<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners]]></title><description><![CDATA[<p dir="auto">CISA has added seven new flaws to its Known Exploited Vulnerabilities (KEV) catalog this week, following confirmed reports of active exploitation. Among the additions is a critical flaw in SonicWall SMA 1000 appliances, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83548" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-83548</a></strong> with a CVSS score of <strong>10.0</strong>. This vulnerability is a server-side request forgery (SSRF) issue that could allow a remote, unauthenticated attacker to probe internal systems or trigger unintended requests from the affected device.</p>
<p dir="auto">The inclusion in the KEV catalog means Federal Civilian Executive Branch (FCEB) agencies are required to apply patches by the mandated deadline, but the advisory serves as a broader warning for all organizations using affected products. According to the advisory, threat actors have been observed leveraging these flaws to deploy reverse shells and cryptocurrency miners on compromised hosts, indicating a shift from initial access to rapid monetization and persistence.</p>
<ul>
<li><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-83548" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-83548</a></strong> (CVSS: 10.0) – SSRF in SonicWall SMA 1000 appliances, exploitable without authentication.</li>
</ul>
<p dir="auto">The full list includes additional vulnerabilities across various vendors, though technical details for the remaining entries were not fully disclosed in the initial report. CISA urges administrators to review the full KEV entry and prioritize remediation, especially for internet-facing devices. Organizations should also audit their environments for indicators of compromise related to reverse shell traffic or unexpected mining processes, as these post-exploitation activities often leave distinct forensic traces.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your organization currently running SonicWall SMA 1000 appliances, and if so, how are you prioritizing the patching of this SSRF vulnerability against potential operational downtime?</p>
]]></description><link>https://xploitlk.com/topic/232/critical-cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-miners</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:27:29 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/232.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 06 Sep 2026 02:30:20 GMT</pubDate><ttl>60</ttl></channel></rss>