Security Briefing | July 15, 2026 - Microsoft Patches Record 622 Flaws Including Two Exploited Zero-Days, SonicWall SMA 1000 Zero-Days Actively Exploited, AsyncAPI npm Packages Deliver Botnet Malware
Microsoft's July 2026 Patch Tuesday is the largest on record, addressing 622 vulnerabilities including two actively exploited zero-days in Active Directory and SharePoint Server. SonicWall warned of active exploitation of two SMA 1000 zero-days including CVE-2026-15409 (CVSS 10.0), an SSRF flaw potentially enabling remote code execution. Four compromised npm packages in the AsyncAPI namespace were found distributing a multi-stage botnet loader.
By EACA Summit Content Team

1. Microsoft Patches Record 622 Flaws, Including Two Exploited Zero-Days
Microsoft shipped its largest Patch Tuesday on record, fixing 622 vulnerabilities according to The Hacker News and SecurityWeek, with Krebs on Security reporting a slightly different figure of 570. Two zero-days are being actively exploited: one in Active Directory and one in SharePoint Server. The update also addresses a publicly disclosed BitLocker vulnerability.
Verified Facts
- Microsoft released its largest ever Patch Tuesday update in July 2026
- Two zero-day vulnerabilities are under active attack: one in Active Directory and one in SharePoint Server
- A BitLocker vulnerability was publicly disclosed prior to the patch
Evidence
- Microsoft Security Update Guide
- Multiple source confirmation from The Hacker News, SecurityWeek, and Krebs on Security
Impact
Defenders must prioritize patching the two exploited zero-days and the BitLocker flaw to prevent active exploitation and potential data exposure.
Confidence Level: High
Sources The Hacker News | SecurityWeek | Krebs on Security
2. SonicWall SMA 1000 Zero-Days Exploited in the Wild

SonicWall warned of active exploitation of two zero-day vulnerabilities in SMA 1000 series appliances. CVE-2026-15409 (CVSS 10.0) is an SSRF flaw that could allow remote code execution, and CVE-2026-15410 enables arbitrary command execution. Patches are urgently recommended.
Verified Facts
- CVE-2026-15409 is a server-side request forgery vulnerability with CVSS score 10.0
- CVE-2026-15410 allows arbitrary command execution
- Both vulnerabilities are being actively exploited
Evidence
- CVE-2026-15409
- CVE-2026-15410
- SonicWall advisory
Impact
Organizations using SonicWall SMA 1000 appliances should apply patches immediately to prevent remote takeover.
Confidence Level: High
Sources The Hacker News | SecurityWeek
3. Compromised AsyncAPI npm Packages Deliver Botnet Malware
Four compromised npm packages in the @asyncapi namespace were found distributing a multi-stage botnet loader. The affected packages are @asyncapi/generator-helpers (1.1.1), @asyncapi/generator-components (0.7.1), @asyncapi/generator (3.3.1), and @asyncapi/specs (v6.11.2 and v6.11.2-alpha.1).
Verified Facts
- Four npm packages in the @asyncapi namespace were compromised
- The packages delivered a multi-stage botnet loader
- Affected packages: @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, @asyncapi/generator@3.3.1, @asyncapi/specs (v6.11.2, v6.11.2-alpha.1)
Evidence
- OX Security, SafeDep, Socket, and StepSecurity reports
Impact
Developers using these packages should check for compromise and rotate any exposed credentials immediately.
Confidence Level: High
Sources The Hacker News
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



