<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vpn-Appliance on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vpn-appliance/</link><description>Recent content in Vpn-Appliance on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vpn-appliance/index.xml" rel="self" type="application/rss+xml"/><item><title>SonicWall SMA 1000 Two Zero-Days Actively Exploited, May Chain</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-may/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-attackers-exploit-two-sonicwall-sma-1000-zero-days-that-may/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Pre-authentication SSRF (CVSS 10.0) with a public PoC and confirmed active exploitation on SonicWall SMA 1000 series VPN appliances — patch to the vendor-released update immediately and isolate appliances from untrusted networks while patching proceeds.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active zero-day exploitation of an edge VPN device means assume-breach posture: sweep SMA 1000 access and authentication logs for anomalous pre-auth requests and unusual outbound SSRF-originated connections since disclosure, and tune detections for chained exploit behavior from the appliance.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether the organization runs SonicWall SMA 1000 appliances and, if so, brief leadership this week — a CVSS 10.0 pre-auth zero-day under active exploitation on a perimeter VPN is a material risk event that may generate customer or board questions.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-83548 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA 1000 Zero-Days Exploited for Root Access Pre-Disclosure</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-sonicwall-sma-zero-days-exploited-before-disclosure-to-gain/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-sonicwall-sma-zero-days-exploited-before-disclosure-to-gain/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> SonicWall SMA 1000 series VPN appliances were exploited for root access as zero-days since at least June 22, 2026; if this appliance is in your environment, treat it as potentially compromised — isolate it, review for signs of intrusion, and apply any vendor patches immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Threat actor UTA0533 actively exploited SonicWall SMA 1000 appliances before disclosure, meaning some estates may already be rooted; sweep for Volexity-published IOCs and hunt for lateral movement originating from SMA appliance IP addresses since June 22.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A named threat actor achieved root access on widely-deployed SonicWall SMA 1000 VPN appliances before the vulnerability was public — confirm whether your organization uses this product and, if so, direct your team to assess exposure and obtain SonicWall&amp;rsquo;s official incident guidance this week.&lt;/li>
&lt;/ul></description></item><item><title>SonicWall SMA1000 zero-days actively exploited, patches available</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attac/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-sonicwall-warns-of-sma1000-flaws-exploited-in-zero-day-attac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation — patch SMA1000 appliances to the latest firmware immediately and audit access logs for signs of pre-patch compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Edge appliance exploitation means assume-breach posture is warranted — sweep for lateral movement or credential harvesting activity originating from SMA1000 IPs since the zero-day window, and hunt for post-exploitation behavior in downstream systems.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Actively exploited VPN appliances are a board-level exposure; confirm whether your organization runs SMA1000, verify patching status with the engineering team, and prepare a brief in case the incident becomes public.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-15409 — CISA KEV: listed, EPSS n/a, public PoC on GitHub, reported by 2 collected sources · CVE-2026-15410 — CISA KEV: listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>