Two things landed in the same window this week, and together they make for a busy night for anyone who runs infrastructure. Oracle pushed out its July Critical Patch Update, and it was a monster: 1,449 fixes across databases, middleware, cloud and enterprise apps, the largest single release in the company's history. At the same time, security teams raised the alarm on SonicWall SMA1000 appliances.
The headline bug is CVE-2026-15409, an unauthenticated server-side request forgery rated a maximum CVSS 10.0. On its own that is serious. Chained with a separate code-injection flaw, it opens the door to full remote code execution, and it is already being used in real attacks.
The reason this is so pressing is where the box sits. SMA1000 appliances live at the network boundary, facing the internet, which is exactly the spot attackers probe first. A maximum-severity flaw that needs no login, on a device reachable from outside, is about as urgent as security gets.
If you run a SonicWall SMA1000, treat this as a tonight job, not a next-sprint job. Patch the appliance, confirm it is on a fixed firmware build, and check logs for anything odd. Then work through Oracle's long list by exposure. Anything internet-facing first, everything reachable from outside second, internal systems after that.
None of this is glamorous, but edge devices are the soft underbelly of most networks right now, and a 10.0 that is already being exploited is the clearest signal you will get to move fast.
Related reading on Future Technology: the Zoom account-takeover bug you should also patch and the KVM Januscape hypervisor escape.
Get a plain-English tech briefing in your inbox every morning. Join the free Future Technology newsletter.
Some links may be affiliate links.