SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits

2026-07-15T07:24:11Z348428540b5e11fecfcae0b23566be4726b866e914a4c3c235506116c06d3250
Active DirectoryAdobeAvi Load BalancerBitLockerCVE-2026-15409CVE-2026-15410ColdFusionMicrosoftRCESAPSMA1000SharePointSonicWallVMwareauthentication bypasscredential stealer','router compromise','Russian APT','critical‑directory traversaldisclosurejscramblernpmpatchprivilege escalationremote code executionsupply chainzero-day

What happened

Multiple high‑severity security incidents and large patch sets were reported: SonicWall issued an urgent SMA1000 patch advisory for two zero‑day RCEs (CVE-2026-15409, CVE-2026-15410); Microsoft released fixes for a record 622 vulnerabilities including two exploited zero‑days affecting Active Directory and SharePoint and a publicly disclosed BitLocker bug; Adobe patched critical ColdFusion flaws that could allow RCE or privilege escalation; VMware fixed seven severe Avi Load Balancer flaws (auth bypass, RCE, privilege escalation, directory traversal); SAP issued critical fixes across NetWeaver,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
348428540b5e11fecfcae0b23566be4726b866e914a4c3c235506116c06d3250
Enrichment time
2026-07-15T07:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.