CISA KEV
CVE-2026-15410: SonicWall SMA1000 administrator code injection
This SMA1000 code-injection flaw requires administrator access to the Appliance Management Console. Apply the current supported hotfix and investigate suspected compromise; the historical minimum build does not establish protection against later vulnerabilities.
CVE-2026-15409: SonicWall SMA1000 unauthenticated WorkPlace SSRF
Unauthenticated requests can make the SMA1000 WorkPlace interface contact unintended destinations. Verify the appliance model and hotfix, update, and conduct the compromise review; SonicWall firewall SSL-VPN and SMA 100 are outside this notice's scope.
CVE-2026-20316: Cisco FMC static credential is exploited and ransomware-linked
A hard-coded FMC password can expose sensitive data through a low-privileged account. Restrict management access, install Cisco's current hardening release, and review indicators; the initial access is not itself root access.
CVE-2026-16812: Arista VeloCloud Orchestrator unauthenticated command injection
Command injection threatens on-premises VeloCloud Orchestrator hosts and their managed data. Restrict exposure, upgrade the orchestrator branch, and examine downstream edge state and trust material when compromise is suspected.
CVE-2026-83549: SonicWall SMA1000 administrator command injection and RCE
SonicWall SMA1000 administrators can exploit command injection through the Appliance Management Console. Apply the supported hotfix and request a support-led compromise review; this is distinct from the separate unauthenticated WorkPlace flaw.
CVE-2026-83548: SonicWall SMA1000 pre-authentication SSRF and proxy bypass
An unintended SMA1000 WorkPlace proxy path can expose sensitive functionality without authentication. Install SonicWall's supported hotfix, preserve exposure history, and obtain a support-led indicator review rather than treating the update as proof of recovery.
CVE-2026-8452: NetScaler memory-bounds flaw can cause denial of service
NetScaler memory-boundary failures can interrupt ADC or Gateway service. Match the appliance edition, configuration and build to the fixed release; this CVE does not establish authentication bypass or code execution.
CVE-2019-1068: SQL Server remote code execution
An authenticated attacker can use a crafted SQL query to execute code as the SQL Server Database Engine service account. Match the service pack and GDR or CU branch; CISA now lists the flaw as exploited.
CVE-2026-65400: macOS Screen Sharing authentication bypass
The macOS Screen Sharing flaw can let a network attacker authenticate without valid credentials. Check service reachability and the installed macOS branch, apply its supported update, and preserve relevant authentication evidence.
CVE-2026-55040: SharePoint authentication bypass
SharePoint's authentication bypass can permit unauthenticated user impersonation. CISA's later exploitation listing differs from Microsoft's original assessment; update every affected on-premises farm server and preserve web, authentication and audit evidence.
