← All briefings

Microsoft SharePoint Server · Microsoft Active Directory Federation Services · SonicWall SMA1000 Appliances

Daily Threat Intelligence Briefing

Date: 2026-07-15 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership


Executive Summary

July 2026 Patch Tuesday delivered a record-breaking 622 Microsoft CVEs, including two actively exploited zero-days: CVE-2026-56164 (SharePoint EoP, KEV) and CVE-2026-56155 (AD FS EoP, KEV). A critical SharePoint authentication bypass (CVE-2026-55040, CVSS 9.1) discovered by Rapid7 is part of an unauthenticated RCE chain — the second component remains embargoed until August. SonicWall SMA1000 appliances are under active zero-day attack via two KEV-listed flaws. Adobe ColdFusion received a cluster of critical RCE patches. CISA separately issued a SharePoint hardening alert citing active exploitation of three vulnerabilities.


Critical Vulnerabilities

CVE-2026-56164 — Microsoft SharePoint Server (Zero-Day EoP, KEV)

  • Severity: CVSS 5.3 (Microsoft rates Important; real-world impact is significantly higher)
  • EPSS: Not yet scored
  • Technical detail: Missing authentication for a critical function allows an unauthenticated network attacker to elevate privileges on SharePoint Server (Subscription Edition, 2019, 2016). Microsoft notes low attack complexity and repeatable success without prior system knowledge. CISA’s separate alert confirms active exploitation chained with CVE-2026-32201 and CVE-2026-45659 for RCE and IIS machine key theft. SharePoint 2016 and 2019 also reached extended end-of-life on July 14, 2026 — no ESU is available; Subscription Edition is the only fully supported on-premises option.
  • Exploitation status: Actively exploited in the wild; CISA KEV deadline 2026-07-17.
  • Remediation: Apply July 2026 Patch Tuesday updates immediately. Review CISA’s SharePoint hardening advisory. Consider migrating off end-of-life SharePoint 2016/2019.

CVE-2026-55040 — Microsoft SharePoint Server (Auth Bypass, Critical RCE Chain)

  • Severity: CVSS 9.1 (Critical)
  • EPSS: Not yet scored
  • Technical detail: A JWT token validation flaw in SharePoint’s authentication pipeline allows a remote unauthenticated attacker to impersonate any SharePoint user — including site administrators — given knowledge of the target’s AD SID or UPN. Discovered by Rapid7 via AI-assisted research and disclosed today. This is the first link in a two-vulnerability unauthenticated RCE chain; the second (RCE) component is embargoed and expected in August 2026 Patch Tuesday. Patching this bypass now breaks the full chain.
  • Exploitation status: No in-the-wild exploitation confirmed; PoC details embargoed for 30 days. Exploitation More Likely per Microsoft.
  • Remediation: Apply July 2026 Patch Tuesday updates for SharePoint Server (all supported versions). Full technical details from Rapid7 will be published within 30 days.

CVE-2026-56155 — Microsoft Active Directory Federation Services (Zero-Day EoP, KEV)

  • Severity: CVSS 7.8
  • EPSS: Not yet scored
  • Technical detail: Insufficient granularity of access control in AD FS allows an authorized attacker with an existing foothold to elevate privileges locally. Eight additional AD FS vulnerabilities were patched in the same cycle. Exploitation likely requires an initial toehold on the target system to leverage the privilege escalation opportunity.
  • Exploitation status: Actively exploited in the wild; CISA KEV deadline 2026-07-28.
  • Remediation: Apply July 2026 Patch Tuesday updates. Audit AD FS event logs for anomalous token issuance or privilege changes.

CVE-2026-15409 / CVE-2026-15410 — SonicWall SMA1000 Appliances (Zero-Day, KEV)

  • Severity: CVSS 10.0 (CVE-2026-15409 SSRF) / not yet scored (CVE-2026-15410 Code Injection)
  • EPSS: 0 (newly published)
  • Technical detail: CVE-2026-15409 is an unauthenticated SSRF in the SMA1000 Workplace interface (versions 12.4.3-03245–03434 and 12.5.0-02283–02800) that can cause the appliance to make requests to unintended locations. CVE-2026-15410 is a code injection flaw exploitable by a remote authenticated administrator to execute arbitrary OS commands under specific conditions. SonicWall confirms both are being exploited as zero-days. SMA1000 appliances are commonly deployed as enterprise SSL-VPN gateways, making them high-value targets.
  • Exploitation status: Actively exploited in the wild; CISA KEV deadline 2026-07-17.
  • Remediation: Apply SonicWall patches immediately. If patching is not immediately possible, restrict management interface access and monitor for anomalous outbound connections.

CVE-2026-48318 / CVE-2026-48284 / CVE-2026-48322 — Adobe ColdFusion (Critical RCE Cluster)

  • Severity: CVSS 9.9 (CVE-2026-48318 path traversal), 9.6 (CVE-2026-48284 input validation), 9.6 (CVE-2026-48322 code injection)
  • EPSS: 0 (newly published)
  • Technical detail: Adobe patched at least eight critical/high vulnerabilities in ColdFusion 2023 (≤Update 21) and ColdFusion 2025 (≤Update 10), including path traversal enabling arbitrary file reads, improper input validation and code injection enabling unauthenticated RCE, missing authentication for critical functions, SQL injection, and incorrect authorization. ColdFusion has a history of rapid weaponization; prior critical ColdFusion CVEs (CVE-2026-48282/48316) are already listed as actively exploited in yesterday’s ONGOING items. BSI advisory WID-SEC-2026-2155 (updated) covers this cluster.
  • Exploitation status: No new confirmed exploitation for this batch; prior ColdFusion CVEs actively exploited.
  • Remediation: Update ColdFusion 2023 to Update 22 and ColdFusion 2025 to Update 11 immediately. Restrict ColdFusion admin interfaces to trusted IPs.

ONGOING:

  • CVE-2026-48282 / CVE-2026-48316 (Adobe ColdFusion): actively exploited; patch or isolate — superseded by new patch batch above.
  • CVE-2026-44747 (SAP NetWeaver ABAP, CVSS 9.9): patch immediately; no confirmed exploitation yet.
  • CVE-2026-6875 (ServiceNow AI Platform, CVSS 9.5): patch immediately; restrict external access.
  • CVE-2008-4128 (Cisco IOS): actively exploited; CISA KEV deadline 2026-07-16 — disable HTTP management interfaces now.
  • CVE-2026-55255 (Langflow): actively exploited; patch immediately.
  • CVE-2026-8037 (Progress Kemp LoadMaster): actively exploited; patch or isolate.
  • CVE-2026-46817 (Oracle E-Business Suite): actively exploited; patch immediately.

European Advisories

BSI — July 14, 2026 (Microsoft Patch Tuesday): BSI published Version 1.0 security warning specifically highlighting SharePoint zero-day and critical vulnerabilities. CVE-2026-56164 and CVE-2026-55040 are covered in Critical Vulnerabilities above.

BSI [WID-SEC-2026-2155](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2155) (Adobe ColdFusion — UPDATE): Updated critical advisory covering the new ColdFusion RCE cluster; covered in Critical Vulnerabilities above.

BSI [WID-SEC-2026-2312](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2312) (Notepad++ — NEW): New high-severity advisory for multiple Notepad++ vulnerabilities enabling arbitrary code execution, information disclosure, file manipulation, and security bypass. Apply the latest Notepad++ release; relevant for developer workstations and SOC analyst endpoints.

BSI — Linux Kernel (multiple UPDATE advisories): BSI updated 15+ Linux Kernel advisories (WID-SEC-2025-xxxx series) covering DoS and privilege escalation. Apply current distribution kernel updates; no new CVEs introduced today.

BSI — Red Hat OpenShift / RHEL / Satellite (UPDATE): Updated advisories for gRPC-Go security bypass (WID-SEC-2026-1136) and RHEL/Satellite container image vulnerabilities (WID-SEC-2026-1160). Apply Red Hat errata.

SAP July 2026 Patch Day: SAP patched CVE-2026-44747 (NetWeaver ABAP, CVSS 9.9) and CVE-2026-44761 (Commerce Cloud default OAuth2 credentials, CVSS 9.1) — both covered in yesterday’s report as ONGOING. Heise Security confirms 16 vulnerabilities addressed across SAP products including NetWeaver and Commerce Cloud.


Active Threats and Campaigns

NEW — OAuth Client ID Spoofing in Microsoft Entra ID: At least two distinct threat actors are exploiting a novel technique that allows enumeration of user accounts and validation of stolen credentials in Entra ID environments without generating successful sign-in events. This effectively blinds defenders relying on sign-in telemetry. Enable anomaly detection for failed authentication patterns and audit OAuth application registrations. (The Hacker News)

NEW — LabubaRAT (Rust-based RAT masquerading as NVIDIA software): A previously undocumented Rust-based RAT disguises itself as NVIDIA software to blend into target environments. Once deployed, it profiles the host and establishes a persistent foothold for hands-on operator activity. Add NVIDIA software impersonation to EDR behavioral rules; verify digital signatures on all NVIDIA-branded executables. (The Hacker News)

NEW — Fake GitHub Repositories Distributing Infostealer Malware: Nearly 300 GitHub repositories impersonate legitimate software and security tools to distribute infostealer malware. Developers and security teams downloading tools from GitHub should verify repository authenticity, star counts, and commit history before execution. (Bleeping Computer)

NEW — Phishing Campaign Targeting LastPass and Bitwarden Users: An active phishing campaign uses fake security alerts to redirect password manager users to credential-harvesting sites. Warn end users; enforce FIDO2/passkey authentication where possible. (Bleeping Computer)

ONGOING — Russian FSB Center 16 router exploitation campaign: Active targeting of legacy network devices; CISA/NCSC advisory remains current. Harden per yesterday’s guidance. ONGOING — Forg365 PhaaS (Microsoft 365 AitM): Block device code authentication flows; monitor inbox rules. ONGOING — ShinyHunters Salesforce OAuth abuse: Audit OAuth connections and third-party app grants.


Security News and Context

Microsoft Patch Tuesday July 2026 — Record 622 CVEs: The release includes 416 Windows vulnerabilities alone, two actively exploited zero-days, and one publicly disclosed flaw (CVE-2026-50661, BitLocker bypass). Rapid7 and SANS ISC provide detailed breakdowns. (Rapid7, The Hacker News)

Progress ShareFile Zero-Day Confirmed: Progress Software confirmed a high-severity zero-day behind last week’s emergency ShareFile Storage Zone Controller shutdown; patches are now available. (Bleeping Computer)

U.S. Sanctions VPN Provider and Malware Cryptor for Ransomware Support: OFAC sanctioned First VPN Service (1VPNS) and a malware cryptor seller for enabling ransomware operations against U.S. organizations. (Bleeping Computer)

New MFA-Bypassing Phishing Kits (Jalisco, OmegaLord): Two new phishing kits targeting Microsoft 365 accounts use AitM techniques to defeat MFA; enforce phishing-resistant authentication. (Bleeping Computer)


  1. Apply July 2026 Patch Tuesday updates immediately, prioritizing SharePoint (CVE-2026-56164, CVE-2026-55040), AD FS (CVE-2026-56155), and high-risk Windows components (DHCP Server CVE-2026-50518 CVSS 9.8, Exchange Spoofing CVE-2026-55008 CVSS 9.6, Dynamics 365 BC CVE-2026-55944 CVSS 9.8).
  2. Patch SonicWall SMA1000 appliances (CVE-2026-15409/CVE-2026-15410) before the CISA KEV deadline of 2026-07-17; restrict management access immediately if patching is delayed.
  3. Apply Adobe ColdFusion Update 22 (2023) / Update 11 (2025) to address the new critical RCE cluster; restrict admin interface access to trusted IPs.
  4. Implement CISA SharePoint hardening guidance: review IIS machine key configurations, audit for post-exploitation indicators (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164).
  5. Block device code authentication and enforce phishing-resistant MFA (FIDO2/passkeys) to counter OAuth spoofing, Forg365, Jalisco, and OmegaLord campaigns.
  6. Patch Progress ShareFile Storage Zone Controllers using newly released updates; treat any controllers that were shut down as potentially compromised pending forensic review.
  7. Audit GitHub repository sources used in development pipelines; verify authenticity before executing downloaded tools or packages.
  8. Warn users about LastPass/Bitwarden phishing campaign; verify all password manager security alerts originate from official domains.
  9. Apply Notepad++ latest release on developer and analyst workstations (BSI WID-SEC-2026-2312).
  10. Continue remediation of previously reported items: CVE-2026-44747 (SAP NetWeaver ABAP), CVE-2026-6875 (ServiceNow), CVE-2008-4128 (Cisco IOS — deadline 2026-07-16), CVE-2026-55255 (Langflow), CVE-2026-8037 (Kemp LoadMaster), CVE-2026-46817 (Oracle EBS), CVE-2026-56271 (Flowise).