cisaregulatorNewsThe Broadside1 min read

CISA adds four SonicWall, AD FS, SharePoint CVEs to KEV

CISA's catalog entry matters because BOD 26-04 turns edge-device patching into a federal compliance clock.


TL;DR

CISA added CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA1000 appliances, CVE-2026-56155 in Microsoft Active Directory Federation Services, and CVE-2026-56164 in Microsoft SharePoint Server to the Known Exploited Vulnerabilities Catalog. Federal Civilian Executive Branch agencies must prioritize rapid remediation under Binding Operational Directive 26-04 for KEV flaws on publicly exposed assets that grant total control after exploitation. Contractors, vendors, and managed service providers supporting those environments inherit the urgency, even where the CISA alert leaves the exact agency deadline unstated.

CISA's four new Known Exploited Vulnerabilities entries are not just another patch queue refresh. The agency says the SonicWall SMA1000 server-side request forgery and code injection flaws, the Microsoft Active Directory Federation Services access-control flaw, and the Microsoft SharePoint Server missing-authentication flaw all have evidence of active exploitation. Under Binding Operational Directive 26-04, that moves the work from advisory triage to mandatory federal prioritization for Federal Civilian Executive Branch agencies when the affected asset is publicly exposed and post-exploitation access gives an actor total control.

The operational consequence is straightforward: agencies running or relying on SMA1000, AD FS, or SharePoint systems need to accelerate remediation and check for compromise where BOD 26-04 requires it. The contractor consequence is almost as straightforward. A vendor or managed service provider may not be directly bound by the directive, but if it operates, supports, or delays remediation for covered federal systems, the agency's compliance clock becomes its problem too.

CISA's alert does not state the specific remediation date for these four entries, and that omission matters for the people assigning tickets and documenting closure. It also leaves the retroactivity question in practical terms: BOD 26-04 establishes expectations for checking whether threat actors compromised a system before patching, but an already-compromised edge appliance is not fixed by making the vulnerability disappear from a scanner. For federal teams and their suppliers, the useful read is narrower and harder: patch the exposed systems, verify compromise status, and document the decision path before the mandate becomes a contract dispute.


Published ·Deep Fathom