Act
active
CISA KEV Adds Seven Flaws Including CVSS 10 SonicWall SSRF
- Engineer — Act: CVE-2026-83548 is a CVSS 10.0 unauthenticated SSRF in SonicWall SMA 1000 — KEV-listed with a public GitHub PoC and confirmed active exploitation. Patch SonicWall SMA 1000 to the vendor-fixed version immediately and audit outbound connections from the appliance for reverse-shell traffic or unauthorized processes.
- SOC/IR — Act: Attackers exploiting these flaws are deploying reverse shells and crypto miners, giving clear post-compromise detection surface. Hunt for anomalous outbound connections and miner processes originating from SonicWall SMA 1000 appliances since the KEV listing date, and tune EDR/SIEM rules for reverse-shell execution patterns on edge devices.
- Leader — Act: A CVSS 10.0 unauthenticated flaw in a widely deployed enterprise VPN appliance is now KEV-confirmed exploited — this warrants same-week action. Confirm with your engineering team whether SonicWall SMA 1000 is in your estate and verify patch status; VPN compromise is a common lateral-movement entry point that may require disclosure if exploitation is found.
- Signals: CVE-2026-83548 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.