SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

2026-07-15T01:23:28Z6b522be1ca8ec2ff376ef7589089d9fd8078496243f33ee33caf673a6cb22add
CVE-2026-15409CVE-2026-15410GitHubKB5099539MFA bypassMicrosoft Patch TuesdayOFAC sanctionsProgressSAPSMA1000ShareFileSonicWallfraud takedowninfostealerpatchphishingransomwaresecurity-updatezero-day

What happened

Multiple high-impact security events and large patch releases: SonicWall warned that two SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) are being exploited in zero-day attacks and urged immediate patching. Microsoft published its July 2026 Patch Tuesday (record 570 flaws) and an extended KB (KB5099539) including multiple zero-days; Progress confirmed a ShareFile Storage Zone zero-day that forced emergency shutdowns; SAP released fixes for several critical issues. Other coverage includes hundreds of fake GitHub repos pushing infostealers, phishing campaigns targeting LastPass/Bitward­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
6b522be1ca8ec2ff376ef7589089d9fd8078496243f33ee33caf673a6cb22add
Enrichment time
2026-07-15T01:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.