CISA's list that day

14 July 2026

On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in SonicWall SMA1000 Appliances, Microsoft Active Directory Federation Services and Microsoft SharePoint Server. The US federal deadlines run from to .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-15409Server-Side Request ForgerySonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module0.07
CVE-2026-15410Code InjectionSonicWall SMA1000 AppliancesPatch nowForensic triage required by CISA; ransomware use, listed within a year0.12
CVE-2026-56164Missing Authentication for Critical FunctionMicrosoft SharePoint ServerPatch nowForensic triage required by CISA0.01
CVE-2026-56155Insufficient Granularity of Access ControlMicrosoft Active Directory Federation ServicesPatch soon0.00