FORTBRIDGE can help assess exposure and respond to SonicWall SMA 1000 VPN appliances under active attack with two zero-days including a maximum-severity 10.0 SSRF flaw.
Public source
Publisher name
Public post
SonicWall SMA 1000 VPN appliances are under active attack. Two zero-days, including a maximum-severity 10.0 SSRF flaw, are being chained for remote code execution on edg…
Company
FORTBRIDGE
FORTBRIDGE – Leading IT Security Services in London | Cybersecurity, Penetration Testing, Red Teaming and Cloud Security
- Industry
- Computer and Network Security
- Location
- London, GB
- Company size
- 2–10 employees
About FORTBRIDGE
Every engagement led by consultants with 10-20 years of offensive security experience. No juniors. No outsourcing. No bait-and-switch. FORTBRIDGE is a CREST and DESC accredited penetration testing firm based in London, UK. We specialise in identifying and mitigating vulnerabilities across web applications, APIs, mobile apps, cloud environments, and AI/LLM systems. What sets us apart: every assessment is executed start-to-finish by senior consultants holding elite certifications (OSCP, OSWE, CRTO, CRTL, AWS/Azure/GCP). You communicate directly with the tester - no account managers, no go-betweens. Our research has been featured in The Guardian, Market Watch, The Register, and more. Our Services Include: ➤ Web Application Penetration Testing ➤ Mobile & API Penetration Testing ➤ Cloud Security Assessment ➤ Red Teaming ➤ Network Penetration Testing ➤ Security Architecture Review ➤ Phishing Simulations ➤ LLM Security Testing ➤ White Box Penetration Testing As a family-run business, security is in our blood. We work with organisations from startups to FTSE 100 companies. For more information, contact FORTBRIDGE today.
See moreLatest activity
Latest activity from FORTBRIDGE
3 signals
Products & Services
FORTBRIDGE patched the vulnerability in Next.js 15.5.24 and 16.3.3 to address the path traversal vulnerability on Windows hosts.
Products & Services
FORTBRIDGE identified and reported a vulnerability CVE-2026-18963 affecting Keycloak 26.0.0 through 26.7.1, which allows unauthenticated account takeover via the Forgot password flow without requiring email access or user interaction.
Discover more
Similar signals
Similar public activity from other companies.
Products & Services
Fortinet
Fortinet noted SonicWall confirmed active exploitation of a pre-auth SSRF and post-auth RCE affecting listed 12.4.3 and 12.5.0 builds.
Products & Services
Factory Internet
Factory Internet published a security advisory for SonicWall SMA1000 appliances with vulnerabilities CVE-2026-83548 and CVE-2026-83549, which can be chained to achieve unauthenticated remote code execution.
Products & Services
Smarttech247
Smarttech247 reports that two new SonicWall SMA1000 vulnerabilities are being chained together to give unauthenticated attackers root access on the appliance.
Products & Services
Rapid7
Rapid7 disclosed 2 vulnerabilities affecting SonicWall SMA1000 appliances on September 1, 2026, confirmed to be actively exploited in the wild.
Products & Services
Pentest-Tools.com