This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.
Last updated: 21 July 2026 · Week 30 / 2026 · Next update: 28 July 2026
Every week we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.
Seven confirmed vulnerabilities in software used by UK businesses were added to the US government's active exploitation list this week alone. That is the highest weekly count since January. The affected software includes Microsoft SharePoint, Microsoft's identity management system, Fortinet security equipment, and — strikingly — a piece of Cisco networking software with a vulnerability first identified in 2008 that is only now being actively exploited by criminals. This week's threat level is raised to High. If your business has not reviewed its patching and access controls recently, this week is the week to do it.
Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:
If your business uses Microsoft 365 — and the majority of UK businesses do — your organisation almost certainly uses something called Active Directory Federation Services, or ADFS. It is the layer that manages who is allowed to log in, what they can access, and how different Microsoft systems recognise each other. It is, in effect, the keymaster for your entire Microsoft environment.
This week, a confirmed vulnerability in ADFS (CVE-2026-56155) was added to the US government's actively-exploited list. The vulnerability allows an attacker who already has a standard user account — perhaps obtained through a phishing email or a previous breach — to elevate their privileges to administrator level. Once at administrator level, they can access everything: email, SharePoint, Teams, your file storage, your backup systems.
At the same time, Microsoft SharePoint has received its third confirmed vulnerability in four weeks. This one (CVE-2026-56164) requires no login at all — an unauthenticated attacker on your network can use it to elevate their privileges directly. The pattern of repeated SharePoint vulnerabilities in consecutive weeks is unusual and worth taking seriously.
And in an editorial detail that tells you something important about how cyber attacks work: a Cisco networking vulnerability first discovered in 2008 — eighteen years ago — was added to the active exploitation list this week. Criminal groups are scanning for and successfully exploiting vulnerabilities in equipment that businesses installed years ago and have never patched.
Microsoft releases security patches on the second Tuesday of each month — this is known as Patch Tuesday, and July's round included fixes for the ADFS and SharePoint vulnerabilities confirmed exploited this week. If your IT provider manages your Microsoft environment, they should have applied these automatically. But "should have" and "has been" are not the same thing. Contact them today and ask specifically: have the July 2026 Microsoft security patches been applied, and in particular the patches for Active Directory Federation Services (CVE-2026-56155) and SharePoint (CVE-2026-56164 and CVE-2026-58644)? You do not need to understand what those reference numbers mean — the question is enough. A well-run IT provider will confirm within hours.
Why now: Both vulnerabilities were added to CISA's active exploitation list on 14–16 July 2026. They are being used in real attacks on real organisations right now. The patches exist — the risk is entirely in whether they have been applied.
Cisco IOS 12.4 — a version of Cisco's networking software released in the mid-2000s — has just had an 18-year-old vulnerability added to the active exploitation list. This means criminals are scanning for and successfully attacking networking equipment running software that has not been updated since before the iPhone existed. If your office has Cisco switches, routers, or other networking equipment, ask your IT provider: what version of software is it running, and is it still receiving security updates from Cisco? Equipment running end-of-support software will never receive patches for new vulnerabilities. The only solution for truly end-of-life equipment is replacement. If cost is a concern, prioritise any equipment that faces the internet — switches inside the office are lower risk than routers and firewalls that connect to the outside world.
Why now: CVE-2008-4128 — an 18-year-old vulnerability in Cisco IOS — was added to CISA's active exploitation list on 13 July 2026. Legacy networking equipment is a live attack surface today, not a theoretical future risk.
The National Cyber Security Centre this week announced a free hands-on cyber consultancy programme specifically for UK small businesses. This is not a generic government guidance document — it is practical consultancy support. For businesses that have been deferring a security review because of cost, this removes the cost barrier. Visit ncsc.gov.uk and search for the small business consultancy programme. If you work with clients, suppliers, or professional contacts who you know have not addressed their cyber security posture, forwarding them this resource is a genuinely useful thing to do. It also positions you as someone who is across the current landscape — which is exactly the kind of trust-building that matters in financial services relationships.
Why now: NCSC published this programme on 15 July 2026. Free, government-backed, hands-on. Cost is one of the most common barriers small businesses cite for not addressing cyber security — this removes it.
A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.
Book a Free Resilience Scan → View Technical Version