● Daily security briefing
Tuesday, July 14, 2026
On July 14, 2026, the security advisory landscape was marked by the addition of four critical vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog, including CVE-2026-15409 and CVE-2026-15410, both affecting SonicWall SMA1000 Appliances. Additionally, Microsoft reported critical vulnerabilities in Active Directory Federation Services (CVE-2026-56155) and SharePoint Server (CVE-2026-56164), both of which are being actively exploited. A total of 30 advisories were released today, alongside 1,051 new CVEs, highlighting significant security concerns across various platforms. Notably, several other critical vulnerabilities were identified, including CVE-2026-56451 in Opcenter X and CVE-2026-62422 in JetBrains YouTrack, emphasizing the need for immediate attention from security teams.
17 critical3 high1 medium3 unknownacross the day’s notable advisories and CVEs
Added to the KEV catalog
Exploitation observed in the wild — remediate first.
- exploitedCVE-2026-15409CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
- exploitedCVE-2026-15410CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability
- exploitedCVE-2026-56155CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
- exploitedCVE-2026-56164CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
Notable advisories
Critical/high or exploited items from national CERTs and vendor PSIRTs.
- highexploitedmsrcCVE-2026-56155: Active Directory Federation Services Elevation of Privilege Vulnerability
- mediumexploitedmsrcCVE-2026-56164: Microsoft SharePoint Server Elevation of Privilege Vulnerability
- unknownexploitedncsc-nlNCSC-2026-0231 [1.00] [M/H] Vulnerabilities fixed in Microsoft Windows
- criticalexploitedcisaCISA Adds Four Known Exploited Vulnerabilities to Catalog
- criticalexploitedcisaABB Ability Edgenius
- unknownexploitedncsc-nlNCSC-2026-0237 [1.00] [M/H] Vulnerabilities fixed in Microsoft Office
- criticalexploitedcccsMicrosoft security advisory – July 2026 monthly rollup (AV26-698)
- unknownexploitedcisaCISA Urges SharePoint Hardening After New Exploitations
- criticalexploitedcccsSonicWall security advisory (AV26-699) – Update 1
- criticalmsrcCVE-2026-57092: Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-45499: Azure OpenAI Elevation of Privilege Vulnerability
- criticalmsrcCVE-2026-57100: Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
Notable CVEs
Highest-severity CVEs published this day from the NVD and GitHub Advisory firehose — the sharpest items behind the day’s numbers.
- criticalexploitedCVE-2026-15409CVSS 10A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the
- highexploitedCVE-2026-56155CVSS 7.8Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- highexploitedCVE-2026-15410CVSS 7.2Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific
- criticalCVE-2026-56451CVSS 10A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm specified in the JSON Web Token (JWT) header.
- criticalCVE-2026-62422CVSS 10In JetBrains YouTrack before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to adm
- criticalCVSS 9.9GHSA-hgjx-r89m-m7v4: FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
- criticalCVE-2026-44747CVSS 9.9SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized
- criticalCVE-2026-54052CVSS 9.9GHSA-j6r7-6fhx-77wx: n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
- criticalCVE-2026-48318CVSS 9.9ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker
- criticalCVE-2026-45262CVSS 9.9GHSA-5qmh-x653-g8qj: FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`
- criticalCVE-2026-57092CVSS 9.9Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network.
- criticalCVE-2026-56159CVSS 9.8Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Where the day’s advisories came from
Curated CERT and PSIRT sources — these add up to the 30 above.