SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs

2026-09-02T20:51:39Z5a5e63906a78935757c51ef82a47aac6b0d9b27deb87e0b58493de2f1914ff3b
CVE-2026-0768CVE-2026-81578APTATM jackpottingAWSAvastCISA KEVDPRK-linkedIran-linkedKasperskyLangflowMirage KittenNodeRabbitPLCPaperCutPollCatSSRFSonicWall SMA 1000VPNactive exploitationhealthcare data breachindustrial control systemsinsider threatprivilege escalationremote code executionzero-day

What happened

Security Affairs reports active exploitation and disclosure of multiple critical vulnerabilities and threats, including SonicWall SMA 1000 zero-days, unauthenticated remote code execution in Langflow (CVE-2026-0768), and actively exploited PaperCut NG/MF flaws added to CISA's KEV catalog. The feed also covers malware delivery by Iran-linked Mirage Kitten, DPRK-linked insider infiltration, cloud data exposure affecting 9.5 million people, privilege-escalation zero-day exploit releases targeting Avast and Kaspersky products, AI-assisted PLC exploitation, and ATM jackpotting.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5a5e63906a78935757c51ef82a47aac6b0d9b27deb87e0b58493de2f1914ff3b
Enrichment time
2026-09-02T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.