CVE-2026-15409

5 karet z 7 položek · v celém archivu · celý přehled CZ · EN/orig

CVE-2026-15409

KEV ✓ · ransomware EPSS 0.85 EPSS k 20. 9. 2026 náprava do 17. 7. 2026

Hodnocení závažnosti

10.0 CVSS 3.1 CISA-ADP

útok odkudkoli z internetu bez přípravy bez přihlášení bez zásahu uživatele
dopad plný únik dat úplná změna dat úplný výpadek
přesah dopad i mimo zranitelnou součást

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

zvyšuje závažnost mírně zvyšuje závažnost snižuje závažnost

Hvězdička u CVE znamená, že radar to číslo vytáhl z textu článku, ne ze seznamu chyb, který zpráva uvádí — u té zprávy proto neukazuje KEV, EPSS ani CVSS. Fakta o samotném CVE jsou nahoře.

1

1

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …

KEV ✓ · ransomware EPSS 0.97 CVE-2025-49132 CVE-2026-15409 CVE-2026-27760 CVE-2026-29053 CVE-2026-3891 CVE-2026-46300 CVE-2026-48907 CVE-2026-60137 CVE-2026-63030 WordPress Ghost CMS SonicWall Linux US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: Lot of summer shells and fit http profiles

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ · ransomware EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

· Check Point Research · 20th July – Threat Intelligence Report

1

SPOJENO PŘES CVE Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share…

KEV ✓ · ransomware EPSS 0.85 CVSS 10.0 CVE-2026-15409 CVE-2026-15410 SonicWall US SE AT

· Volexity · Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation · CERT-SE · Kritiska sårbarheter i SonicWall SMA1000 · CERT.at · Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

1

Multiples vulnérabilités dans Sonicwall Secure Mobile Access (15 juillet 2026)

Le 14 juillet 2026, Sonicwall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-15409 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...

KEV ✓ · ransomware EPSS 0.85 CVE-2026-15409 Sonicwall FR

· CERT-FR – alerty · Multiples vulnérabilités dans Sonicwall Secure Mobile Access (15 juillet 2026)