CISA KEV: Critical SonicWall & Cisco Vulnerabilities Under Active Exploitation
BreachModal analyzes active exploitation of critical SonicWall SMA 1000 and Cisco vulnerabilities in CISA KEV Catalog. Understand the threats, PoC, and urgent mitigations.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an unequivocal directive: critical SonicWall and Cisco vulnerabilities, now enshrined in its Known Exploited Vulnerabilities (KEV) Catalog, are under active, aggressive exploitation by sophisticated threat actors. This is not a theoretical risk; it is an ongoing compromise of network perimeters globally, demanding immediate, decisive remediation. The KEV Catalog listing confirms that these flaws are being leveraged in the wild, posing an existential threat to federal agencies and any organization deploying these widely used network-edge devices. The evidence trail points to a calculated assault on the digital boundaries of enterprises and governments alike. CISA has explicitly listed CVE-2026-83548, CVE-2026-83549, CVE-2026-15409, CVE-2024-40766 for SonicWall products, and CVE-2026-20349, CVE-2026-20127, CVE-2026-20128, CVE-2026-20122, CVE-2026-20133, CVE-2026-20245, CVE-2025-20333, and CVE-2025-20362 for Cisco products, all validated by real-world compromise. Each entry in the KEV catalog is a direct signal of confirmed malicious use, often by state-sponsored groups or financially motivated ransomware collectives. Organizations failing to address these promptly are actively choosing to operate with known, open backdoors. This negligence is a strategic liability. Note what this means: the very devices designed to be your first line of defense—VPNs and firewalls—are now your most critical points of failure. The active exploitation of these vulnerabilities undermines the fundamental trust in perimeter security, forcing a re-evaluation of every network's architectural assumptions. This isn't merely about patching; it's about understanding that the traditional castle-and-moat model is under siege, and adversaries are already inside the outer walls. The cost of inaction will be measured in exfiltrated data, ransomed systems, and irreparable reputational damage. [Visual Graphic 1] ## SonicWall's Perimeter Under Siege: Exploited VPN and Firewall Zero-Days Threat actors have relentlessly targeted SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances and Gen 7 firewalls. The active exploitation underscores a clear shift towards abusing trusted network infrastructure for initial access. The most critical chain involves two zero-day vulnerabilities in the SMA1000 Appliance WorkPlace interface: CVE-2026-83548 and CVE-2026-83549. CVE-2026-83548, a pre-authentication Server-Side Request Forgery (SSRF) with a CVSS score of 10.0, allows remote, unauthenticated attackers to bypass access controls, associated with CWE-918 and CWE-441. Chained with CVE-2026-83549, a post-authentication operating system command injection (OS Command Injection) in the Appliance Management Console (AMC) with a CVSS score of 7.8 (CWE-78), this combination enables unauthenticated remote code execution (RCE). The affected versions include SMA 1000 models 6210, 7210, and 8200v in versions 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older. Organizations that have not upgraded to the latest hotfix versions (12.4.3-03526 and 12.5.0-02952) are running demonstrably vulnerable systems, a decision that places their entire network at extreme risk. > ⚠️ BreachModal Insight: The chaining of pre-authentication SSRF with post-authentication RCE is a classic, devastating pattern, bypassing both network and authentication layers to achieve full system compromise. CISA has mandated a remediation deadline of September 5, 2026, for federal civilian executive branch agencies, requiring not just patching but forensic triage for any exposed devices. If you were the CISO here, you would be reviewing your logs for indicators of compromise (IoCs) related to unexpected connections to the AMC, anomalous user logins, or outbound connections from the SMA appliance, specifically looking for evidence of MITRE ATT&CK technique T1190 (Exploitation for Client Execution) or T1210 (Exploitation of Remote Services). Further actively exploited SonicWall SMA 1000 vulnerabilities include CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2). These allowed unauthenticated remote attackers to establish WebSocket tunnels to restricted services and escalate privileges to root. These were exploited as zero-days since at least June 22, 2026, and added to CISA's KEV catalog on July 14, 2026. Cybersecurity firm Volexity attributed the exploitation of these flaws to UTA0533, a threat actor observed harvesting credentials and deploying KNUCKLEBALL malware. The INC Ransomware group has also been identified actively exploiting these vulnerabilities, with multiple new victims appearing on their Data Leak Site (DLS) shortly after initial compromise. Organizations running these unpatched versions effectively provide a root shell to these actors. SonicWall Gen 7 firewalls are also under active attack, specifically targeting CVE-2024-40766, an improper access control vulnerability already in CISA's KEV catalog. This flaw has been leveraged by ransomware groups including Akira and Fog ransomware operators, who exploit these weaknesses to rapidly establish persistence and deploy ransomware. The advice from SonicWall is clear: upgrade to SonicOS 7.3 for enhanced protections, reset local user credentials, and enforce Multi-Factor Authentication (MFA) rigorously. The irony is that MFA is often deployed to protect against stolen credentials, but here, it's a critical layer against an attacker who might bypass the initial authentication entirely. Failure to implement these patches and security hygiene measures transforms a perimeter device into a direct conduit for ransomware operations. [Visual Graphic 2] ## Cisco's Network Fabric Compromised: SD-WAN and Firewall Vulnerabilities Cisco, a cornerstone of enterprise networking, has also seen several critical vulnerabilities added to the CISA KEV Catalog, impacting its Secure Firewall ASA and FTD, and Catalyst SD-WAN products. This broad targeting indicates a strategic focus by adversaries on core network infrastructure. A heap inspection vulnerability, CVE-2026-20349, affecting Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD), was added to the CISA KEV Catalog on August 11, 2026, due to active exploitation. This type of vulnerability can often lead to denial-of-service or remote code execution, making it a prime target for disruption or compromise. > 🧩 Tactical Note: Heap inspection vulnerabilities are notoriously difficult to detect without specialized tools and deep memory analysis, often only becoming apparent after a crash or successful exploit. The focus on Cisco Catalyst SD-WAN is particularly alarming, given its role in modern distributed network architectures. CISA has listed multiple vulnerabilities: CVE-2026-20127, an authentication bypass; CVE-2026-20128, allowing access to unsecured password files; CVE-2026-20122, an API flaw enabling file overwrites with read-only access; CVE-2026-20133, permitting unauthorized viewing of sensitive information due to poor access restrictions; and CVE-2026-20245 (CVSS 7.8), an improper encoding vulnerability in Cisco Catalyst SD-WAN Manager allowing authenticated, local attackers to execute arbitrary commands as root. Cisco's cyber threat intelligence unit has dubbed the actor exploiting these as UAT-8616, a
Want this expertise working for your team?
Schedule a 30-minute call and we'll walk through your specific security posture.
Book a consultation