SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
2026-07-15T07:24:11Z•348428540b5e11fecfcae0b23566be4726b866e914a4c3c235506116c06d3250
Active DirectoryAdobeAvi Load BalancerBitLockerCVE-2026-15409CVE-2026-15410ColdFusionMicrosoftRCESAPSMA1000SharePointSonicWallVMwareauthentication bypasscredential stealer','router compromise','Russian APT','critical‑directory traversaldisclosurejscramblernpmpatchprivilege escalationremote code executionsupply chainzero-day
What happened
Multiple high‑severity security incidents and large patch sets were reported: SonicWall issued an urgent SMA1000 patch advisory for two zero‑day RCEs (CVE-2026-15409, CVE-2026-15410); Microsoft released fixes for a record 622 vulnerabilities including two exploited zero‑days affecting Active Directory and SharePoint and a publicly disclosed BitLocker bug; Adobe patched critical ColdFusion flaws that could allow RCE or privilege escalation; VMware fixed seven severe Avi Load Balancer flaws (auth bypass, RCE, privilege escalation, directory traversal); SAP issued critical fixes across NetWeaver,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 348428540b5e11fecfcae0b23566be4726b866e914a4c3c235506116c06d3250
- Enrichment time
- 2026-07-15T07:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.