Výsledky hledání

výrobce: SonicWall× v celém archivu zrušit filtry

26 karet z 37 položek CZ · EN/orig

1

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!New module content (16)Elasticsearch ingest-attachment Apache Tika XFA XXE Local File ReadAuthors: Bourbon Offensive Security Services and Jean-Marie BourbonType: AuxiliaryPull request: #21739…

KEV ✓ EPSS 0.88 CVE-2025-54988 CVE-2025-66516 CVE-2026-19295 CVE-2026-20079 CVE-2026-20929 CVE-2026-23744 CVE-2026-48558 CVE-2026-63077 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 CVE-2026-83548 CVE-2026-83549 Cisco PaperCut SonicWall JetBrains US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: This One Goes to Sixteen!

1

SonicWall security advisory (AV26-884)

Serial Number: AV26-884Date: September 4, 2026 As of September 4, 2026, SonicWall is affected by vulnerabilities in the following product: Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM) 4.3.0 and earlier versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SonicWall NSM On-Prem Affected By Multiple Vulnerabilities Security Advisory

SonicWall CA

tg: zranitelnost

· Cyber Centre Kanada · SonicWall security advisory (AV26-884)

1

7th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information. Hit, a major Slovenian gambling and tourism…

KEV ✓ EPSS 0.09 CVSS 10.0 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 Thomson Reuters Dropbox SonicWall JFrog IL

tg: přehled tp: malware tp: ransomware tp: únik dat tp: AI

· Check Point Research · 7th September – Threat Intelligence Report

1

Multiples vulnérabilités dans Sonicwall Network Security Manager (04 septembre 2026)

De multiples vulnérabilités ont été découvertes dans Sonicwall Network Security Manager. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.

EPSS 0.02 CVE-2026-78327 CVE-2026-78328 CVE-2026-81939 SonicWall FR

tg: zranitelnost

· CERT-FR – avis · Multiples vulnérabilités dans Sonicwall Network Security Manager (04 septembre 2026)

1

SPOJENO PŘES CVE SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10

Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…

KEV ✓ EPSS 0.09 CVSS 10.0 CVE-2026-83548 CVE-2026-83549 SonicWall FI US CA IT AT FR

tg: zneužíváno tg: zranitelnost

· NCSC-FI · SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10 · Rapid7 · Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild · Cyber Centre Kanada · SonicWall security advisory (AV26-872) · CSIRT Itálie (ACN) · SonicWall: rilevato sfruttamento in rete delle CVE-2026-83548 e CVE-2026-83549 · CERT.at · Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar · CERT-FR – avis · Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)

6

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

KEV ✓ EPSS 0.36 CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 CVE-2026-9586 Sangoma JFrog SonicWall BerriAI veřejná správa US

tg: zneužíváno tg: zranitelnost

· CISA Advisories · CISA Adds Seven Known Exploited Vulnerabilities to Catalog

NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

SonicWall heeft kwetsbaarheden verholpen in de SMA1000 Appliance. De SMA1000 Appliance bevat twee kwetsbaarheden. De eerste is een pre-authenticatie Server-Side Request Forgery (SSRF) in de Work Place interface, waarmee een externe, niet-geauthenticeerde aanvaller ongeautoriseerde acties kan uitvoeren. De tweede kwetsbaarheid betreft post-authenticatie remote code execution, waarbij een aanvaller met geldige inloggegevens willekeurige code op afstand kan uitvoeren. Beide kwetsbaarheden zijn als…

SonicWall NL

tg: zneužíváno tg: zranitelnost

· NCSC-NL · NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

SPOJENO PŘES CVE SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-83548)

CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.

KEV ✓ EPSS 0.05 CVE-2026-83548 SonicWall US FR

tg: zneužíváno tg: zranitelnost

· CISA KEV · SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-83548) · CERT-FR – alerty · Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

1

SonicWall security advisory (AV26-853)

Serial Number: AV26-853Date: August 26, 2026 As of August 25, 2026, SonicWall is affected by vulnerabilities in the following product: NetExtender Linux Client 3.5 and earlier versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory SonicWall Security Advisories

SonicWall CA

· Cyber Centre Kanada · SonicWall security advisory (AV26-853)

1

SPOJENO PŘES CVE Vulnerabilità in prodotti SonicWall

Aggiornamenti di sicurezza SonicWall sanano 2 vulnerabilità con gravità "alta" presenti in SonicWall NetExtender Linux Client. Tali vulnerabilità, qualora sfruttate, potrebbero permettere a un utente malintenzionato di eludere i meccanismi di sicurezza e di manipolare i dati sui dispositivi target.

EPSS 0.00 CVSS 8.8 CVE-2026-66152 CVE-2026-66153 SonicWall IT FI FR

· CSIRT Itálie (ACN) · Vulnerabilità in prodotti SonicWall · NCSC-FI · SonicWall NetExtender Linux Client Multiple Vulnerabilities · CERT-FR – avis · Multiples vulnérabilités dans SonicWall NetExtender (26 août 2026)

1

Metasploit Wrap Up: Lot of summer shells and fit http profiles

This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …

KEV ✓ · ransomware EPSS 0.97 CVE-2025-49132 CVE-2026-15409 CVE-2026-27760 CVE-2026-29053 CVE-2026-3891 CVE-2026-46300 CVE-2026-48907 CVE-2026-60137 CVE-2026-63030 WordPress Ghost CMS SonicWall Linux US

tg: novinka v produktu tg: přehled

· Rapid7 · Metasploit Wrap Up: Lot of summer shells and fit http profiles

3

SonicWall security advisory (AV26-809)

Serial number: AV26-809Date: August 12, 2026 As of August 11, 2026, SonicWall is affected by vulnerabilities in the following products: Email Security 10.0.35.8405 and earlier versions GMS 9.5.1 and earlier versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory Security Advisory (1) Security Advisory (2)

SonicWall CA

· Cyber Centre Kanada · SonicWall security advisory (AV26-809)

Multiples vulnérabilités dans les produits SonicWall (12 août 2026)

De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

EPSS 0.02 CVE-2026-18634 CVE-2026-66145 CVE-2026-66146 CVE-2026-66147 CVE-2026-66148 CVE-2026-66149 CVE-2026-66150 CVE-2026-66154 SonicWall FR

· CERT-FR – avis · Multiples vulnérabilités dans les produits SonicWall (12 août 2026)

3

ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66150.

EPSS 0.00 CVSS 7.8 CVE-2026-66150 SonicWall US

· Zero Day Initiative · ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability

ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66148.

EPSS 0.01 CVSS 7.8 CVE-2026-66148 SonicWall US

· Zero Day Initiative · ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability

ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-66149.

EPSS 0.00 CVSS 7.8 CVE-2026-66149 SonicWall US

· Zero Day Initiative · ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability

1

1

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ · ransomware EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

· Check Point Research · 20th July – Threat Intelligence Report

1

SPOJENO PŘES CVE Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

In early July 2026, Volexity was engaged to perform an incident response investigation where it discovered a threat actor had successfully compromised SonicWall Secure Mobile Access (SMA) VPN appliances through a chain of multiple zero-day exploits in the devices. The initial compromise was discovered after suspect authentication and lateral movement attempts were observed from the SonicWall SMA appliances. Following public disclosure by SonicWall on July 14, 2026, Volexity is now able to share…

KEV ✓ · ransomware EPSS 0.85 CVSS 10.0 CVE-2026-15409 CVE-2026-15410 SonicWall US SE AT

· Volexity · Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation · CERT-SE · Kritiska sårbarheter i SonicWall SMA1000 · CERT.at · Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

1

1

1