SonicWall confirmed both SMA1000 flaws were exploited before disclosure, and CISA gave federal agencies three days to remediate. The lower-scored console bug is the step that reaches the operating system.
Reality
- Evidence55
- Adoption60
- Hype gap+8
- Incentives35
- Confidence48
Three published exposure counts for the September 2026 SonicWall SMA1000 chain measure three different objects: identifiable banners, text mentions, and observed instances.
Reality
- Evidence45
- Adoption25
- Hype gap−10
- Incentives65
- Confidence45
Sixteen new modules landed in the framework, ten of them exploits, and Rapid7 counts five of those against CISA's exploited list. The SonicWall entry runs September's zero-day chain from SSRF to root.
Reality
- Evidence64
- Adoption55
- Hype gap+12
- Incentives74
- Confidence62
Hunt.io crawled the operator's own open directory and found the campaign output: 250 SonicWall SMA1000 appliances scanned, 168 leaking LDAP credentials, five Active Directory databases replicated in full.
Reality
- Evidence58
- Adoption80
- Hype gap−8
- Incentives55
- Confidence62
Rapid7's latest wrap-up ships working exploit code for seven separately documented flaws, including an unauthenticated Joomla web shell and a Linux kernel LPE. Reprioritize this week, not next cycle.
Reality
- Evidence74
- Adoption52
- Hype gap+22
- Incentives71
- Confidence63