- ## Þjónustu samantekt Þjónustuþátturinn er ennþá með aðalvirkni í nýtingu á almennt notuðum kerfisvirkni í fyrirtæki. **SonicWall SMA1000** núll-daga veikleikar (CVE-2026-15409, CVE-2026-15410) eru nú beinlega notaðir af gíslatökuhugbúnaðarhópum, sem hefur aukast ráðstöfun á VPN kerfum. **Fortinet** er ennþá aðalmarkmið, með nýjum kritískum RCE (fjarkeyrsla kóða) veikleikum í FortiSandbox og FortiClientEMS sem eru í virkri nýtingu. Þar að auki eru kritískar veikleikar í **Microsoft SharePoint**, **Splunk Enterprise**, og **Oracle E-Business Suite** nýttar í vinnu, sem krefst aukastæða uppfærslu á áhrifastöðum kerfum. ## ⚠️ Þörf á áætlaðri aðgerð
- *SonicWall SMA1000 núll-daga nýtingar** Fjöldi kritískra núll-daga veikleika er í virkri nýtingu af gíslatökuhugbúnaðarhópum, sem leyfir fjarkeyrslu kóða og auðkenningarframhjáhlaup á SMA1000 VPN kerfum.
- *CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Firmware 12.4.3-03245 og seinna
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
- *Splunk Enterprise óauðkennd fjarkeyrsla kóða** Kritískur veikleikur í Splunk Enterprise leyfir óauðkennd fjarkeyrslu kóða og er í virkri nýtingu.
- *CVE:** CVE-2026-20253 (CVSS: Ekki tilgreint)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Splunk Enterprise útgáfur 10.x og 9.x áður en nýjar uppfærslur
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
- *Oracle E-Business Suite kritísk fjarkeyrsla kóða** Kritískur veikleikur í Oracle Payments og öðrum hlutum er í virkri nýtingu, sem leyfir fjarkeyrslu á öryggisástandi, heimildi og aðgangi.
- *CVE:** CVE-2026-46817 (CVSS: 9.8-9.9)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur 12.2.3 til 12.2.15
- *Lagfært í:** Uppfærslur útgefnar maí 2026 — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [SC Media: Critical Oracle EBS bug added to CISA list of exploited vulnerabilities](https://www.scworld.com/news/critical-oracle-ebs-bug-added-to-cisa-list-of-exploited-vulnerabilities)
- *Fortinet FortiSandbox óauðkennd fjarkeyrsla kóða** Fjöldi kritískra veikleika leyfir óauðkennd fjarkeyrslu kóða með sérstaklega HTTP beðum og er í virkri nýtingu.
- *CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: 9.8 til 9.1)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** FortiSandbox 4.4.0-4.4.8, 5.0.0-5.0.5, og eldri
- *Lagfært í:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Register Security: Attackers target critical FortiSandbox flaws as CISA issues patch order](https://www.theregister.com/a/5274287)
- *Microsoft SharePoint núll-daga fjarkeyrsla kóða** Fjöldi kritískra SharePoint veikleika var í virkri nýtingu áður en árið, með einu nýjum viðauka (CVE-2026-58644) til CISA's KEV lista.
- *CVE:** CVE-2026-58644, CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5)
- *Staða:** Í virkri nýtingu
- *Veikar útgáfur:** Útgáfur áður en 16.0.19127.20442 og 16.0.19725.20210
- *Lagfært í:** Uppfærslur útgefnar maí/júní 2026
- *Tímabundin lausn:** Ekkert nefnt í heimildum
- *Heimild:** [The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html) ## 📋 Uppfærslur og uppfærslur
- *Adobe ColdFusion:** Adobe hefur uppfært 55 kritískar veikleikar í 11 vörum, með fjölda hávirkna veikleika í ColdFusion 2023 og 2025 sem leyfir fjarkeyrslu kóða. Fjöldi, eins og CVE-2026-48282, var í virkri nýtingu.
- *Microsoft Edge og Chrome:** Google Chrome núll-daga veikleikur CVE-2026-2441 var uppfært í febrúar 2026. Fjöldi kritískra og hávirkna veikleika í Microsoft Edge, sem áhrif á útgáfur áður en 146.0.7680.75, hefur einnig verið uppfært.
- *Zoom:** Fjöldi kritískra réttindaaukninga veikleika í Zoom Rooms og Workplace, með CVSS stig upp á 9.8 og áhrif á Windows, iOS og Android, hefur verið uppfært.
- *n8n Workflow Automation:** Kritískar veikleikar í n8n (áður en 1.123.55 og 2.2.2) sem leyfir fjarkeyrslu kóða, auðkenningarframhjáhlaup og gagnaflyttingu, hefur verið uppfært í nýjum útgáfum.
- *Veeam Backup & Replication:** Fjöldi kritískra fjarkeyrslu kóða veikleika sem áhrif á útgáfur áður en 12.3.2.4854 og 13.0.2.29 hefur verið uppfært. Þessar veikleikar leyfa auðkenndan notanda að keyra óskilgreinda kóða og auka réttindi. ## 🔍 Þjónustu aðgerð
- *npm aðfangakeðju aðgreiningar:** Þjónustu aðgreiningar hafa áhrif á npm útgáfur (`@automagik/genie`, `pgserve`) með skadalegum kóða sem leyfir að sækja út forritarauðkenni, API lykla og kriptóvalda. Kóðinn notar postinstall fyrirhuga og sjálfgefnar útgáfur.
- *FortiClientEMS nýting:** Þjónustu aðgreiningar eru í virkri nýtingu á kritískri SQL-innsetningu veikleika (CVE-2026-21643) og aðgangsstýringu veikleika (CVE-2026-35616) í FortiClientEMS (útgáfur 7.4.0-7.4.6) til að setja innfærsluþjónustu á fyrirtæki. ## Daglegar fyrirspurnir 1. **Uppfæra SonicWall SMA1000 kerfum á meðferð.** Staðfestu nýtingarstöðu á CVE-2026-15409 og CVE-2026-15410 á ytri hringnum og skilríðu nýjasta firmware. 2. **Skoðaðu og uppfæra Splunk Enterprise útgáfur.** Fokusaðu á uppfærslu fyrir CVE-2026-20253 vegna virkra, óauðkenndra nýtinga. 3. **Uppfæra Fortinet uppfærslur.** Fokusaðu á FortiSandbox og FortiClientEMS útgáfur, þar sem þær eru í virkri nýtingu fyrir fyrirstöðu og auðkenningu. 4. **Staðfestu SharePoint og Oracle E-Business Suite uppfærslu nákvæmni.** Tryggðu að kerfum séu uppfærð með útgáfum sem auka á nýjasta nýttu CVEs sem eru í CISA's KEV lista. ## 🔗 Heimildir - [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237) - [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286) - [The Register Security: Attackers target critical FortiSandbox flaws as CISA issues patch order](https://www.theregister.com/a/5274287) - [SC Media: Critical Oracle EBS bug added to CISA list of exploited vulnerabilities](https://www.scworld.com/news/critical-oracle-ebs-bug-added-to-cisa-list-of-exploited-vulnerabilities) - [The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html)
## Executive Summary The threat landscape remains dominated by active, widespread exploitation of critical vulnerabilities in widely deployed enterprise software. **SonicWall SMA1000** zero-days (CVE-2026-15409, CVE-2026-15410) are now confirmed to be leveraged by ransomware groups, escalating the immediate risk to VPN infrastructure. **Fortinet** continues to be a primary target, with new critical RCE flaws in FortiSandbox and FortiClientEMS under active attack. Additionally, critical vulnerabilities in **Microsoft SharePoint**, **Splunk Enterprise**, and **Oracle E-Business Suite** are being exploited in the wild, requiring urgent patching across affected systems.
## ⚠️ Immediate Action Required * **SonicWall SMA1000 Zero-Day Exploits** Multiple critical zero-day vulnerabilities are being actively exploited by ransomware groups, allowing remote code execution and security bypass on SMA1000 VPN appliances. * **CVE:** CVE-2026-15409, CVE-2026-15410 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Firmware 12.4.3-03245 and later * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
* **Splunk Enterprise Unauthenticated RCE** A critical vulnerability in Splunk Enterprise allows unauthenticated remote code execution and is being actively exploited. * **CVE:** CVE-2026-20253 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Splunk Enterprise versions 10.x and 9.x prior to recent patches * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
* **Oracle E-Business Suite Critical RCE** A critical vulnerability in Oracle Payments and other modules is actively exploited, allowing remote compromise of confidentiality, integrity, and availability. * **CVE:** CVE-2026-46817 (CVSS: 9.8-9.9) * **Status:** Active exploitation detected * **Vulnerable:** Versions 12.2.3 through 12.2.15 * **Fixed:** Patches released May 2026 — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [SC Media: Critical Oracle EBS bug added to CISA list of exploited vulnerabilities](https://www.scworld.com/news/critical-oracle-ebs-bug-added-to-cisa-list-of-exploited-vulnerabilities)
* **Fortinet FortiSandbox Unauthenticated RCE** Multiple critical vulnerabilities allow unauthenticated remote code execution via crafted HTTP requests and are under active exploitation. * **CVE:** CVE-2026-39813, CVE-2026-39808, CVE-2026-25089, CVE-2026-26083, CVE-2026-44277 (CVSS: 9.8 to 9.1) * **Status:** Active exploitation detected * **Vulnerable:** FortiSandbox 4.4.0-4.4.8, 5.0.0-5.0.5, and earlier * **Fixed:** Not specified in source — check vendor advisory * **Workaround:** None mentioned in source * **Reference:** [The Register Security: Attackers target critical FortiSandbox flaws as CISA issues patch order](https://www.theregister.com/a/5274287)
* **Microsoft SharePoint RCE Zero-Day** Multiple critical SharePoint vulnerabilities were actively exploited earlier this year, with one recent addition (CVE-2026-58644) to CISA's KEV catalog. * **CVE:** CVE-2026-58644, CVE-2026-20963 (CVSS: 8.8), CVE-2026-32201 (CVSS: 6.5) * **Status:** Active exploitation detected * **Vulnerable:** Versions prior to 16.0.19127.20442 and 16.0.19725.20210 * **Fixed:** Patches released March/April 2026 * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html)
## 📋 Patches & Updates * **Adobe ColdFusion:** Adobe has patched 55 critical vulnerabilities across 11 products, including multiple high-severity flaws in ColdFusion 2023 and 2025 that allow remote code execution. Several, like CVE-2026-48282, were actively exploited. * **Microsoft Edge & Chrome:** Google Chrome zero-day CVE-2026-2441 was patched in February 2026. Multiple critical and high-severity vulnerabilities in Microsoft Edge, affecting versions prior to 146.0.7680.75, have also been patched. * **Zoom:** Multiple critical privilege escalation vulnerabilities in Zoom Rooms and Workplace, rated up to CVSS 9.8 and affecting Windows, iOS, and Android, have been patched. * **n8n Workflow Automation:** Critical vulnerabilities in n8n (prior to 1.123.55 and 2.2.2) allowing remote code execution, security bypass, and data exfiltration have been patched in updated versions. * **Veeam Backup & Replication:** Multiple critical remote code execution vulnerabilities affecting versions prior to 12.3.2.4854 and 13.0.2.29 have been patched. These flaws allow authenticated users to execute arbitrary code and escalate privileges.
## 🔍 Threat Activity * **npm Supply Chain Attacks:** A series of attacks compromised npm packages (`@automagik/genie`, `pgserve`) with malware designed to steal developer credentials, API keys, and cryptocurrency data. The malware uses postinstall hooks and self-propagates via republished package versions. * **FortiClientEMS Exploitation:** Threat actors are actively exploiting a critical SQL injection vulnerability (CVE-2026-21643) and an access control flaw (CVE-2026-35616) in FortiClientEMS (versions 7.4.0-7.4.6) to deploy infostealer malware onto enterprise devices.
## Today's Priorities 1. **Patch SonicWall SMA1000 appliances immediately.** Confirm exploitation status of CVE-2026-15409 and CVE-2026-15410 on your perimeter and apply the latest firmware. 2. **Review and update Splunk Enterprise instances.** Prioritize patching for CVE-2026-20253 due to active, unauthenticated exploitation. 3. **Apply Fortinet patches.** Focus on FortiSandbox and FortiClientEMS deployments, as these are under active attack for initial access and credential theft. 4. **Verify SharePoint and Oracle E-Business Suite patch levels.** Ensure systems are updated to versions that address the recently exploited CVEs listed in CISA's KEV catalog.
## 🔗 References
- [Volexity: Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation](https://www.volexity.com/?p=5237)
- [Help Net Security: Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)](https://www.helpnetsecurity.com/?p=375286)
- [The Register Security: Attackers target critical FortiSandbox flaws as CISA issues patch order](https://www.theregister.com/a/5274287)
- [SC Media: Critical Oracle EBS bug added to CISA list of exploited vulnerabilities](https://www.scworld.com/news/critical-oracle-ebs-bug-added-to-cisa-list-of-exploited-vulnerabilities)
- [The Hacker News: CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV](https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html)