CISA has confirmed that ransomware operators are now actively exploiting two previously disclosed vulnerabilities — one in Microsoft SharePoint and two in SonicWall SMA1000 appliances — both of which WaterISAC flagged for members in July.
For SharePoint, ransomware activity has been tied to CVE-2026-45659, a high-severity remote code execution flaw exploitable by low-privilege attackers on unpatched SharePoint Enterprise Server 2016, 2019, and Subscription Edition systems. For SonicWall, threat intelligence firm Resecurity has linked exploitation of CVE-2026-15409 and CVE-2026-15410 — including a maximum-severity server-side request forgery flaw — to an affiliate of the INC Ransomware operation. Both product categories are common in utility IT environments, and the escalation from general exploitation to confirmed ransomware use significantly raises the threat level.