← All briefings

SonicWall SMA1000 Appliances · Kestra OSS · JFrog Artifactory

Date: 2026-09-03 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

SonicWall SMA1000 vulnerabilities CVE-2026-83548 and CVE-2026-83549 are being actively exploited and can be chained to achieve unauthenticated remote code execution. CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog, including critical risks in Kestra, LiteLLM, JFrog Artifactory, Sangoma Switchvox and Starlette. Immediate exposure assessment and emergency patching are recommended for internet-facing appliances and development platforms.

Critical Vulnerabilities

CVE-2026-83548 — SonicWall SMA1000 Appliances

  • Severity: CVSS 10.0
  • EPSS: Not available
  • Technical detail: A server-side request forgery vulnerability in the SMA1000 Workplace interface allows a remote unauthenticated attacker to access sensitive functionality and perform unauthorized operations. Available reporting indicates that it can be chained with CVE-2026-83549 to achieve unauthenticated remote code execution.
  • Exploitation status: Actively exploited in the wild; listed in CISA KEV.
  • Remediation: Apply SonicWall’s fixed release immediately. Remove internet exposure where possible, restrict administrative access, review appliance authentication and configuration events, and investigate suspicious outbound connections or system changes.

CVE-2026-83549 — SonicWall SMA1000 Appliances

  • Severity: CVSS 7.8
  • EPSS: Not available
  • Technical detail: An OS command-injection vulnerability permits a remote authenticated administrator to execute arbitrary operating-system commands. In combination with the pre-authentication SSRF in CVE-2026-83548, attackers may reach code execution without valid credentials.
  • Exploitation status: Actively exploited in the wild; listed in CISA KEV.
  • Remediation: Patch immediately and treat exposed appliances as potentially compromised. Review administrator logins, command execution, process creation, persistence, configuration modifications and outbound network activity; rotate credentials and rebuild appliances if compromise indicators are found.

CVE-2026-49869 — Kestra OSS

  • Severity: Not provided
  • EPSS: Not available
  • Technical detail: An unauthenticated remote attacker can create and execute arbitrary workflows through OS command injection. The flaw is especially significant where the Kestra interface is reachable from untrusted networks or workflows execute with access to cloud credentials, source code or internal services.
  • Exploitation status: Actively exploited; added to CISA KEV with a remediation deadline of 2026-09-05.
  • Remediation: Upgrade to the vendor-fixed version before the deadline. Restrict the Kestra API and dashboard, review newly created or modified workflows, inspect command execution and service-account use, and rotate secrets accessible to Kestra.

CVE-2026-82329 — JFrog Artifactory

  • Severity: Not provided
  • EPSS: Not available
  • Technical detail: Under default configuration, an unauthenticated attacker with network access can exploit improper authentication to obtain administrative privileges. Compromise could enable artifact manipulation, credential access, malicious package distribution and further supply-chain attacks.
  • Exploitation status: Actively exploited; added to CISA KEV with a remediation deadline of 2026-09-05.
  • Remediation: Patch immediately and verify that default or weak authentication settings are not present. Audit administrator-token creation and use, repository and artifact changes, anonymous access, build integrations and unusual downloads; revoke exposed tokens and credentials.

CVE-2026-9586 — Sangoma Switchvox

  • Severity: Not provided
  • EPSS: Not available
  • Technical detail: An unauthenticated remote attacker can submit a crafted request to execute arbitrary SQL statements against the backend PostgreSQL database. The reported impact includes database manipulation and potential remote code execution, making internet-exposed telephony systems a priority.
  • Exploitation status: Actively exploited; added to CISA KEV with a remediation deadline of 2026-09-05.
  • Remediation: Apply Sangoma’s update urgently and restrict management interfaces to trusted networks. Review database queries, administrative changes, newly created accounts, call-system modifications and unexpected processes; assume stored credentials may require rotation after exposure.

ONGOING:

  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and inspect for web shells.
  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): Actively exploited; verify patching and management-interface restrictions.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF): Chained exploitation remains reported; patch before the 2026-09-14 KEV deadline.
  • CVE-2026-60004 (Gitea): KEV remediation deadline passed; patch and inspect Git hook directories.
  • CVE-2023-49105 (ownCloud), CVE-2026-19478 (GitLab), CVE-2019-1068 (Microsoft SQL Server), CVE-2026-53362 (Linux Kernel): Active or KEV-listed remediation remains required.

European Advisories

  • WID-SEC-2026-3135 (SonicWall SMA1000): covered in Critical Vulnerabilities. BSI reports active exploitation of the two SMA vulnerabilities.
  • WID-SEC-2026-3093 (JFrog Artifactory): covered in Critical Vulnerabilities. CERT-Bund updated its critical advisory concerning unauthenticated acquisition of administrator privileges.
  • CERT-Bund published new high-severity advisories for GitHub Enterprise Server, Coolify, Jolokia, Kibana, Google Chrome, Mozilla Firefox/Thunderbird, Elasticsearch, ArubaOS-CX and Proxmox VE. Prioritize internet-facing GitHub Enterprise Server, Coolify, Kibana and Proxmox management interfaces; apply vendor updates.
  • CERT-Bund also updated advisories for Microsoft products, Go, Linux Kernel, FreeRDP, Red Hat Apicurio Registry and Snipe-IT. Review these against asset inventories and existing maintenance plans.

Active Threats and Campaigns

  • SonicWall SMA1000 exploitation — NEW STATUS: BSI and Rapid7 report active exploitation of CVE-2026-83548 and CVE-2026-83549, including a chain to unauthenticated RCE. Hunt for suspicious administrator activity, command execution, persistence and outbound connections from appliances.
  • Langflow exploitation — ONGOING: Attackers reportedly continue using CVE-2026-0768 to steal OpenAI and AWS credentials. Revoke exposed keys and review flow-execution and secret-access logs.
  • Virtualizor malicious update campaign — ONGOING: BGP hijacking and malicious update redirection remain reported. Validate installed packages against trusted hashes and investigate VPS management hosts.
  • Faronics Deploy / ScreenConnect abuse — ONGOING: Phishing actors continue abusing remote-management tooling. Hunt for unexpected Deploy activity, ScreenConnect services and remote administrative sessions.

Security News and Context

  1. Patch or isolate SonicWall SMA1000 appliances immediately; begin compromise assessment.
  2. Remediate Kestra, JFrog Artifactory and Sangoma Switchvox before the 2026-09-05 KEV deadline.
  3. Audit KEV-listed LiteLLM and Starlette deployments and apply fixes.
  4. Rotate credentials and tokens accessible to compromised or exposed management platforms.
  5. Hunt for Artifactory token issuance, Kestra workflow execution, Switchvox SQL activity and SonicWall process creation.
  6. Prioritize new CERT-Bund advisories for GitHub Enterprise Server, Coolify, Kibana, Proxmox VE and browser platforms.
  7. Continue remediation of previously reported items: CVE-2026-63520, CVE-2026-8452, CVE-2026-81578, CVE-2026-82078, CVE-2026-60004, CVE-2023-49105, CVE-2026-19478, CVE-2019-1068 and CVE-2026-53362.