← Carolina Clear Tech

Cyber Threat Brief

2026-07-20

Listen to this brief (11:06)

Download MP3
Show Notes

Show Notes - 2026-07-20

Stories Covered

CVEs Referenced

CVE-2026-14266, CVE-2026-15409, CVE-2026-15410, CVE-2026-42533, CVE-2026-45784, CVE-2026-48095, CVE-2026-53374, CVE-2026-53375, CVE-2026-53376, CVE-2026-53381, CVE-2026-53382, CVE-2026-53383, CVE-2026-53386, CVE-2026-53390, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53397, CVE-2026-53402, CVE-2026-62389, CVE-2026-63795, CVE-2026-63796, CVE-2026-63801, CVE-2026-63803, CVE-2026-63805, CVE-2026-63806, CVE-2026-63808, CVE-2026-63809, CVE-2026-63810, CVE-2026-63812, CVE-2026-63815, CVE-2026-63816, CVE-2026-63819, CVE-2026-63822, CVE-2026-63825, CVE-2026-63826, CVE-2026-63828, CVE-2026-63829, CVE-2026-63833, CVE-2026-63834, CVE-2026-63836, CVE-2026-63853

Indicators of Compromise

IP Addresses: 37.0.3.1

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - July 20, 2026

Today: SonicWall SMA zero-days exploited in the wild with CISA KEV deadlines passed, NGINX critical heap overflow affects 15 years of releases with possible RCE, and 7-Zip XZ handling flaw patched in late June. Patches are out for all three, update immediately.

Critical Alerts

SonicWall SMA Zero-Days Exploited Before Disclosure (CVE-2026-15409, CVE-2026-15410)

Threat actor UTA0533 exploited two SonicWall Secure Mobile Access (SMA) 1000 VPN zero-days starting June 22, 2026, before public disclosure. CVE-2026-15409 (CVSS 10.0) is a pre-authentication WebSocket bypass that allows unauthenticated external requests to tunnel to localhost services. CVE-2026-15410 (CVSS 7.2) enables privilege escalation to root. Both were chained to deploy custom malware including ROOTRUN (setuid privilege escalation binary), KNUCKLEBALL (persistence via modified startup scripts), Suo5 (HTTP proxy), and ORANGETAIL (Java web shell). Volexity observed the attacker sniffing LDAP traffic to capture credentials and modifying NGINX Unit configs to route to backdoor endpoints. Both CVEs are now on CISA KEV with a remediation deadline of July 17, 2026 (already passed). EPSS scores are low (1.3% and 1.5%), but active exploitation is confirmed.

NGINX Heap Overflow in Script Engine (CVE-2026-42533)

NGINX versions 0.9.6 through 1.31.2 (2011 to present) contain a critical heap buffer overflow in the script engine that can crash workers or enable remote code execution. CVE-2026-42533 (CVSS 9.2 v4 / 8.1 v3.1, EPSS 99th percentile at 61.5%) affects configurations using regex-based maps where the output variable is referenced in a string expression after a capture from an earlier regex match. The flaw occurs when the map's regex evaluation overwrites shared capture state between the engine's two-pass buffer allocation and write operations. F5 conditions RCE on ASLR being disabled or bypassed, but security researcher Stan Shaw argues the flaw itself provides the ASLR bypass through uninitialised heap data disclosure, achieving 10/10 success in testing on default Ubuntu 24.04 builds. F5's temporary mitigation (switching to named captures) leaves a second exploitation path open when map defines the same named group as the location regex.

Patch Priority

Vulnerability Disclosures

7-Zip XZ Archive Handling Flaw (CVE-2026-14266)

7-Zip versions prior to 26.02 contain a heap-based buffer overflow (CVE-2026-14266, CVSS 7.0, EPSS 57th percentile) in XZ chunked data processing. Opening a crafted XZ archive can execute code in the context of the current process. The flaw is a local attack vector (AV:L) requiring user interaction and high attack complexity, not network-reachable. The overflow occurs in the MixCoder_Code function in C/XzDec.c where the decoder receives the full output buffer length on each pass instead of remaining space after earlier writes. Code runs under 7-Zip's token (filtered standard-user on Windows unless elevated). The flaw appears in source code back to at least version 21.07 (2021). Trend Micro ZDI published details July 15, but the patch shipped June 25 in version 26.02, giving a 20-day head start. No public proof-of-concept or exploitation in the wild as of July 20.

Linux Kernel CVEs (Multiple)

Microsoft Security Response Center published 30 Linux kernel CVEs on July 19, covering subsystems including ksmbd (SMB server), f2fs and exfat filesystems, NFS client/server, KVM virtualization, network stack (ip_gre, batman-adv, tipc, hdlc_ppp), and various drivers (amdgpu, amdkfd, ath11k WiFi). Highlights include CVE-2026-53390 (ksmbd out-of-bounds read in DACL check), CVE-2026-53383 (ksmbd compound request session validation), CVE-2026-63806 (KVM guest-triggerable BUG_ON replaced with safer handling), CVE-2026-63833 (ntfs3 rejection of userspace writes to reserved xattrs), CVE-2026-63829 (ip_gre CAP_NET_ADMIN requirement for changelink), CVE-2026-63828 (AppArmor mediation of TCP fast open implicit connect), and multiple use-after-free, NULL pointer dereference, divide-by-zero, and bounds check failures. MSRC entries contain minimal detail ("Information published" only), no CVSS scores, and sparse EPSS coverage.

Rust OpenSSL Binding Out-of-Bounds Write (CVE-2026-45784)

The rust-openssl crate contains a potential out-of-bounds write in CipherCtxRef::cipher_update_inplace for AES-KW-PAD ciphers (CVE-2026-45784, EPSS 8th percentile at 0.2%). MSRC published the CVE on July 19 with no additional detail beyond "Information published." AES Key Wrap with Padding is a NIST-standardized key encryption algorithm, less commonly used than AES-GCM or ChaCha20-Poly1305 in modern applications. Impact depends on whether the affected method is reachable in deployed code.

Node.js ws Library Memory Exhaustion (CVE-2026-62389)

The ws library (WebSocket implementation for Node.js) prior to version 8.21.1 allows memory exhaustion denial of service due to default maxFragments setting (CVE-2026-62389, EPSS 36th percentile at 0.4%). MSRC published the CVE on July 19. The ws library is widely used in Node.js applications for WebSocket support. Memory exhaustion can crash the process, disrupting service.

Trends & Context

Zero-day exploitation continues to target edge devices (VPNs, firewalls) that defenders patch slowly, with SonicWall SMA joining the long list of exploited appliances. The NGINX script engine flaw demonstrates how obscure configuration patterns can hide critical vulnerabilities for over a decade in widely deployed software. The 30-CVE Linux kernel batch from MSRC reflects the kernel community's systematic backporting of stability and security fixes to long-term support branches, not necessarily active exploitation.