CISA KEV Catalog Update: SonicWall SMA1000 and Microsoft ADFS/SharePoint Actively Exploited Vulnerabilities
First seen Jul 15, 2026 · Updated Jul 15, 2026
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, affecting SonicWall SMA1000 appliances (SSRF and code injection) and Microsoft Active Directory Federation Services and SharePoint Server (access control and authentication bypass issues). These flaws are being actively exploited in the wild and pose significant risk to federal and enterprise networks, with BOD 26-04 mandating rapid remediation for FCEB agencies.
Technical Analysis
CVE-2026-15409 and CVE-2026-15410 affect SonicWall SMA1000 appliances, enabling server-side request forgery and code injection respectively, which can allow attackers to pivot into internal networks or achieve remote code execution on edge access infrastructure. CVE-2026-56155 is an insufficient access control granularity flaw in Microsoft Active Directory Federation Services (ADFS), potentially allowing privilege escalation or unauthorized access to federated identity tokens. CVE-2026-56164 is a missing authentication vulnerability in Microsoft SharePoint Server that could allow unauthenticated attackers to reach critical functions, risking data exposure or further compromise. Given that SonicWall SMA1000 devices are commonly used as remote access gateways and ADFS/SharePoint are core identity and collaboration infrastructure, compromise of these systems could expose credentials, API keys, and session tokens used by AI agents and automation pipelines that authenticate through federated identity or access internal resources via these gateways, indirectly enabling downstream agent-relevant compromise.
Affected Systems
SonicWall SMA1000 series appliances (all firmware versions vulnerable to CVE-2026-15409 and CVE-2026-15410); Microsoft Active Directory Federation Services (ADFS) affected by CVE-2026-56155; Microsoft SharePoint Server affected by CVE-2026-56164
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source data
Remediation Steps
- 1
Apply Vendor Patches
Immediately apply SonicWall and Microsoft security updates addressing CVE-2026-15409, CVE-2026-15410, CVE-2026-56155, and CVE-2026-56164.
- 2
Follow BOD 26-04 Guidance
FCEB agencies must prioritize remediation per Binding Operational Directive 26-04, including checking for prior compromise before patching internet-facing assets granting full asset control.
- 3
Restrict Exposure
Limit public exposure of SonicWall SMA1000 management interfaces and SharePoint/ADFS endpoints where possible, using network segmentation and access controls.
- 4
Audit Federated Identity and API Credentials
Review and rotate credentials, API keys, and tokens used by internal systems, including AI agent and automation frameworks, that authenticate via ADFS or access resources through affected gateways.
- 5
Monitor for Exploitation Indicators
Review logs on SonicWall SMA1000, ADFS, and SharePoint servers for signs of unauthorized access or anomalous requests consistent with SSRF, code injection, or authentication bypass activity.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.