CISA warns admins to patch actively exploited SharePoint flaws

2026-07-15T13:23:33Z59d1ae8d5d429f8df41ff9a217ee89e3d66e050dbb9d343ed4a073725030a93b
bulletproof-hostingcommerce-cloudcve-2026-15409cve-2026-15410dellentra-idgithub-malwareinfostealerjaliscokb5099539law-enforcementmfa-bypassmicrosoft-patch-tuesdaynetweaveromegalordpasskeysphishingprogresssapsharefilesharepointsonicwallvulnerabilitieswindows-updateszero-day

What happened

Multiple high-impact security developments: CISA warns that attackers are actively exploiting three vulnerabilities in Internet-exposed on-premises SharePoint Server instances and urges immediate patching. SonicWall reports in-the-wild exploitation of two SMA1000 zero-days (CVE-2026-15409, CVE-2026-15410) and has released fixes. Microsoft issued the July 2026 Patch Tuesday covering a record 570 flaws (including multiple zero-days) and released the Windows 10 extended update KB5099539; some recent Windows 11 updates are being blocked on affected Dell devices due to shutdowns. Progress confirmed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
59d1ae8d5d429f8df41ff9a217ee89e3d66e050dbb9d343ed4a073725030a93b
Enrichment time
2026-07-15T13:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA warns admins to patch actively exploited SharePoint flaws · Baitaphish