CRITICAL 3 min read 11 Aug 2026

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-15409, cve-2026-15410, cwe-918, cve-2026-8037, cve-2026-33691, cwe-77, security-brief, www-bleepingcomputer-com

Key findings
01
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CRITICAL
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...] The assigned identifier is CVE-2026-15409.
02
Critical Progress LoadMaster flaw now actively exploited in attacks
CRITICAL
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. The assigned identifier is CVE-2026-8037.
03
BdThemes plugins supply-chain hack creates rogue WordPress admins
INFO
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators browsers to create rogue admin accounts. [...]
04
Framework loses customer data in Metabase zero-day attack
INFO
Repairable hardware is little comfort when personal details escape
05
Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC
INFO
Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.

Executive assessment

Today's brief leads with CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs. All 5 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

What changed: CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]

Technical evidence: CVE-2026-15409; CVSS v3.1 10; weakness ['CWE-918']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-15409 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-now-exploited-by-ransomware-gangs/>)

Finding 02 — Critical Progress LoadMaster flaw now actively exploited in attacks

What changed: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability.

Technical evidence: CVE-2026-8037; CVSS v3.1 9.6; weakness ['CWE-77']; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Action: Map CVE-2026-8037 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/cisa-warns-of-critical-progress-loadmaster-flaw-exploited-in-attacks/>)

Finding 03 — BdThemes plugins supply-chain hack creates rogue WordPress admins

What changed: A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators browsers to create rogue admin accounts. [...]

Why it matters: The cited reporting affects widely deployed technology, so exposure validation and source verification need explicit ownership.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/>)

Finding 04 — Framework loses customer data in Metabase zero-day attack

What changed: Repairable hardware is little comfort when personal details escape

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.theregister.com](<https://www.theregister.com/personal-tech/2026/08/10/framework-loses-customer-data-in-metabase-zero-day-attack/5285302>)

Finding 05 — Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

What changed: Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition.

Why it matters: Public exploit code is available, so weaponisation is low-effort; prioritise exposure validation and patching ahead of routine cycles.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.securityweek.com](<https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/>)

cve-2026-15409cve-2026-15410cve-2026-33691cve-2026-8037cwe-77cwe-918security-briefwww-bleepingcomputer-com

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.