top of page

CISA Flags Four Actively Exploited CVEs: Microsoft AD FS, SharePoint, and SonicWall Under Attack

  • Writer: Sean Ebeling
    Sean Ebeling
  • Jul 15
  • 2 min read

TL;DR

CISA added four CVEs to its Known Exploited Vulnerabilities catalog on July 14, 2026, covering two SonicWall SMA1000 appliance flaws and two Microsoft zero-days in Active Directory Federation Services and SharePoint Server. Both Microsoft vulnerabilities are confirmed exploited in the wild and landed on the same day as the largest Patch Tuesday on record, covering 622 CVEs. Federal agencies face patch deadlines of July 17 for the SharePoint flaw and July 28 for the AD FS flaw.


The week of July 14, 2026 saw CISA confirm active exploitation across enterprise identity and collaboration infrastructure, with four new KEV entries spanning network edge appliances and core Microsoft services. The additions coincide with Microsoft releasing its largest-ever single-month security update, raising the stakes for security teams who must triage a historically large patch volume while prioritizing confirmed in-the-wild threats. SonicWall had already issued advisories for its SMA1000 flaws, while the two Microsoft zero-days were patched the same day CISA listed them.




CVE-2026-56155: Microsoft AD FS Elevation of Privilege Exploited in the Wild


Active Directory Federation Services contains an access control flaw that allows a low-privileged local attacker to gain administrator-level access, with a CVSS score of 7.8. Microsoft confirmed its own incident responders observed exploitation in the wild, and Zero Day Initiative warned the bug can be chained with an RCE vulnerability as frequently seen in ransomware incidents. Federal agencies must patch by July 28, 2026, and Microsoft is hardening the AD FS Distributed Key Manager ACL as part of the fix rollout.



CVE-2026-56164: Microsoft SharePoint Server Missing Auth Flaw Actively Exploited


SharePoint Server contains a missing authentication vulnerability allowing an unauthenticated attacker to elevate privileges over the network with low attack complexity and no required user interaction. CISA separately urged SharePoint hardening after confirming exploitation of three SharePoint CVEs, including this one, involving RCE and post-exploitation persistence techniques such as IIS machine key theft. The fix requires deploying the correct SharePoint-specific update on every server in a farm, not just the standard Windows cumulative update, with a federal deadline of July 17, 2026.



CVE-2026-15409 and CVE-2026-15410: SonicWall SMA1000 SSRF and Code Injection Pair


CISA added two SonicWall SMA1000 vulnerabilities on the same day: a server-side request forgery flaw allowing unauthenticated attackers to force the appliance to reach internal systems, and a code injection flaw that can let a remote authenticated administrator execute arbitrary OS commands. Security analysts flagged the simultaneous listing as a sign attackers may be chaining the two bugs, turning a trusted remote-access gateway into an internal pivot point. SonicWall had already published advisories, and CISA directs organizations to apply vendor firmware updates immediately.





References


 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page