RE: https://infosec.exchange/@nemokamui/116919449162115047
Perfect 10 in SonicWALL SMA1000! 🥳
sev:CRIT 10.0 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
Edit to add that it's EITW:
IMPORTANT: SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities.