SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
2026-07-15T07:23:27Z•7877a3dc27895c96c4cc4d28c567a1ce9894cc383bd1933fb73ef3fb3b030bca
GitHub-malwareMFA-bypassMicrosoft Patch TuesdayOFAC-sanctionsProgress ShareFileSAPSMA1000SonicWallexploitationinfostealerlaw-enforcement-takedownpatch-nowphishingzero-day
What happened
Multiple high-impact security events reported: SonicWall warns that two SMA1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) are being exploited in active zero-day attacks and urges immediate patching. Microsoft released its July 2026 Patch Tuesday update covering 570 flaws (including multiple zero-days), and SAP and Progress also published fixes for critical/zero-day issues affecting enterprise products. Additional notable threats include hundreds of fake GitHub repos distributing infostealer malware, new MFA-bypassing phishing kits (Jalisco, OmegaLord), targeted phishing against password
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 7877a3dc27895c96c4cc4d28c567a1ce9894cc383bd1933fb73ef3fb3b030bca
- Enrichment time
- 2026-07-15T07:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.