ctipilot.ch
← Back to Weekly 2026-W29
HIGHexploitedNATOA1synthesis

Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation

discovered 2026-07-19 23:40 UTCrun 2026-07-19T2310Z-weekly5 sourcesmulti-source

If you did nothing this week: every internet-facing SonicWall SMA 1000, on-prem ShareFile Storage Zone Controller, exposed Oracle E-Business Suite web tier and unpatched on-prem SharePoint Server in your estate is now sitting behind at least one confirmed, in-the-wild-exploited pre-authentication vulnerability — and for the appliance and SharePoint cases, an attacker who reached it before you patched still holds credentials or keys that the patch does not revoke.

The common shape this week was not a single product but a category crossing the line from disclosed to exploited. SonicWall SMA 1000 is the sharpest case: Volexity reconstructed the intrusion behind the actively-exploited CVE-2026-15409 (CVSS 10.0 server-side request forgery) and CVE-2026-15410, attributing it to an actor it tracks as UTA0533 with the earliest compromise on 2026-06-22 (Volexity, 2026-07-17). An unauthenticated /wsproxy request tunnels to a localhost-only service for initial code execution, a hotfix-rollback path traversal escalates to root, and the actor then injects a Suo5 proxy and an ORANGETAIL Java webshell into the appliance's legitimate workplace process, captures cleartext LDAP credentials with tcpdump, and pivots inward — "No valid SMA session cookie was required during this process" (Volexity, 2026-07-17). SonicWall's own PSIRT confirms "the active exploitation of the vulnerabilities described in this advisory" and both CVEs are KEV-listed (SonicWall PSIRT, 2026-07-14).

Progress ShareFile ran the same play in compressed time: Shadowserver honeypots "first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday" — the same day Progress ordered every on-prem Storage Zone Controller powered off — with an ISMG-cited analyst assessing "This smells like CL0P ransomware group activity" (BankInfoSecurity, 2026-07-13); Progress later named a path-traversal root cause and shipped 5.12.5/6.0.2. Oracle E-Business Suite Payments was exploited even earlier and quieter — decoys "recorded the first in-the-wild exploitation of CVE-2026-46817 ... roughly six weeks after Oracle's May 2026 patch and before any public proof-of-concept existed" (Help Net Security, 2026-06-30), and CISA KEV-listed it on 2026-07-15. Microsoft's on-prem stack closed the set: July's cycle patched two exploited zero-days (AD FS EoP CVE-2026-56155, SharePoint EoP CVE-2026-56164), then CISA confirmed active exploitation of a wider on-prem SharePoint cluster "enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances" (CISA, 2026-07-16) — theft of IIS machine keys is among the documented post-exploitation actions.

SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.

SonicWall PSIRT (SNWLID-2026-0008)

Honeypots run by nonprofit cybersecurity organization Shadowserver Foundation first recorded active, in-the-wild attacks attempting to exploit CVE-2026-2699 on Friday.

BankInfoSecurity (ISMG) 2026-07-13

CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances.

CISA 2026-07-16

ATT&CK mapping

5 techniques mapped from the cited reporting · MITRE ATT&CK v19.1

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1040Network Sniffing

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

overlap matrix · ATT&CK page ↗

Discovery TA0007
T1040Network Sniffing

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

overlap matrix · ATT&CK page ↗

Command and Control TA0011
T1090Proxy

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap. Adversaries use these types of proxies to manage command and control communications, reduce the number of simultaneous outbound network connections, provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. Adversaries may chain together multiple proxies to further disguise the source of malicious traffic.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.