CVE-2025-40602 is a vulnerability tracked across 6 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed December 17, 2025; most recent activity March 6, 2026.
SonicWall has released a patch for the actively exploited zero-day vulnerability CVE-2025-40602, which affects the Appliance Management Console (AMC) of their devices. This vulnerability allows for deserialization of…
Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors…
SonicWall has addressed a medium-severity zero-day vulnerability in the SMA1000 Appliance Management Console. This vulnerability is actively being exploited, affecting users of the SonicWall SMA1000. The company has…
Cisco disclosed a state-espionage campaign targeting its Adaptive Security Appliances (ASA), which are used for firewall and VPN functions. Attackers exploited two zero-day vulnerabilities to infiltrate government…
SonicWall has alerted customers to a local privilege escalation vulnerability (CVE-2025-40602) in the SMA1000 Appliance Management Console, which has been exploited in the wild in conjunction with another vulnerability…
A critical privilege escalation vulnerability, CVE-2025-40602, has been discovered in SonicWall's SMA1000 appliance, allowing attackers to gain unauthorized administrative access. The flaw affects the appliance…