CISA's list that day
14 July 2026
On CISA added 4 vulnerabilities to its list of exploited vulnerabilities, in SonicWall SMA1000 Appliances, Microsoft Active Directory Federation Services and Microsoft SharePoint Server. The US federal deadlines run from to .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2026-15409Server-Side Request Forgery | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year; Metasploit module | 0.07 | ||
| CVE-2026-15410Code Injection | SonicWall SMA1000 Appliances | Patch nowForensic triage required by CISA; ransomware use, listed within a year | 0.12 | ||
| CVE-2026-56164Missing Authentication for Critical Function | Microsoft SharePoint Server | Patch nowForensic triage required by CISA | 0.01 | ||
| CVE-2026-56155Insufficient Granularity of Access Control | Microsoft Active Directory Federation Services | Patch soon | 0.00 |