Skip to content

CVE-2025-40602

CVE

Threat entity extracted from intelligence sources

Frequency
18
occurrences
First Seen
December 17, 2025
Last Seen
September 2, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

SonicWall has released a patch for the actively exploited zero-day vulnerability CVE-2025-40602, which affects the Appliance Management Console (AMC) of their devices. This vulnerability allows for deserialization of untrusted data, posing risks to users of SonicWall products. Organizations are advi...

SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated att...

Google's Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, a rise from 78 in 2024. Less than half of these vulnerabilities were attributed to specific threat actors, with spyware vendors and China being the most prominent. This increase highlights ongoing cybersecurity...

SonicWall has addressed a medium-severity zero-day vulnerability in the SMA1000 Appliance Management Console. This vulnerability is actively being exploited, affecting users of the SonicWall SMA1000. The company has released fixes to mitigate the risk associated with this security flaw.

Public Exploits

Checking GitHub for proof-of-concept code…

Related Articles (18)

1 / 4