Executive Summary
On July 14, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating active exploitation. The vulnerabilities include CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA1000 Appliances, CVE-2026-56155 impacting Microsoft Active Directory Federation Services, and CVE-2026-56164 related to Microsoft SharePoint Server. These vulnerabilities are commonly exploited by malicious actors and pose significant risks to federal enterprises. CISA's Binding Operational Directive (BOD) 26-04 emphasizes the importance of promptly addressing such high-risk vulnerabilities to protect federal networks. While BOD 26-04 is mandatory for Federal Civilian Executive Branch agencies, CISA encourages all organizations to adopt risk-based vulnerability management practices and prioritize remediation of vulnerabilities listed in the KEV Catalog. This proactive approach is crucial in mitigating potential threats and enhancing overall cybersecurity resilience.
Why This Matters Now
The inclusion of these vulnerabilities in CISA's KEV Catalog underscores the ongoing threat posed by actively exploited security flaws. Organizations must prioritize remediation efforts to safeguard their systems against potential attacks.
Attack Path Analysis
An attacker exploited a Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 appliances (CVE-2026-15409) to gain unauthorized access. They then leveraged a code injection flaw (CVE-2026-15410) to execute arbitrary commands, escalating their privileges. Using these elevated privileges, the attacker moved laterally within the network, targeting Microsoft Active Directory Federation Services (AD FS) to exploit an access control vulnerability (CVE-2026-56155). Establishing command and control, the attacker maintained persistent access and exfiltrated sensitive data from Microsoft SharePoint Server by exploiting a missing authentication vulnerability (CVE-2026-56164). The attack culminated in significant data exfiltration and potential disruption of services.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited a Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 appliances (CVE-2026-15409) to gain unauthorized access to the network.
Related CVEs
CVE-2026-56155
CVSS 7.8Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
Affected Products:
Microsoft Windows Server 2012 – 6.2.9200.0 to 6.2.9200.26226
Microsoft Windows Server 2012 R2 – 6.3.9600.0 to 6.3.9600.23291
Microsoft Windows Server 2016 – 10.0.14393.0 to 10.0.14393.9339
Microsoft Windows Server 2019 – 10.0.17763.0 to 10.0.17763.9020
Microsoft Windows Server 2022 – 10.0.20348.0 to 10.0.20348.5386
Microsoft Windows Server 2025 – 10.0.26100.0 to 10.0.26100.33158
Exploit Status:
exploited in the wildCVE-2026-56164
CVSS 9.8Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Affected Products:
Microsoft SharePoint Server – All versions prior to July 2026 security update
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Valid Accounts
Application Layer Protocol
OS Credential Dumping
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity
Control ID: Pillar 1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Federal agencies face critical vulnerability exploitation risks in SonicWall and Microsoft infrastructure, requiring immediate remediation under BOD 26-04 compliance mandates.
Financial Services
Banking institutions using SonicWall SMA appliances and Microsoft SharePoint face server-side request forgery and authentication bypass threats affecting customer data protection.
Health Care / Life Sciences
Healthcare organizations risk patient data exposure through Active Directory Federation Services and SharePoint vulnerabilities, violating HIPAA compliance requirements for secure authentication.
Information Technology/IT
IT service providers managing client infrastructures face amplified attack surface through SonicWall code injection and Microsoft authentication vulnerabilities across multiple environments.
Sources
- CISA Adds Four Known Exploited Vulnerabilities to Cataloghttps://www.cisa.gov/news-events/alerts/2026/07/14/cisa-adds-four-known-exploited-vulnerabilities-catalogVerified
- Microsoft Security Update Guide - CVE-2026-56155https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56155Verified
- Microsoft Security Update Guide - CVE-2026-56164https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56164Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have significantly limited the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained, reducing the likelihood of unauthorized entry into the network.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited, reducing the scope of potential damage.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network could have been restricted, limiting access to critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command and control channels could have been limited, reducing persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data could have been restricted, reducing data loss.
The overall impact of the attack could have been limited, reducing data loss and service disruption.
Impact at a Glance
Affected Business Functions
- Identity Management
- Collaboration Services
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of sensitive corporate documents and user credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the attacker's ability to exploit vulnerabilities across different systems.
- • Deploy Inline Intrusion Prevention Systems (IPS) to detect and block known exploit patterns, such as those targeting CVE-2026-15409 and CVE-2026-15410.
- • Enhance East-West Traffic Security to monitor and control internal traffic, preventing unauthorized access and data exfiltration.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights into network activities and detect anomalous behaviors indicative of command and control communications.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic, mitigating the risk of data exfiltration through unauthorized channels.



