View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands — The Hacker News
    SonicWall warns of active exploitation targeting SMA 1000 series appliances via two zero-days, including CVE-2026-15409 (CVSS 10.0), a critical SSRF vulnerability enabling remote unauthenticated attackers to execute arbitrary commands. Immediate patching or mitigation is critical to prevent full system compromise.

🔓 VULNERABILITIES & CVEs

  • <https://cve.threatint.eu/CVE/CVE-2026-12512?utm_campaign=info&utm_medium=rss&utm_source=website%7CQuotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter> — CVE ThreatInt
    The Quotes Llama WordPress plugin prior to 3.1.6 suffers from an unauthenticated SQL injection vulnerability allowing UNION-based attacks through an unsanitized sc parameter. Exploitation could lead to data leakage or database compromise. Upgrade recommended.

  • <https://cve.threatint.eu/CVE/CVE-2026-12281?utm_campaign=info&utm_medium=rss&utm_source=website%7CShibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing> — CVE ThreatInt
    Shibboleth WordPress plugin versions before 2.5.4 improperly trust HTTP identity headers without anti-spoofing keys, enabling attackers to create admin accounts without authentication. Patch to 2.5.4 or later to close this critical privilege escalation vector.

  • <https://cve.threatint.eu/CVE/CVE-2026-11580?utm_campaign=info&utm_medium=rss&utm_source=website%7CKali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDO> — CVE ThreatInt
    Kali Forms plugin before 2.4.17 lacks per-object capability checks on post duplication AJAX actions, allowing users with Contributor+ roles to access sensitive post metadata. Update to 2.4.17 to enforce proper authorization.

  • <https://cve.threatint.eu/CVE/CVE-2026-11579?utm_campaign=info&utm_medium=rss&utm_source=website%7CKali Forms < 2.4.17 - Unauthenticated Media Upload> — CVE ThreatInt
    An unauthenticated file upload vulnerability exists in Kali Forms before 2.4.17 due to missing validation that uploads correspond to configured forms with file-upload fields. This could lead to arbitrary file upload and potential remote code execution. Immediate patching advised.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check