Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since July 14, 2026.

Known ransomware use

CVE-2026-15410

SonicWall SMA1000 Appliances Code Injection Vulnerability

SonicWall · SMA1000 Appliances

Added to KEV July 14, 2026

Alert details

Source feed
CISA KEV
CVE ID
CVE-2026-15410
CWE
CWE-94
Affected products
SMA1000 Appliances · SonicWall SMA1000 Appliances · SonicWall

What happened

SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.

What it means for your business

SonicWall SMA1000 Appliances is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-15410). SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. CISA remediation due date: 2026-07-17. If you need help checking exposure, call (864) 335-9223.

Required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA due date: July 17, 2026

Sources

Related briefs

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.