“Immediately inventory all SonicWall SMA1000, Fortinet FortiSandbox, and Cisco IOS XE/ISE appliances across your entire client base and begin emergency patching today—don't wait for next maintenance window.”
ACTIVE OUTAGE: Microsoft 365 & Azure West US Down — Teams, SharePoint, Outlook, Copilot Affected (MO1437424)
Starting at approximately 14:44 UTC on 23 July 2026, a major incident (Tracking ID: ZJV6-SGG) knocked out Azure West US infrastructure, cascading into widespread M365 degradation including Teams, SharePoint, Outlook, Office for the Web, and Copilot. Affected Azure services span AKS, Microsoft Sentinel, Azure Monitor, Azure Firewall, Log Analytics, Microsoft Graph, Power BI Embedded, and more. Workaround: Monitor admin centre incident MO1437424 for updates; consider routing workloads to alternate Azure regions where possible.
Read more →SharePoint, Outlook & Office for the Web Showing Elevated Error Rates — Microsoft Investigating Root Cause
Microsoft confirmed via its 365 Status handle that users in North America are experiencing issues opening Office files and accessing Teams, with elevated error rates across Office for the Web. The company is analysing service telemetry to isolate the source. Workaround: Use the Microsoft 365 Service Health dashboard and reference incident ID MO1437424 in the Admin Centre for live updates.
Read more →SonicWall SMA1000 Zero-Days (CVE-2026-15409 CVSS 10.0 + CVE-2026-15410) Actively Exploited — CISA KEV Added 14 July
SonicWall advisory SNWLID-2026-0008 covers two chained vulnerabilities: CVE-2026-15409 (unauthenticated SSRF, CVSS 10.0) can be combined with CVE-2026-15410 (code injection) to achieve full remote code execution on SMA1000 appliances. Both were added to CISA's KEV catalog on 14 July 2026, with post-compromise activity including exfiltration of credentials, session databases, and TOTP seeds — meaning patching alone may be insufficient if already compromised. Workaround: Update to version 12.4.3-03453 or 12.5.0-02835 immediately, then conduct a forensic review and consider rebuilding compromised appliances.
Read more →Fortinet FortiSandbox: Dual Unauthenticated OS Command Injection Bugs (CVE-2026-39808 & CVE-2026-25089) — Appliance Takeover Risk
Two unauthenticated OS command injection vulnerabilities in Fortinet FortiSandbox — CVE-2026-39808 (affecting versions 4.4.0–4.4.8) and CVE-2026-25089 — can be triggered via crafted HTTP requests and lead to full appliance takeover. Fortinet also addressed unauthenticated VNC access on FortiSandbox in the same advisory cycle (FG-IR-26-100 and FG-IR-26-141). Workaround: Apply Fortinet patches immediately and ensure FortiSandbox management interfaces are not exposed to the internet.
Read more →Cisco IOS XE and ISE: Recurring Exploited CVEs Again Listed on CISA KEV in July 2026
Cisco IOS XE and Identity Services Engine remain recurring entries on the CISA KEV catalogue, with new additions confirmed in July 2026. Security researchers note that patching Cisco devices does not always guarantee a clean state, as some attack techniques survive upgrades. Verify IOC checks and integrity validation after any Cisco patch deployment.
Read more →SonicWall SMA1000 Exploitation Linked to Akira Ransomware Wave — Australian MSPs With SMA Deployments at High Risk
Active exploitation of the SonicWall SMA1000 zero-days (CVE-2026-15409/15410) has been linked to approximately 40 Akira ransomware attacks between mid-July and early August, with CISA confirming ransomware campaign usage. Post-compromise forensics reveal attackers exfiltrated credentials, session databases, and TOTP seed configurations — meaning MFA protections may be compromised even after patching. Australian MSPs managing SonicWall SMA1000 appliances should treat any previously exposed device as fully compromised and initiate incident response procedures.
Read more →Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.