CISA adds seven actively exploited flaws to its KEV catalog, including a critical SonicWall SSRF with a perfect CVSS score. Attackers are deploying reverse shells and crypto miners—here's what to do now.
When the Cybersecurity and Infrastructure Security Agency (CISA) adds vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, it's never good news. It means attackers aren't just aware of these flaws—they're actively using them in the wild, right now, against real targets.
This week, CISA flagged seven newly exploited vulnerabilities that demand your immediate attention. The most alarming part? One of them carries a perfect CVSS score of 10.0, which is about as severe as it gets in the cybersecurity world.
### The Big One: SonicWall SMA 1000
Let's start with the headline grabber. CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability found in SonicWall SMA 1000 appliances. With a CVSS score of 10.0, this flaw could allow a remote, unauthenticated attacker to send crafted requests through the appliance, potentially reaching internal systems that should never be exposed to the outside world.
Think of SSRF like this: it's as if someone figured out how to use your office's mailroom to send packages to rooms you never wanted visitors to access. The attacker doesn't need credentials. They don't need to be on your network. They just need to reach the appliance from the internet.
If you're running a SonicWall SMA 1000, this should be your top priority today. Not next week. Today.
### What Else Is on the List?
While the SonicWall flaw grabs headlines, CISA added six other vulnerabilities to the catalog, each with its own story of active exploitation. Attackers aren't just scanning for these weaknesses—they're deploying reverse shells and crypto miners once they get in.
A reverse shell is like handing the attacker a remote control to your system. Instead of them opening a door from the outside, the compromised system reaches out to them, making detection much harder for traditional firewalls.
Crypto miners are a different beast entirely. They quietly hijack your computing power to mine cryptocurrency. You might not notice anything wrong at first—just slightly higher CPU usage, a bit more electricity on the bill. But the real damage is often just a cover for something worse.
### Why the KEV Catalog Matters
Here's the thing about the KEV catalog that many people miss: CISA doesn't add vulnerabilities to this list casually. The agency only includes flaws that have confirmed, documented cases of active exploitation. That's a much higher bar than just "this could be exploited."
When you see a CVE on this list, you know attackers have already figured out how to use it. They've built tools around it. They've tested it against real systems. The playbook is written, and now it's being shared across criminal forums.
### What You Should Do Right Now
If you're responsible for any systems that might be affected, here's your action plan:
- Check your asset inventory against the seven CVEs CISA listed this week
- Apply patches immediately if vendors have released them
- If no patch exists, implement compensating controls like network segmentation or access restrictions
- Review logs for signs of reverse shells or unusual outbound connections
- Monitor CPU usage for spikes that could indicate crypto mining activity
### The Bigger Picture
This announcement is a reminder that the gap between vulnerability disclosure and exploitation is shrinking. Attackers are getting faster, more automated, and more creative. They don't wait for patches. They move the moment a flaw becomes public knowledge.
For security teams, this means the old way of doing things—scan quarterly, patch monthly, hope for the best—just doesn't cut it anymore. You need real-time visibility into your attack surface and a process for responding to threats like these within hours, not weeks.
### Final Thoughts
CISA's KEV catalog is one of the most useful resources for prioritizing your patching efforts. If a vulnerability makes this list, it moves to the top of your queue. No exceptions.
The seven flaws added this week are being actively exploited right now. Somewhere, someone is using them to break into systems, deploy malicious payloads, and cash in on compromised infrastructure. Make sure that someone isn't targeting you.
Stay vigilant, patch quickly, and keep an eye on those outbound connections. Your network's security depends on it.