Posts Tagged ‘vpn’
WatchGuard Firebox Ransomware Exploitation
WatchGuard Firebox ransomware exploitation is now officially confirmed. CISA updated its Known Exploited Vulnerabilities catalog entry for CVE-2025-14733 on September 10, 2026, to reflect that ransomware gangs, not just opportunistic access brokers, are actively weaponizing a firewall flaw that has had a public patch available since December 2025. What Happened CVE-2025-14733 is an out-of-bounds write…
Read MoreCheck Point VPN Certificate Vulnerability: Patch Now
Check Point disclosed a Check Point VPN certificate vulnerability pair, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8, on September 9, and the Dutch National Cyber Security Centre has since warned that large-scale exploitation is likely imminent, even though Check Point itself has not yet observed attacks in the wild. Both flaws allow unauthenticated remote code execution…
Read MoreSonicWall SMA1000 RCE Vulnerability: Patch Now
A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…
Read MoreWindows IKE RCE: Patched in April, Exploited Now
CVE-2026-33824 Windows IKE RCE has gone from a quietly patched bug in April to an actively exploited flaw four months later: CISA added it to its Known Exploited Vulnerabilities catalog on August 18, 2026, giving U.S. federal agencies until August 21 to patch — while Microsoft’s own advisory still lists it as not exploited. What…
Read MoreSonicWall SMA1000 CVE-2026-15409 RCE: Patch by July 17
SonicWall confirmed that the SonicWall SMA1000 CVE-2026-15409 RCE chain is being actively exploited: an unauthenticated attacker can force a target appliance into arbitrary requests, then pivot to full administrator-level command execution — no valid login required at any point. CISA added both flaws to its Known Exploited Vulnerabilities catalog, with a federal remediation deadline of…
Read More
