Security Roundup: SonicWall Zero-Days, Microsoft's Record Patch Tuesday, and the Klue Breach Fallout (Week of July 13, 2026)
Weekly briefing: SonicWall SMA 1000 zero-day chain, Microsoft 622-CVE Patch Tuesday, Accenture breach, and GhostApproval AI trust flaws.
This week brought active exploitation of a maximum-severity SonicWall SMA appliance flaw, Microsoft's largest Patch Tuesday on record, a major consulting-firm breach, continued fallout from the Klue supply chain compromise, and new Wiz Research findings on a systemic trust-boundary flaw across AI coding assistants. Details, CVEs, and remediation below.
SonicWall SMA 1000 Zero-Days Under Active Exploitation
SonicWall disclosed two zero-days in its Secure Mobile Access (SMA) 1000 series appliances, both confirmed under active exploitation and added to CISA's KEV catalog this week.
CVE-2026-15409 — CVSS 10.0 — Server-Side Request Forgery (SSRF) in the SMA 1000 management interface, allowing unauthenticated attackers to reach internal network resources through the appliance.
CVE-2026-15410 — CVSS 7.2 — Post-authentication code injection, allowing an already-authenticated attacker to execute arbitrary code on the appliance.
Attack chain: attackers appear to be chaining the two, using the unauthenticated SSRF to reach internal management functions, then pivoting into the post-auth code injection path to gain code execution, consistent with prior SonicWall SMA exploitation patterns.
Remediation: apply SonicWall's emergency firmware update for SMA 1000 series immediately. If patching is delayed, restrict management interface access to trusted IPs only and review VPN session logs for anomalous authentication.
Microsoft's Record Patch Tuesday: 622 CVEs, Two Under Active Attack
Microsoft's July release covered 622 CVEs, the largest single Patch Tuesday on record, including two zero-days already being exploited:
CVE-2026-56164 — CVSS 5.3 — SharePoint Server, unauthenticated network privilege escalation.
CVE-2026-56155 — CVSS 7.8 — Active Directory Federation Services (AD FS), authenticated local privilege escalation via weak access controls.
Separately, CVE-2026-45659 (SharePoint Server RCE) was added to CISA's KEV catalog this week after confirmed in-the-wild exploitation, joining earlier SharePoint flaws in active attack chains against on-prem SharePoint deployments.
Remediation: prioritize the SharePoint and AD FS updates in this month's cumulative rollup. For internet-facing SharePoint servers, treat as emergency-patch priority given the KEV listing, and audit AD FS trust configurations for the access-control weakness in CVE-2026-56155.
Accenture Confirms Breach After Source Code Theft Claim
Accenture confirmed a breach after a threat actor claimed to have stolen roughly 35GB of internal data, including Azure access keys and tokens, configuration files, RSA/SSH keys, and proprietary source code.
Remediation: if you have vendor relationships with Accenture, rotate any shared credentials or API keys. Watch for phishing/BEC attempts referencing exposed configuration or key material, and treat any leaked RSA/SSH keys as compromised and rotate regardless of confirmed misuse.
Wiz Research: GhostApproval, a Trust Boundary Flaw Across AI Coding Assistants
Wiz Research disclosed a systemic vulnerability class, dubbed GhostApproval, affecting six major AI coding assistants, where agents write file changes to disk before the user-facing approval or undo dialog is shown, turning a supposed authorization gate into a post-hoc undo button.
Cursor was assigned CVE-2026-50549, fixed in v3.0.
Windsurf writes modifications to disk before Accept or Reject controls render, enabling attacker-supplied SSH key injection via disguised files ahead of user review.
Google Antigravity's permission dialog displays the symlink path rather than the resolved canonical path, allowing a symlink disguised as project_settings.json to redirect writes to the SSH directory. Google is assessing CVE issuance.
Amazon Q internally identifies symlink targets correctly but proceeds with the write before offering Undo.
Remediation: update affected assistants to patched versions as they ship, including Cursor v3.0 and later. Until patched, avoid running AI coding agents with write access in directories containing symlinks to sensitive paths, and review agent action logs for unexpected writes outside the project directory.
Klue Supply Chain Breach: Fallout Continues
Fallout continued this week from the June Klue breach, in which attackers used compromised legacy credentials to access Klue's integration environment and steal OAuth tokens tied to customer platform integrations, in an attack window of June 11 to 12. Roughly two dozen Klue customers have now confirmed impact, including LastPass, Huntress, Recorded Future, Tanium, Jamf, Gong, Sprout Social, and HackerOne. Salesforce disabled the Klue Battlecards integration on June 17. Klue has revoked affected credentials and removed unauthorized code.
Remediation: any org with a past or present Klue integration should audit connected OAuth grants and API tokens issued to Klue, revoke and reissue as a precaution, and review integration logs for the June 11 to 12 window for anomalous data access.
Deep Dives
Deeper technical breakdowns of this week's top stories:
CVE-2026-15409 & CVE-2026-15410: Inside the SonicWall SMA 1000 Zero-Day Chain, at colibrisec.org/cve-2026-15409-cve-2026-15410-inside-the-sonicwall-sma-1000-zero-day-chain/
CVE-2026-56164 & CVE-2026-56155: Microsoft's SharePoint and AD FS Zero-Days in the July 622-CVE Patch Tuesday, at colibrisec.org/cve-2026-56164-cve-2026-56155-microsofts-sharepoint-and-ad-fs-zero-days-in-the-july-622-cve-patch-tuesday/
Accenture Breach: What Was Taken, Third-Party Exposure, and What to Do If You're a Vendor or Client, at colibrisec.org/accenture-breach-what-was-taken-third-party-exposure-and-what-to-do-if-youre-a-vendor-or-client/
GhostApproval: How Wiz Research Found AI Coding Assistants Writing Files Before You Approve Them, at colibrisec.org/ghostapproval-how-wiz-research-found-ai-coding-assistants-writing-files-before-you-approve-them/
Klue Supply Chain Breach: What Happened, Who's Affected, and What to Audit, at colibrisec.org/klue-supply-chain-breach-what-happened-whos-affected-and-what-to-audit/
Sources
The Hacker News: SonicWall SMA 1000 zero-days, SharePoint RCE CVE-2026-45659 added to KEV, and Microsoft's 622-CVE Patch Tuesday.
CISA: KEV catalog additions, July 14 to 15, 2026, covering SonicWall, SharePoint, and AD FS.
SecurityWeek: Accenture breach and Klue supply chain attack customer impact.
Wiz Research and Dark Reading: GhostApproval AI coding assistant trust boundary flaw.