Lead · Vulnerabilities
SonicWall patched on Tuesday. It was being exploited by Friday.
Four internet-facing products are under active exploitation at once, and the only federal remediation deadline in the pile lands today, on a Sunday.
CISA added five flaws to the Known Exploited Vulnerabilities catalogue on Thursday after abuse by the China-linked actor Flax Typhoon, with a remediation deadline for federal agencies of 11 October, which is today, which is a Sunday. In the same window the FBI seized seven web domains linked to Integrity Technology Group, a Chinese security firm accused of supplying the tooling. One of these things is an operation. The other is a date in a spreadsheet.
The rest of the board is worse for anyone with an appliance. CVE-2026-102255, the maximum-severity pre-authentication SSRF in SonicWall SMA1000 Work Place, was patched on Tuesday and reported as exploited in attacks on Friday, three days later: a smoke alarm fitted on Tuesday and tested by a chip pan on Friday. Two AhsayCBS flaws, CVE-2026-105133 and CVE-2026-105134, have been exploited since 7 October with no patch available, dropping webshells and XMRig miners dressed up as Microsoft Edge. Citrix is telling administrators to fix CVE-2026-107406 in NetScaler ADC and Gateway immediately, a memory overflow that can give remote code execution or denial of service in SAML deployments. Cisco Talos is tracking active exploitation of two Secure Firewall Management Center bugs, including the critical authentication bypass CVE-2026-20079.
The reframe is uncomfortable and it is not new. Patching is not the control; the schedule is. If your mean time to apply a vendor advisory on an edge device is measured in change windows, and the attacker's mean time to weaponise it is measured in sleeps, then you are not running a vulnerability management programme, you are running a very slow apology. Find the boxes. Patch or isolate them today. Then go and look for the webshell, because the interesting question this morning is not whether you were vulnerable, it is whether you still are.
Why it mattersInternet-facing SonicWall SMA1000, AhsayCBS, NetScaler and Cisco FMC need an inventory check, a patch or an isolation decision, and a webshell hunt before Monday's standup invents a reason to defer it.
- 1Security newsFlax Typhoon Exploits Five Flaws as CISA Sets Octob…
- 2Security newsUS Disrupts Chinese State-Sponsored Hacking Tools —…
- 3AlienVault OTXUS disrupts Chinese hacking tools as 7 govts warn o…
- 4RSSMax severity SonicWall SMA1000 flaw now exploited i…
- 5Security newsMax severity SonicWall SMA1000 flaw now exploited i…
- 6NVDCVE-2026-102255: A Pre-authentication SSRF vulnerab…