop date

31 July 2026

9 records left active watch this week — view archive

Sources and Methodology

Evidence window: 20–26 July 2026; cutoff 27 July at 12:00 a.m. America/New_York.

Open Source Index
Issue-level sources 3
  1. Health-ISAC ShinyHunters advisory
  2. CVE Program CNA record (Wordfence)
  3. WPForms changelog
Healthcare Incident Watch 3
  1. Craneware incident notice
  2. Health-ISAC ShinyHunters advisory
  3. AnMed systems disruption notice
Regulatory & Privacy 4
  1. Health Sector Coordinating Council
  2. Health-ISAC CISO Benchmarking Report
  3. Health-ISAC Quarterly Threat Insights
  4. FDA TEMPO announcement
AI & Clinical Automation Watch 3
  1. OpenAI security disclosure
  2. Health-ISAC Quarterly Threat Insights
  3. FDA TEMPO announcement
Other supporting sources 2
  1. FDA ENROUTE Early Alert
  2. FDA Baxter Duo-Vent Early Alert
CVE sources 35
  1. Oracle Cpu
  2. Cve Cve-2026-60644
  3. Oracle WebCenter Content 12c Marketplace 26.7.1
  4. Oracle WebCenter Content 14c Marketplace 26.7.1
  5. Cve Cve-2026-60606
  6. Oracle PeopleSoft security-fix process
  7. Ffmpeg Patch
  8. Cve Cve-2026-66040
  9. FFmpeg official releases
  10. FFmpeg security and backport status
  11. Wpforms Changelog
  12. Cve Cve-2026-10818
  13. Msrc Azure
  14. Msrc Azure Products
  15. Cve Cve-2026-56167
  16. Netscaler Bulletin
  17. Cve Cve-2026-10816
  18. Cve Cve-2026-10817
  19. Cve Cve-2026-13474
  20. Chrome Release
  21. Cve Cve-2026-13774
  22. Cve Cve-2026-13783
  23. Cve Cve-2026-13784
  24. Msrc Sharepoint
  25. Msrc Sharepoint Products
  26. Cve Cve-2026-45659
  27. Simplehelp Notice
  28. Simplehelp Release
  29. Cve Cve-2026-48558
  30. CISA Known Exploited Vulnerabilities catalog (linked in applicable CVE records)
  31. Redhat Cve
  32. Cve Cve-2026-58014
  33. Cve Cve-2026-8451
  34. Cve Cve-2026-8452
  35. Cve Cve-2026-8655

Clinical Cyber Dispatch

Independent healthcare cybersecurity analysis for security and technology leaders.