Sploitus
Critical SSRF and UAF Vulnerabilities Discovered in SonicWall and Linux Kernel
Article Content
Two critical vulnerabilities have been reported on September 7, 2026. CVE-2026-15409 is a critical Server-Side Request Forgery (SSRF) vulnerability in SonicWall SMA1000 series devices, allowing remote attackers to execute unintended HTTP requests. This vulnerability has been actively exploited since its disclosure on July 14, 2026. CVE-2026-23111 is a high-severity Use-After-Free (UAF) vulnerability in the Linux kernel's netfilter/nf_tables, potentially allowing local attackers to escalate privileges. The UAF vulnerability was published on February 13, 2026, with a proof-of-concept released on June 9, 2026. Both vulnerabilities pose significant risks to affected systems and require immediate attention from security professionals.
Key Points: • CVE-2026-15409 allows remote exploitation on SonicWall SMA1000 devices. • CVE-2026-23111 presents a local privilege escalation risk in the Linux kernel. • Both vulnerabilities are critical and require immediate remediation efforts.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.