criticalZero-Day

CISA KEV Catalog Update: SonicWall SMA1000 and Microsoft ADFS/SharePoint Actively Exploited Vulnerabilities

First seen Jul 15, 2026 · Updated Jul 15, 2026

CISAKEVSonicWallSSRFcode-injectionMicrosoftActive-DirectorySharePointfederalBOD-26-04agent-relevant

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, affecting SonicWall SMA1000 appliances (SSRF and code injection) and Microsoft Active Directory Federation Services and SharePoint Server (access control and authentication bypass issues). These flaws are being actively exploited in the wild and pose significant risk to federal and enterprise networks, with BOD 26-04 mandating rapid remediation for FCEB agencies.

Technical Analysis

CVE-2026-15409 and CVE-2026-15410 affect SonicWall SMA1000 appliances, enabling server-side request forgery and code injection respectively, which can allow attackers to pivot into internal networks or achieve remote code execution on edge access infrastructure. CVE-2026-56155 is an insufficient access control granularity flaw in Microsoft Active Directory Federation Services (ADFS), potentially allowing privilege escalation or unauthorized access to federated identity tokens. CVE-2026-56164 is a missing authentication vulnerability in Microsoft SharePoint Server that could allow unauthenticated attackers to reach critical functions, risking data exposure or further compromise. Given that SonicWall SMA1000 devices are commonly used as remote access gateways and ADFS/SharePoint are core identity and collaboration infrastructure, compromise of these systems could expose credentials, API keys, and session tokens used by AI agents and automation pipelines that authenticate through federated identity or access internal resources via these gateways, indirectly enabling downstream agent-relevant compromise.

Affected Systems

SonicWall SMA1000 series appliances (all firmware versions vulnerable to CVE-2026-15409 and CVE-2026-15410); Microsoft Active Directory Federation Services (ADFS) affected by CVE-2026-56155; Microsoft SharePoint Server affected by CVE-2026-56164

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided in source data

Remediation Steps

  1. 1

    Apply Vendor Patches

    Immediately apply SonicWall and Microsoft security updates addressing CVE-2026-15409, CVE-2026-15410, CVE-2026-56155, and CVE-2026-56164.

  2. 2

    Follow BOD 26-04 Guidance

    FCEB agencies must prioritize remediation per Binding Operational Directive 26-04, including checking for prior compromise before patching internet-facing assets granting full asset control.

  3. 3

    Restrict Exposure

    Limit public exposure of SonicWall SMA1000 management interfaces and SharePoint/ADFS endpoints where possible, using network segmentation and access controls.

  4. 4

    Audit Federated Identity and API Credentials

    Review and rotate credentials, API keys, and tokens used by internal systems, including AI agent and automation frameworks, that authenticate via ADFS or access resources through affected gateways.

  5. 5

    Monitor for Exploitation Indicators

    Review logs on SonicWall SMA1000, ADFS, and SharePoint servers for signs of unauthorized access or anomalous requests consistent with SSRF, code injection, or authentication bypass activity.

CVE / Advisory IDs

CVE-2026-15409CVE-2026-15410CVE-2026-56155CVE-2026-56164

Industries Most Exposed

GovernmentFederal Civilian Executive BranchEnterprise ITFinancial ServicesHealthcareCritical Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.