CVE-2026-15409

v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

CVE-2026-15409

KEV ✓ EPSS 0.74 náprava do 17. 7. 2026

Hodnocení závažnosti

10.0 CVSS 3.1 CISA-ADP

útok odkudkoli z internetu bez přípravy bez přihlášení bez zásahu uživatele
dopad plný únik dat úplná změna dat úplný výpadek
přesah dopad i mimo zranitelnou součást

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

4 karet z 6 položek

1

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …

KEV ✓ EPSS 0.96 CVE-2025-49132 CVE-2026-15409 CVE-2026-27760 CVE-2026-29053 CVE-2026-3891 CVE-2026-46300 CVE-2026-48907 CVE-2026-60137 CVE-2026-63030 Rapid7 US

Rapid7 ·

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ EPSS 0.96 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

Check Point Research ·

1

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share…

KEV ✓ EPSS 0.76 CVSS 10.0 CVE-2026-15409 CVE-2026-15410 SonicWall US SE AT 3 zdrojů

Volexity · CERT-SE · CERT.at

1