we_are_coded.by CODE · The world, decoded
БГ
CISA

CISA puts four actively exploited zero-days into KEV in one day

CISASecurity

On 14 July CISA added four CVEs to the Known Exploited Vulnerabilities catalog - SharePoint, two bugs in SonicWall SMA1000, and AD FS. Three different surfaces. Confirmed exploitation on every one. Two of the deadlines fall on 17 July.

In short
  • CISA confirms active exploitation of four CVEs at once - SharePoint, SonicWall SMA1000 (two bugs) and AD FS.
  • SonicWall SMA1000 carries CVSS 10.0 - an unauthenticated SSRF that chains with a second bug into full RCE.
  • Three of the four deadlines for US federal agencies fall on 17 July; AD FS waits until 28 July.
Checked on15 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

CISA doesn't add vulnerabilities to KEV on theory. It adds them when it sees proven exploitation in the real world. On 14 July, four new CVEs landed at once, from three different vendors, across three different surfaces - collaboration, perimeter and identity. Not a routine Friday list.

The facts: CISA added to KEV on 14.07.2026 - CVE-2026-56164 (Microsoft SharePoint Server, missing authentication for a critical function, unauthenticated privilege escalation, deadline for federal agencies 17.07); CVE-2026-15409 (SonicWall SMA1000, unauthenticated SSRF in the WorkPlace interface, CVSS 10.0, affects models 6210, 7210 and 8200v, patch available - hotfix 12.4.3-03453 / 12.5.0-02835+, deadline 17.07); CVE-2026-15410 (SonicWall SMA1000, authenticated code injection in the management console, CVSS 7.2, chains with 15409 into full unauthenticated RCE, deadline 17.07); CVE-2026-56155 (Microsoft AD FS, insufficient granularity of access control, authenticated privilege escalation, deadline 28.07). All four - confirmed active exploitation. Source: CISA Known Exploited Vulnerabilities Catalog; SonicWall PSIRT advisory SNWLID-2026-0009.

What's the risk here - not the individual bug, the combination. SonicWall SMA1000 sits on the perimeter, exactly where nobody wants unauthenticated access. A score of 10.0 means the ceiling. There's nothing higher. The second bug in it doesn't stand alone - it turns the first from a serious problem into an open door to full control. Add SharePoint, add AD FS, and you have perimeter, identity and collaboration breached all at once. If you run infrastructure, there's very concrete work here for the weekend.

Don't look at the CVE numbers one by one - perimeter, identity and collaboration fell on the same day.

Got SonicWall SMA1000, SharePoint Server on a public address, or AD FS in your identity stack - the patches wait until the 17th, the 28th at the latest. Don't wait for a maintenance window. CISA only puts something in KEV after confirmed exploitation, never on theory.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog
Original: https://wearecoded.com/en/articles/cisa-kev-sharepoint-sonicwall-adfs-0714.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news