SonicWall warns of actively exploited SMA1000 zero-day flaws
2026-09-02T07:23:22Z•0a32fbdb70ab476692461355ffd094224edc4733ef068ba4fd722cc164fc92b7
CVE-2026-0768ATM-jackpottingBGP-hijackingCisco-IOS-XRClickFixDeFiLangflowMicrosoft-ExchangePaperCutScreenConnectSonicWall-SMA1000Virtualizoractive-exploitationcredential-theftcryptocurrencydata-breachhealthcarephishingremote-code-executionreverse-tunnelingzero-day
What happened
A BleepingComputer security-news feed reports active exploitation of multiple zero-day and recently patched vulnerabilities, including SonicWall SMA1000 and PaperCut flaws, plus exploitation of CVE-2026-0768 in Langflow to steal cloud and AI credentials. Other incidents include malicious Virtualizor updates delivered through BGP hijacking, phishing abuse of Faronics Deploy to install ScreenConnect, Microsoft Exchange exposure to mailbox-hijacking attacks, ClickFix/TerminalFix social engineering, router compromise, major healthcare data breaches, ATM jackpotting, and a $74 million DeFi exploit.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0a32fbdb70ab476692461355ffd094224edc4733ef068ba4fd722cc164fc92b7
- Enrichment time
- 2026-09-02T07:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.