On 14 July CISA added four CVEs to the Known Exploited Vulnerabilities catalog - SharePoint, two bugs in SonicWall SMA1000, and AD FS. Three different surfaces. Confirmed exploitation on every one. Two of the deadlines fall on 17 July.
- CISA confirms active exploitation of four CVEs at once - SharePoint, SonicWall SMA1000 (two bugs) and AD FS.
- SonicWall SMA1000 carries CVSS 10.0 - an unauthenticated SSRF that chains with a second bug into full RCE.
- Three of the four deadlines for US federal agencies fall on 17 July; AD FS waits until 28 July.
CISA doesn't add vulnerabilities to KEV on theory. It adds them when it sees proven exploitation in the real world. On 14 July, four new CVEs landed at once, from three different vendors, across three different surfaces - collaboration, perimeter and identity. Not a routine Friday list.
What's the risk here - not the individual bug, the combination. SonicWall SMA1000 sits on the perimeter, exactly where nobody wants unauthenticated access. A score of 10.0 means the ceiling. There's nothing higher. The second bug in it doesn't stand alone - it turns the first from a serious problem into an open door to full control. Add SharePoint, add AD FS, and you have perimeter, identity and collaboration breached all at once. If you run infrastructure, there's very concrete work here for the weekend.
Got SonicWall SMA1000, SharePoint Server on a public address, or AD FS in your identity stack - the patches wait until the 17th, the 28th at the latest. Don't wait for a maintenance window. CISA only puts something in KEV after confirmed exploitation, never on theory.