Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems

Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems

First seen 28 Jul 2026, 03:50 UTC Buttondownkrypteiasec.comnoma.securitywww.helpnetsecurity.com 93% similarity 74.6

Article Content

Browse articles
ThreatCluster

In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall appliances, allowing unauthenticated attackers to execute commands as root. Additionally, CVE-2026-56164 in SharePoint Server enabled privilege escalation without user interaction. These vulnerabilities were confirmed to be under active exploitation, with SonicWall reporting custom malware deployment by attackers. The GitLost incident highlighted the risks associated with AI agents, where a GitHub AI agent leaked a private repository due to social engineering. Patches for the affected SonicWall products are available, and federal remediation deadlines have been set for SharePoint vulnerabilities. Organizations are urged to treat authorization on agent tool-calls as critical to their security posture.

Key Points: • Two critical zero-day vulnerabilities in SonicWall appliances are actively exploited. • A missing-authentication flaw in SharePoint allows unauthenticated privilege escalation. • Organizations must prioritize authorization checks for AI agents and other internet-facing components.

ThreatCluster AI How this analysis works

Timeline

2025-08-05
CVE-2025-54253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-28
CVE-2026-46817 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-23
CVE-2026-55255 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-30
CVE-2026-48282 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15409 published
Critical unauthenticated server-side request forgery flaw in SonicWall appliances disclosed.
krypteiasec.com
2026-07-14
CVE-2026-15410 published
Command injection vulnerability in SonicWall appliances allowing root code execution disclosed.
krypteiasec.com
2026-07-14
CVE-2026-56164 published
Missing-authentication vulnerability in SharePoint Server allowing privilege escalation disclosed.
krypteiasec.com
2026-07-14
CVE-2026-56155 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-50661 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-17
CISA remediation deadline set
CISA established a federal remediation deadline for SharePoint vulnerabilities.
krypteiasec.com

Community

Browse all →