SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs
2026-09-02T20:51:39Z•5a5e63906a78935757c51ef82a47aac6b0d9b27deb87e0b58493de2f1914ff3b
CVE-2026-0768CVE-2026-81578APTATM jackpottingAWSAvastCISA KEVDPRK-linkedIran-linkedKasperskyLangflowMirage KittenNodeRabbitPLCPaperCutPollCatSSRFSonicWall SMA 1000VPNactive exploitationhealthcare data breachindustrial control systemsinsider threatprivilege escalationremote code executionzero-day
What happened
Security Affairs reports active exploitation and disclosure of multiple critical vulnerabilities and threats, including SonicWall SMA 1000 zero-days, unauthenticated remote code execution in Langflow (CVE-2026-0768), and actively exploited PaperCut NG/MF flaws added to CISA's KEV catalog. The feed also covers malware delivery by Iran-linked Mirage Kitten, DPRK-linked insider infiltration, cloud data exposure affecting 9.5 million people, privilege-escalation zero-day exploit releases targeting Avast and Kaspersky products, AI-assisted PLC exploitation, and ATM jackpotting.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5a5e63906a78935757c51ef82a47aac6b0d9b27deb87e0b58493de2f1914ff3b
- Enrichment time
- 2026-09-02T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.