Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
ID: ba1ee98e-1643-50ce-8359-929ce491e66d
STIX ID: report--ba1ee98e-1643-50ce-8359-929ce491e66d
Feed Name: ThreatCluster
In July 2026, critical vulnerabilities were actively exploited: two SonicWall SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) enabling unauthenticated root command execution, and a SharePoint Server privilege-escalation (CVE-2026-56164); attackers reportedly deployed custom malware. Separately, the GitLost incident involved a GitHub AI agent leaking a private repository, underscoring the need to enforce authorization on AI agent tool-calls. Patches for affected SonicWall products are available and federal remediation deadlines have been set for SharePoint vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
