SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now

2026-07-15T07:23:27Z7877a3dc27895c96c4cc4d28c567a1ce9894cc383bd1933fb73ef3fb3b030bca
GitHub-malwareMFA-bypassMicrosoft Patch TuesdayOFAC-sanctionsProgress ShareFileSAPSMA1000SonicWallexploitationinfostealerlaw-enforcement-takedownpatch-nowphishingzero-day

What happened

Multiple high-impact security events reported: SonicWall warns that two SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) are being exploited in active zero-day attacks and urges immediate patching. Microsoft released its July 2026 Patch Tuesday update covering 570 flaws (including multiple zero-days), and SAP and Progress also published fixes for critical/zero-day issues affecting enterprise products. Additional notable threats include hundreds of fake GitHub repos distributing infostealer malware, new MFA-bypassing phishing kits (Jalisco, OmegaLord), targeted phishing against password

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7877a3dc27895c96c4cc4d28c567a1ce9894cc383bd1933fb73ef3fb3b030bca
Enrichment time
2026-07-15T07:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now · Baitaphish