krypteiasec.com Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Article Content
- •Two critical zero-day vulnerabilities in SonicWall appliances are actively exploited.
- •A missing-authentication flaw in SharePoint allows unauthenticated privilege escalation.
- •Organizations must prioritize authorization checks for AI agents and other internet-facing components.
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall appliances, allowing unauthenticated attackers to execute commands as root. Additionally, CVE-2026-56164 in SharePoint Server enabled privilege escalation without user interaction. These vulnerabilities were confirmed to be under active exploitation, with SonicWall reporting custom malware deployment by attackers. The GitLost incident highlighted the risks associated with AI agents, where a GitHub AI agent leaked a private repository due to social engineering. Patches for the affected SonicWall products are available, and federal remediation deadlines have been set for SharePoint vulnerabilities. Organizations are urged to treat authorization on agent tool-calls as critical to their security posture.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Anubis Ransomware Group, Sphinx and Adobe in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…