SonicWall SMA1000 · Mozilla Firefox · Critical Account Takeover Vulnerability
Daily Threat Intelligence Briefing
Date: 2026-07-16 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
Two critical SonicWall SMA1000 zero-days (CVE-2026-15409 / CVE-2026-15410) — already KEV-listed — have been detailed by Rapid7 with full technical analysis, confirmed IOCs, and a published Python PoC for the SSRF component. Active exploitation includes credential theft, TOTP seed harvesting, and AD lateral movement. Firefox and Chrome received emergency patches for critical flaws with public exploit code. A supply-chain attack compromised AsyncAPI npm packages with credential-stealing malware. A Zoom critical account-takeover vulnerability was disclosed today.
Critical Vulnerabilities
CVE-2026-15409 / CVE-2026-15410 — SonicWall SMA1000 (Zero-Day Chain, KEV)
- Severity: CVSS 10.0 (
CVE-2026-15409); high-severity (CVE-2026-15410) - EPSS: 0 (newly published; exploitation confirmed in wild)
- Technical detail:
CVE-2026-15409is an unauthenticated SSRF in the/wsproxyendpoint of SonicWall WorkPlace (port 443) that tunnels arbitrary TCP traffic to localhost services, including a hardcoded-cookie Erlang process on port 1050 enabling unauthenticated RCE.CVE-2026-15410is a path traversal in theremove_hotfixworkflow ofctrl-service(port 8188) that executes attacker-staged shell scripts as root, triggering a reboot. Chained, these yield full root compromise. Rapid7 MDR observed pre-disclosure exploitation targeting credential stores, active session databases, and TOTP MFA seeds, followed by VPN-less NTLM lateral movement into domain controllers using attacker-controlled workstation names (e.g.,kali). A Python PoC forCVE-2026-15409is publicly available; a Metasploit module is in development. Affected models: SMA1000 6210, 7210, 8200v on firmware 12.4.3-03245 through 12.5.0-02800. - Exploitation status: Actively exploited in the wild; CISA KEV deadline 2026-07-17.
- Remediation: Upgrade immediately to 12.4.3-03453 or 12.5.0-02835 (platform-hotfix). No workaround exists. If compromise is suspected: re-image appliances, rotate all credentials and TOTP seeds, audit for NTLM logons (Event ID 4624, type 3) sourced from the appliance IP. Block ASN 206092 (FNS Holdings Limited) if no business need. IOC IP ranges:
45.131.194.0/24,45.146.54.0/24,63.135.161.0/24,173.239.211.0/24,193.37.32[.]179/214,216.73.163[.]151/158.
CVE-2026-15718 / CVE-2026-15719 — Mozilla Firefox (Critical, Public Exploit Code)
- Severity: Critical (CVSS not yet published)
- EPSS: Not yet scored
- Technical detail:
CVE-2026-15718is an invalid pointer dereference in the JavaScript/WebAssembly component;CVE-2026-15719is a site isolation bypass in the DOM Navigation component. Mozilla confirmed public exploit code exists for both, though in-the-wild exploitation has not been confirmed. Both flaws affect the Firefox desktop client; enterprise deployments using Firefox ESR should verify patch applicability. Chrome received concurrent critical updates per the same Hacker News report. - Exploitation status: Public exploit code available; no confirmed in-the-wild exploitation.
- Remediation: Update Firefox and Chrome to latest releases immediately. Prioritize endpoints where browser isolation is not enforced.
Zoom — Critical Account Takeover Vulnerability (CVE pending)
- Severity: Critical (CVSS not yet published)
- EPSS: Not yet scored
- Technical detail: Zoom disclosed a critical vulnerability in its Windows desktop client and SDK that allows an unauthenticated remote attacker to hijack user accounts. Specific technical details are limited at time of publication; the attack vector is network-accessible and requires no user interaction based on Zoom’s advisory language. Zoom is widely deployed in European enterprise environments.
- Exploitation status: No confirmed exploitation; patch urgency is high given unauthenticated attack vector.
- Remediation: Apply Zoom client and SDK updates for Windows immediately. Monitor Zoom’s security bulletin for CVE assignment and additional technical detail.
AsyncAPI npm Supply-Chain Attack — Credential-Stealing RAT
- Severity: High (no CVE assigned; supply-chain compromise)
- Technical detail: Five malicious versions of four
@asyncapinamespace packages (generator-helpers@1.1.1,generator-components@0.7.1,generator@3.3.1,specs@6.11.2and6.11.2-alpha.1) were published to npm delivering a multi-stage botnet loader and remote access trojan with credential-stealing capabilities. The packages are widely used in API tooling pipelines. Confirmed by OX Security, SafeDep, Socket, and StepSecurity. - Exploitation status: Active supply-chain compromise; malicious versions confirmed in the wild.
- Remediation: Audit
package.jsonandpackage-lock.jsonfor affected versions immediately. Remove and replace with clean versions. Rotate credentials on any systems where affected packages were installed. Review CI/CD pipeline logs for anomalous outbound connections.
Windows User Profile Service — New Zero-Day PoC (LegacyHive)
- Severity: High (EoP; CVSS not yet published)
- EPSS: Not yet scored
- Technical detail: Researcher “Chaotic Eclipse” released a PoC exploit (
LegacyHive) for an arbitrary hive load elevation-of-privilege vulnerability in the Windows User Profile Service (ProfSvc) hours after July Patch Tuesday. The PoC enables local privilege escalation. It is unclear whether this is a bypass of a patch issued this cycle or a separate unpatched issue — treat as potentially unpatched until Microsoft clarifies. - Exploitation status: Public PoC released; no confirmed in-the-wild exploitation.
- Remediation: Apply July 2026 Patch Tuesday updates. Monitor Microsoft’s response for an out-of-band patch if this is confirmed as a new unpatched flaw. Restrict local user privileges as a compensating control.
ONGOING:
CVE-2026-56164(SharePoint EoP, KEV): actively exploited; CISA deadline 2026-07-17 — patch now.CVE-2026-55040(SharePoint Auth Bypass, CVSS 9.1): patch applied; RCE second component embargoed until August.CVE-2026-56155(AD FS EoP, KEV): actively exploited; CISA deadline 2026-07-28 — patch now.CVE-2026-48318/CVE-2026-48284/CVE-2026-48322(Adobe ColdFusion RCE cluster): patch to ColdFusion 2023 Update 22 / 2025 Update 11.CVE-2026-44747(SAP NetWeaver ABAP, CVSS 9.9): patch immediately.CVE-2026-46817(Oracle E-Business Suite): actively exploited; patch immediately.CVE-2026-55255(Langflow): actively exploited; patch immediately.CVE-2026-8037(Progress Kemp LoadMaster): actively exploited; patch or isolate.
European Advisories
BSI [WID-SEC-2026-2346](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2346) — SonicWall SMA (NEW, kritisch): BSI published a critical advisory on 2026-07-15 confirming that a remote unauthenticated attacker can bypass security controls and execute arbitrary OS commands on SonicWall SMA appliances. The BSI IT-Sicherheitshinweis (Version 1.0) separately confirms zero-day exploitation of CVE-2026-15409 and CVE-2026-1541 on SMA1000 models 6210, 7210, and 8200v, with SonicWall reporting “numerous cases” of active exploitation. Covered in detail in Critical Vulnerabilities above.
BSI [WID-SEC-2026-2316](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2316) / [WID-SEC-2026-2317](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2317) — Microsoft Windows and Office (NEW, kritisch): BSI published new critical advisories for July 2026 Patch Tuesday covering Windows privilege escalation, RCE, DoS, information disclosure, and security bypass, plus Office RCE and privilege escalation. Critical items (CVE-2026-56164, CVE-2026-56155) covered in yesterday’s report. Apply July 2026 Patch Tuesday updates.
BSI [WID-SEC-2025-2475](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2475) — Apple macOS (UPDATE, kritisch): Updated advisory covering information disclosure, DoS, security bypass, file manipulation, and privilege escalation. Apply current macOS updates.
BSI — GNU libc / Linux Kernel / GStreamer / Golang (multiple UPDATEs, hoch): BSI updated numerous advisories for Linux Kernel (DoS, privilege escalation, memory corruption), GNU libc (file manipulation, DoS), GStreamer (DoS, memory corruption, potential RCE), and Golang Go (DoS, spoofing). Apply current distribution updates for all affected components.
BSI — Windows Hello for Business Analysis: BSI published an analysis of Windows Hello for Business identifying weaknesses in biometric authentication, particularly in deployments without Enhanced Sign-in Security (ESS). Review BSI findings and enforce ESS where hardware supports it.
Active Threats and Campaigns
NEW — TuxBot v3 Evolution (LLM-Assisted IoT Botnet): Unit 42 and The Hacker News report a new IoT botnet framework, TuxBot v3 Evolution, showing evidence of LLM-assisted development (including an AI safety disclaimer left in the code). The framework uses cross-compiled binaries and a structured C2 architecture. While current capability appears limited by development bugs, the use of LLMs to accelerate botnet development is a notable trend. Ensure IoT device firmware is current and management interfaces are not internet-exposed.
NEW — OkoBot Malware (Hardware Wallet Seed Phrase Phishing): A Windows malware framework active since April 2025 injects fake seed-phrase prompts into legitimate Ledger and Trezor desktop applications, waiting for device connection before triggering. Relevant for organizations with cryptocurrency holdings or employees using hardware wallets. Enforce application allowlisting and monitor for process injection into wallet software.
NEW — Google Gemini CLI Abused as Hacking Agent: A Russian-speaking threat actor (“bandcampro”) used Google’s open-source Gemini CLI as a hacking agent and botnet operator. This represents an emerging abuse pattern of legitimate AI tooling for offensive operations. Review policies on AI CLI tool installation in enterprise environments.
NEW — Fake GitHub Repositories Distributing Infostealers: ~290 GitHub repositories impersonating security vendors and developer tool providers are distributing infostealer malware. Verify repository authenticity before executing any downloaded tooling. (Heise Security)
ONGOING — OAuth Client ID Spoofing (Microsoft Entra ID): Credential enumeration without sign-in telemetry; audit OAuth registrations and enable anomaly detection. ONGOING — Forg365 PhaaS / ShinyHunters Salesforce OAuth abuse: Block device code auth flows; audit third-party OAuth grants.
Security News and Context
SonicWall SMA1000 Zero-Days — Full Technical Disclosure: Rapid7 published a detailed technical writeup including exploit code, IOCs, and observed post-exploitation behavior (credential theft, TOTP harvesting, AD lateral movement) — treat all unpatched SMA1000 appliances as compromised.
Dutch Police Bust €100M Investment Fraud Ring: Dutch authorities arrested multiple suspects in an international investment fraud scheme with tens of thousands of victims across Europe. (Bleeping Computer)
US Charges Russian Bulletproof Hosting Operators: Three Russian nationals charged for providing bulletproof hosting to ransomware gangs causing over $62M in damages. (Bleeping Computer)
CISA / NSA Joint CVD Guidance Published: New joint guidance on establishing coordinated vulnerability disclosure programs released for software manufacturers and service providers.
Recommended Actions
- Patch SonicWall SMA1000 immediately (12.4.3-03453 or 12.5.0-02835); CISA KEV deadline 2026-07-17. If compromise is suspected, re-image and rotate all credentials and TOTP seeds. Block ASN 206092 (FNS Holdings).
- Update Firefox and Chrome to latest releases; public exploit code exists for
CVE-2026-15718andCVE-2026-15719. - Apply Zoom Windows client and SDK updates immediately to address the critical unauthenticated account-takeover vulnerability.
- Audit npm dependencies for
@asyncapipackages (generator-helpers@1.1.1,generator-components@0.7.1,generator@3.3.1,specs@6.11.2); remove affected versions and rotate credentials on impacted systems. - Investigate Windows User Profile Service PoC (LegacyHive): apply July Patch Tuesday updates and monitor for Microsoft out-of-band advisory; restrict local user privileges as interim control.
- Enforce BSI guidance on Windows Hello for Business: deploy Enhanced Sign-in Security (ESS) on all hardware-capable endpoints.
- Verify GitHub repository authenticity before executing any downloaded security or developer tooling; enforce code-signing policies in CI/CD pipelines.
- Review AI CLI tool policies: assess whether tools like Gemini CLI require enterprise governance controls given confirmed offensive abuse.
- Apply July 2026 Patch Tuesday updates for Windows and Office (BSI WID-SEC-2026-2316/2317); apply macOS, Linux Kernel, GNU libc, GStreamer, and Golang updates per BSI advisories.
- Continue remediation of previously reported items:
CVE-2026-56164/CVE-2026-56155(SharePoint/AD FS KEV),CVE-2026-48318cluster (ColdFusion),CVE-2026-44747(SAP NetWeaver),CVE-2026-46817(Oracle EBS),CVE-2026-55255(Langflow),CVE-2026-8037(Kemp LoadMaster).