Posts Tagged ‘edge-device’
Progress LoadMaster CVE-2026-8037: 792 Attacks Logged
Progress LoadMaster CVE-2026-8037, a CVSS 9.6 unauthenticated command-injection flaw, has already been hit with 792 confirmed exploitation attempts from 65 IP addresses over 41 days — and CISA added it to its Known Exploited Vulnerabilities catalog on August 7. If your load balancer is still running an unpatched build, the scanning has almost certainly already…
Read MoreCisco Secure FMC CVE-2026-20316 Exploited
Cisco Secure FMC CVE-2026-20316 is under confirmed active exploitation: a hardcoded, low-privilege account built into every on-premises Secure Firewall Management Center gives an unauthenticated attacker a foothold — and in the same advisory cycle, Cisco quietly reactivated a five-month-old, maximum-severity root-level bypass in the same product, sharing an identical indicator of compromise. CISA added the…
Read MoreArista VeloCloud Orchestrator CVE-2026-16812 Exploited
Arista VeloCloud Orchestrator CVE-2026-16812 is a maximum-severity, unauthenticated command injection flaw under active exploitation right now, and it hands an attacker control of an entire SD-WAN fabric from a single unpatched management console. CISA added it to the Known Exploited Vulnerabilities catalog on July 27, with a federal patch deadline of July 30. If your…
Read MoreSonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17
SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…
Read MoreOPNsense CVE-2026-57155: Root RCE via GeoIP Alias
OPNsense CVE-2026-57155 (CVSS 9.9) is a path-traversal flaw in the firewall’s GeoIP alias importer that lets a low-privileged user escalate to full root remote code execution. It is the fifth critical or high-severity OPNsense vulnerability disclosed since May 2026, and it matters disproportionately for German Mittelstand IT teams and MSPs because OPNsense’s free, open-source model…
Read More
