CuraSec

Act active

CISA KEV Adds Seven Flaws Including CVSS 10 SonicWall SSRF

2026-09-03 14:58 UTC · The Hacker News · read the source ↗ #cisa-kev#sonicwall#ssrf
  • Engineer — Act: CVE-2026-83548 is a CVSS 10.0 unauthenticated SSRF in SonicWall SMA 1000 — KEV-listed with a public GitHub PoC and confirmed active exploitation. Patch SonicWall SMA 1000 to the vendor-fixed version immediately and audit outbound connections from the appliance for reverse-shell traffic or unauthorized processes.
  • SOC/IR — Act: Attackers exploiting these flaws are deploying reverse shells and crypto miners, giving clear post-compromise detection surface. Hunt for anomalous outbound connections and miner processes originating from SonicWall SMA 1000 appliances since the KEV listing date, and tune EDR/SIEM rules for reverse-shell execution patterns on edge devices.
  • Leader — Act: A CVSS 10.0 unauthenticated flaw in a widely deployed enterprise VPN appliance is now KEV-confirmed exploited — this warrants same-week action. Confirm with your engineering team whether SonicWall SMA 1000 is in your estate and verify patch status; VPN compromise is a common lateral-movement entry point that may require disclosure if exploitation is found.
  • Signals: CVE-2026-83548 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.