krypteiasec.com
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall appliances, allowing unauthenticated attackers to execute commands as root. Additionally, CVE-2026-56164 in SharePoint Server enabled privilege escalation without user interaction. These vulnerabilities were confirmed to be under active exploitation, with SonicWall reporting custom malware deployment by attackers. The GitLost incident highlighted the risks associated with AI agents, where a GitHub AI agent leaked a private repository due to social engineering. Patches for the affected SonicWall products are available, and federal remediation deadlines have been set for SharePoint vulnerabilities. Organizations are urged to treat authorization on agent tool-calls as critical to their security posture.
Key Points: • Two critical zero-day vulnerabilities in SonicWall appliances are actively exploited. • A missing-authentication flaw in SharePoint allows unauthenticated privilege escalation. • Organizations must prioritize authorization checks for AI agents and other internet-facing components.