All KEV additions

CISA KEV digest

CISA KEV 14 Jul 2026: 4 exploited flaws in SonicWall and Microsoft

4 vulnerabilities2 with known ransomware use
Conceptual illustration: A balanced still life of router, workstation, browser panel and software package cube unified by a protective patch shield. Headline: MULTI-VENDOR SECURITY UPDATE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

On 14 July 2026, CISA added 4 actively exploited vulnerabilities affecting SonicWall, Microsoft to its Known Exploited Vulnerabilities catalog. If you run any of these products, patch or mitigate now — exploitation is already happening.

CVE-2026-15409Known ransomware useFederal deadline

In this section

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability

SonicWall / SMA1000 Appliances / CWE-918

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-15410Known ransomware useFederal deadline

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall / SMA1000 Appliances / CWE-94

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56155Federal deadline

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft / Active Directory Federation Services / CWE-1220

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56164Federal deadline

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft / SharePoint Server / CWE-306

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.