Future TechnologyFuture Technology
Cybersecurity

A CVSS 10.0 SonicWall flaw is being exploited right now

· 3 min read · By Nath Connell

Key takeaways

  • A maximum severity SonicWall vulnerability is under active exploitation and has been added to CISA's Known Exploited Vulnerabilities catalogue.
  • CISA added six actively exploited flaws in the same batch.
  • Edge security appliances are the most attacked class of device on the internet, because they sit outside everything else.
  • If you cannot patch immediately, restrict management access and assume the device may already be touched.

CVSS 10.0 is the top of the scale, and it is rarer than the noise around vulnerability scoring suggests. It means remotely reachable, no authentication required, low complexity, and full compromise on success. A SonicWall flaw now sits there, and it is being used.

CISA added it to the Known Exploited Vulnerabilities catalogue as part of a batch of six actively attacked issues. The KEV listing is the signal worth reacting to. A high CVSS score is a theoretical statement about how bad something could be. A KEV entry is a factual statement that somebody is doing it.

Why edge appliances keep ending up here

Firewalls, VPN concentrators and secure access gateways share an awkward property: they are deliberately exposed to the internet, they terminate encrypted traffic, and they usually sit outside the reach of the endpoint agents and network monitoring that watch everything else. Compromise one and you are inside, authenticated, and largely unobserved.

That is why this class of device has dominated the KEV catalogue for three years running. It is not that the vendors are uniquely careless. It is that the attack surface is small, valuable, and permanently lit up.

What to do today

The order matters more than the list.

  • Patch to the fixed firmware. Vendor advisories for edge kit are usually explicit about the minimum safe build, so match the exact version rather than assuming a recent update covers it.
  • If you cannot patch this week, take the management interface off the public internet. Most compromises of this shape start at an admin portal that never needed to be reachable.
  • Rotate credentials and any VPN certificates or pre-shared keys on affected devices. Assume anything stored on the appliance was readable.
  • Check logs for configuration changes, new local accounts and unexpected VPN sessions going back several weeks, not several days. Exploitation usually predates disclosure.
  • Terminate live sessions after patching. Patching does not evict an attacker who already holds a session token.

The wider pattern

Six KEV additions in one batch is not unusual any more. What is changing is the speed at which proof of concept code turns into broad scanning, and that trend is being pushed along by tooling that writes the exploit for you. The practical consequence is that a monthly patch cycle is no longer a defensible posture for anything with a public IP address.

A workable rule for small teams: internet facing kit gets patched on a separate, faster track from everything else, and the KEV catalogue is what sets that track's queue. It is a free, government maintained list of things that are definitely being attacked. Very few security inputs are that clean.

The quiet detail here is timing. By the time a flaw reaches KEV, the exploitation has already been observed in the wild by somebody. You are not getting ahead of it. You are catching up, and how fast you catch up is the whole game.

Read next

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.