{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acrafthemeselegant_addons_for_elementorwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:sonicwall:sma_1000_series:*:*:*:*:*:*:*:*","cpe:2.3:a:sktthemes:skt_addons_for_elementor:*:*:*:*:*:wordpress:*:*","cpe:2.3:a:crafthemes:elegant_addons_for_elementor:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2024-5091"},{"cvss":6.4,"id":"CVE-2024-5092"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SMA 1000 Series"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["SonicWall"],"content_html":"\u003cp\u003eSonicWall has released security updates for its SMA 1000 series appliances to remediate two vulnerabilities currently being exploited by threat actors in the wild. The first vulnerability, CVE-2024-5091, permits an unauthenticated remote attacker to perform unauthorized actions on the affected appliance. The second vulnerability, CVE-2024-5092, can be leveraged by an attacker who has already obtained administrative credentials to execute arbitrary commands at the operating system level. Given the combination of active exploitation and the critical nature of these edge devices, these vulnerabilities represent a high risk to organizations. Defenders should prioritize patching and initiate forensic reviews of administrative access logs and appliance integrity to identify any prior unauthorized access or persistent backdoors established during the exploitation window.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities allows for full system compromise, enabling unauthorized access to sensitive network traffic and lateral movement into the protected internal environment. Organizations relying on SMA 1000 appliances for secure remote access are at immediate risk of data exfiltration and persistent network intrusion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately apply the latest security patches provided by SonicWall to all SMA 1000 series appliances.\u003c/li\u003e\n\u003cli\u003eReview administrative access logs for suspicious sessions or anomalous command execution indicative of exploitation of CVE-2024-5092.\u003c/li\u003e\n\u003cli\u003eConduct an immediate audit of user accounts and privilege assignments to identify potentially compromised credentials used to exploit CVE-2024-5092.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic logs for unexpected outbound connections from the management interface of the SMA appliances.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T11:41:25Z","date_published":"2026-09-02T11:41:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/","summary":"SonicWall has addressed two actively exploited vulnerabilities, CVE-2024-5091 and CVE-2024-5092, in the SMA 1000 series that allow for unauthenticated unauthorized actions and authenticated command execution.","title":"Active Exploitation of SonicWall SMA 1000 Series Appliances","url":"https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:crafthemes:elegant_addons_for_elementor:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}