CISA added nine new vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog during the past seven days, spanning enterprise collaboration platforms (Microsoft SharePoint), identity services (AD FS), sandboxing solutions (Fortinet FortiSandbox), access gateways (SonicWall SMA1000), financial ERP suites (Oracle E-Business Suite), and industrial automation protocols (KNX). The most significant operational trend is the concentrated targeting of remote access gateways, internal sandboxing infrastructure, and enterprise collaboration platforms for unauthenticated command injection, SSRF, and privilege escalation. Security, vulnerability management, and infrastructure teams should prioritize perimeter appliances, identity providers, and SharePoint environments for immediate validation and remediation activity.
Reading time 10 minutes
Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes
| CVE ID | Vendor / Product | CVSS | Date Added | CISA Due Date | Exploitation Type | EPSS | Reachability |
| CVE-2026-58644 | Microsoft SharePoint Server | 9.8 (Critical) | 16 July 2026 | 06 Aug 2026 | Untrusted Deserialization → Network RCE | 1.00% (0.01000) | Network |
| CVE-2026-25089 | Fortinet FortiSandbox | 9.8 (Critical) | 16 July 2026 | 06 Aug 2026 | OS Command Injection → Unauthenticated RCE | 2.03% (0.02030) | Network |
| CVE-2026-39808 | Fortinet FortiSandbox | 9.8 (Critical) | 16 July 2026 | 06 Aug 2026 | OS Command Injection via HTTP Requests | 48.67% (0.48670) | Network |
| CVE-2026-46817 | Oracle E-Business Suite | 9.8 (Critical) | 15 July 2026 | 05 Aug 2026 | Improper Privilege Management / Takeover | 1.05% (0.01050) | Network |
| CVE-2023-4346 | KNX Association Protocol | 7.5 (High) | 15 July 2026 | 05 Aug 2026 | Restrictive Lockout / Device Account Purge | 0.86% (0.00860) | Network |
| CVE-2026-56155 | Microsoft AD FS | 7.8 (High) | 14 July 2026 | 04 Aug 2026 | Insufficient Granularity Access Control → Local EoP | 0.38% (0.00380) | Network |
| CVE-2026-56164 | Microsoft SharePoint Server | 9.8 (Critical) | 14 July 2026 | 04 Aug 2026 | Missing Authentication → Network EoP | 7.05% (0.07047) | Network |
| CVE-2026-15409 | SonicWall SMA1000 | 10.0 (Critical) | 14 July 2026 | 04 Aug 2026 | Server-Side Request Forgery (SSRF) | 1.40% (0.01404) | Network |
| CVE-2026-15410 | SonicWall SMA1000 | 7.2 (High) | 14 July 2026 | 04 Aug 2026 | Authenticated Admin Code Injection → OS Command Exec | 1.65% (0.01647) | Network |
CVE-2026-58644 - Microsoft SharePoint Server
What it is → An unauthenticated remote code execution flaw caused by improper deserialization of untrusted data in Microsoft SharePoint Server.
Affected versions → Supported versions of Microsoft SharePoint Server (refer to MSRC July 2026 guidance).
Exploitation status Active zero-day exploitation confirmed via CISA KEV inclusion.
Patch available Yes. Security updates available via Microsoft MSRC.
Operational risk Allows network-adjacent or remote unauthenticated attackers to execute arbitrary code on SharePoint hosts, serving as an immediate entry point into corporate intranet domains.
CVE-2026-25089 - Fortinet FortiSandbox
What it is→ An OS command injection flaw (CWE-78) in the Web UI resulting from improper neutralization of special elements in HTTP requests.
Affected versions → FortiSandbox 5.0.0 through 5.0.5 → FortiSandbox 4.4.0 through 4.4.8 → FortiSandbox 4.2 (all versions) → FortiSandbox Cloud & PaaS 5.0.4 through 5.0.5
Exploitation status Active exploitation confirmed via CISA KEV inclusion.
Patch available Yes. Addressed in Fortinet Advisory FG-IR-26-141.
Operational risk Compromising security sandboxing appliances grants threat actors root-level access, blinding internal malware inspection mechanisms and enabling network lateral movement.
CVE-2026-39808 - Fortinet FortiSandbox
What it is→ An unauthenticated OS command injection vulnerability in FortiSandbox handling specific HTTP request routes.
Affected versions → FortiSandbox 4.4.0 through 4.4.8
Exploitation status Active exploitation confirmed; elevated EPSS score indicates widespread scanning and exploitation attempts.
Patch available Yes. Fixed in FortiSandbox version 4.4.9 (FG-IR-26-100).
Operational risk High reliability unauthenticated code execution path targeting threat analysis infrastructure.
CVE-2026-46817 - Oracle E-Business Suite
What it is→ An improper privilege management vulnerability (CWE-269/CWE-287) in the Oracle Payments component (File Transmission).
Affected versions → Oracle E-Business Suite 12.2.3 through 12.2.15
Exploitation status Active exploitation confirmed through KEV inclusion.
Patch available Yes. Addressed in Oracle Critical Patch Update advisory.
Operational risk Allows unauthenticated HTTP network attackers to fully compromise Oracle Payments, presenting immediate risk to enterprise financial transaction processing.
CVE-2023-4346 - KNX Association Protocol
What it is → An overly restrictive account lockout vulnerability in KNX Connection Authorization Option 1.
Affected versions → KNX Connection Authorization Option 1 compliant implementations.
Exploitation status Active exploitation confirmed via KEV inclusion.
Patch available Yes. Vendor mitigation and configuration guidance published.
Operational risk Network-reachable attackers can purge all devices lacking secondary security options and set unauthorized BCU keys, causing permanent loss of access and physical facility management disruption.
CVE-2026-56155 - Microsoft Active Directory Federation Services
What it is → An elevation of privilege vulnerability stemming from insufficient granularity of access control within AD FS.
Affected versions → Supported versions of Windows Server running AD FS.
Exploitation status Active exploitation confirmed via MSRC and CISA KEV.
Patch available Yes. Patched in Microsoft July 2026 Patch Tuesday release.
Operational risk Allows local authenticated users to escalate privileges to full identity infrastructure control on AD FS servers.
CVE-2026-56164 - Microsoft SharePoint Server
What it is →A missing authentication flaw for critical functions in Microsoft SharePoint Server enabling remote privilege escalation.
Affected versions → Supported Microsoft SharePoint Server editions. Exploitation status Active zero-day exploitation confirmed.
Patch available Yes. Available via Microsoft MSRC.
Operational risk Unauthenticated network attackers can bypass security controls to escalate rights across farm resources without credentials.
CVE-2026-15409 - SonicWall SMA1000
What it is →A Server-Side Request Forgery (SSRF) vulnerability in the Work Place management interface.
Affected versions → SonicWall SMA1000 Series Appliances (Firmware prior to emergency hotfix).
Exploitation status Active zero-day exploitation confirmed by threat intelligence teams.
Patch available Yes. SonicWall released emergency patches and hotfixes.
Operational risk Critical perimeter bypass allowing unauthenticated attackers to force the appliance to issue unauthorized requests to internal network services.
CVE-2026-15410 - SonicWall SMA1000
What it is →Improper control of generation of code (Code Injection) in the Appliance Management Console (AMC).
Affected versions → SonicWall SMA1000 Series Appliances.
Exploitation status Active zero-day exploitation confirmed in conjunction with perimeter targeting.
Patch available Yes. Hotfixes released by SonicWall.
Operational risk Allows authenticated administrative users (or attackers leveraging chained credentials/SSRF) to execute arbitrary OS commands at the system level.
This week's KEV additions reflect aggressive threat actor focus on edge remote-access devices (SonicWall SMA1000), identity/collaboration hubs (Microsoft AD FS & SharePoint), and security detection assets (Fortinet FortiSandbox).
Attackers are combining perimeter SSRF and unauthenticated OS command injection to gain immediate footholds on internal subnets without requiring endpoint interaction. The simultaneous targeting of security sandboxes highlights an intentional tactic to neutralize detection platforms prior to lateral movement or ransomware deployment.
| Priority | CVE | Recommended Action | Timeline |
| Critical | CVE-2026-15409 | Apply SonicWall hotfix immediately; restrict Work Place interface exposure. | Immediate |
| Critical | CVE-2026-58644 | Patch SharePoint Server; audit server logs for untrusted deserialization objects. | Immediate |
| Critical | CVE-2026-56164 | Apply SharePoint privilege escalation patches. | Immediate |
| Critical | CVE-2026-25089 | Upgrade FortiSandbox to fixed builds (FG-IR-26-141); isolate Web UI. | Immediate |
| Critical | CVE-2026-39808 | Upgrade FortiSandbox to 4.4.9 or later. | Immediate |
| Critical | CVE-2026-46817 | Patch Oracle E-Business Suite (Oracle Payments component). | Within 24 Hours |
| High | CVE-2026-15410 | Patch SonicWall SMA1000 AMC; restrict administrative console access. | Within 24 Hours |
| High | CVE-2026-56155 | Apply Microsoft security updates to all AD FS infrastructure hosts. | Within 72 Hours |
| Medium | CVE-2023-4346 | Enforce secondary security options on KNX networks; restrict local interface access. | Next Patch Window |
| CVE | Minimum Detection Guidance |
| CVE-2026-58644 | Inspect IIS logs for anomalous POST requests targeting SharePoint endpoints and monitor for unexpected child process creation (cmd.exe, powershell.exe) under w3wp.exe. |
| CVE-2026-25089 | Monitor FortiSandbox Web UI traffic for HTTP requests containing shell metacharacters (|, ;, $()); inspect egress traffic for new outbound connections. |
| CVE-2026-39808 | Monitor HTTP access logs on FortiSandbox management interfaces for malformed parameters and unauthenticated command strings. |
| CVE-2026-46817 | Review Oracle E-Business Suite web server logs for unauthorized access to File Transmission endpoints in Oracle Payments. |
| CVE-2023-4346 | Audit KNX network traffic for unusual BCU key assignment commands or repetitive lockout triggers across bus devices. |
| CVE-2026-56155 | Audit Windows Event Logs (Event ID 4624/4672) on AD FS servers for abnormal local privilege assignments and token manipulation. |
| CVE-2026-56164 | Monitor SharePoint API calls and web requests attempting unauthenticated administrative function calls. |
| CVE-2026-15409 | Monitor SMA1000 Work Place web logs for outbound HTTP/HTTPS requests directed toward internal IP ranges or loopback addresses. |
| CVE-2026-15410 | Audit SMA1000 AMC administrative activity logs for anomalous OS-level command strings executed during active web sessions. |
This week's KEV updates emphasize a critical shift in attacker methodology: targeting the platforms organizations rely on for security and remote connectivity. By compromising FortiSandbox appliances and SonicWall gateways, threat actors disable early warning telemetry and establish persistent network footholds simultaneously.
Furthermore, zero-day exploitation against core enterprise productivity tools—specifically Microsoft SharePoint—underlines that internal collaboration servers remain primary targets for initial access and privilege expansion.
Practitioners must prioritize KEV listings above standard CVSS metrics. CISA KEV inclusion confirms real-world adversary adoption, requiring immediate exposure validation, interface hardening, and rapid patch deployment across perimeter and identity systems.
🔗 Exposure-Based Vulnerability Prioritization: EPSS, KEV & Risk
Why read this: Integrate EPSS scoring with KEV intelligence for exposure-driven remediation decisions.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/vulnerability-management-operational-risk-exposure-prioritization
🔗 CVE Overload: Why Most Patch Programs Fail
Why read this: Identify systemic vulnerabilities in traditional patching workflows.
https://www.hackerstorm.com/articles/our-blog/vulnerabililty-intelligence/why-most-patch-programs-fail
🔗 CVSS vs EPSS: How to Prioritise Vulnerabilities by Real Exploitation Risk
Why read this: Replace static severity scoring with probability-based threat modeling.
https://www.hackerstorm.com/articles/our-blog/vulnerability-intelligence-analysis/cvss-vs-epss-vulnerability-prioritisation-exploitation-risk
This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available.
Timur Mehmet | Founder & Lead Editor
Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.
Contact:
This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:
Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections
Learn More: About Hackerstorm.com | FAQs
CISA Known Exploited Vulnerabilities (KEV) Catalog Primary source used to verify KEV additions, inclusion dates, exploitation status, and Federal Civilian Executive Branch (FCEB) remediation deadlines.
Microsoft Security Response Center (MSRC) Advisory — CVE-2026-58644 / CVE-2026-56155 / CVE-2026-56164 Used to validate affected SharePoint and AD FS versions, exploitation conditions, and security update releases.
Fortinet Security Advisories — FG-IR-26-141 / FG-IR-26-100 Used to confirm affected FortiSandbox builds, vulnerability mechanisms, and patch availability.
Oracle Critical Patch Update — CVE-2026-46817 Used to validate affected Oracle E-Business Suite versions and privilege management impact.
SonicWall Security Advisories — CVE-2026-15409 / CVE-2026-15410 Used to validate SMA1000 zero-day exploitation details, SSRF mechanics, and hotfix requirements.
KNX Association Security Guidance — CVE-2023-4346 Used to confirm protocol lockout conditions, affected options, and mitigation controls.
FIRST Exploit Prediction Scoring System (EPSS) Database Used to provide exploitation probability metrics supporting threat-informed patch prioritization.
Hackerstorm CVE Intelligence Portal Used for internal CVE enrichment, analyst workflow integration, vulnerability correlation, and report linking.
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.