Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands

2026-07-15T07:24:07Z87ff69137afedb579dff1c66b0d74f80128c1c8e8b35745c4b798b388291c547
CVE-2026-15409CVE-2026-44747CVE-2026-48939SMA 1000SSRFcrashstealerforg365joomlajscramblerlabubaratmicrosoftmodheadernpmoauthpatch-tuesdayphishing-as-a-service (PhaaS)rabbitmqratsapsecure-bootsonicwallsupply-chainuefiuefi-shimszero-day

What happened

The feed highlights multiple high-impact active threats and supply-chain incidents: SonicWall SMA 1000 appliances are under active exploitation of two zero-days (notably CVE-2026-15409, an SSRF leading to possible arbitrary command execution). Microsoft released a record 622 fixes including two zero-days under active attack. SAP patched a critical NetWeaver ABAP out‑of‑bounds write (CVE-2026-44747, CVSS 9.9). Joomla iCagenda and Balbooa Forms flaws (including CVE-2026-48939, CVSS 10.0) are reported as exploited zero-days. Other notable items: RabbitMQ access-control flaws that can leak OAuth/跨

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
87ff69137afedb579dff1c66b0d74f80128c1c8e8b35745c4b798b388291c547
Enrichment time
2026-07-15T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.