Threat Intelligence

CISA Flags Seven Actively Exploited Vulnerabilities Used to Plant Reverse Shells and Crypto Miners

The Hacker News · 3 Sept 2026
Key Takeaway Check whether your business uses any of the affected products, particularly SonicWall SMA appliances, and apply vendor patches immediately since these flaws are being actively exploited right now.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven newly exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that attackers are actively using them in real-world attacks. Among the flaws is a maximum-severity server-side request forgery vulnerability affecting SonicWall SMA 1000 Series appliances, which could let a remote attacker act without needing valid login credentials.

According to CISA, threat actors have been exploiting these vulnerabilities to install reverse shells - hidden remote-access tools that let attackers control a compromised system from afar - as well as cryptocurrency mining software that quietly hijacks computing resources for financial gain. Government agencies in the US are required to patch KEV-listed flaws by a set deadline, but CISA strongly encourages all organisations, including small and medium businesses, to prioritise fixing these issues given evidence of active exploitation.

For Australian small businesses using SonicWall appliances or other affected products, the risk isn't theoretical: once attackers gain a foothold via a reverse shell, they can pivot deeper into networks, steal data, or use hijacked systems for profit at the business's expense in electricity and performance costs.

Key Takeaway: Check whether your business uses any of the affected products (particularly SonicWall SMA appliances) and apply vendor patches immediately, as these vulnerabilities are being actively exploited right now.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.