<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:sktthemes:skt_addons_for_elementor:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asktthemesskt_addons_for_elementorwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 11:41:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asktthemesskt_addons_for_elementorwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Active Exploitation of SonicWall SMA 1000 Series Appliances</title><link>https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/</link><pubDate>Wed, 02 Sep 2026 11:41:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-sonicwall-sma-exploitation/</guid><description>SonicWall has addressed two actively exploited vulnerabilities, CVE-2024-5091 and CVE-2024-5092, in the SMA 1000 series that allow for unauthenticated unauthorized actions and authenticated command execution.</description><content:encoded><![CDATA[<p>SonicWall has released security updates for its SMA 1000 series appliances to remediate two vulnerabilities currently being exploited by threat actors in the wild. The first vulnerability, CVE-2024-5091, permits an unauthenticated remote attacker to perform unauthorized actions on the affected appliance. The second vulnerability, CVE-2024-5092, can be leveraged by an attacker who has already obtained administrative credentials to execute arbitrary commands at the operating system level. Given the combination of active exploitation and the critical nature of these edge devices, these vulnerabilities represent a high risk to organizations. Defenders should prioritize patching and initiate forensic reviews of administrative access logs and appliance integrity to identify any prior unauthorized access or persistent backdoors established during the exploitation window.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows for full system compromise, enabling unauthorized access to sensitive network traffic and lateral movement into the protected internal environment. Organizations relying on SMA 1000 appliances for secure remote access are at immediate risk of data exfiltration and persistent network intrusion.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately apply the latest security patches provided by SonicWall to all SMA 1000 series appliances.</li>
<li>Review administrative access logs for suspicious sessions or anomalous command execution indicative of exploitation of CVE-2024-5092.</li>
<li>Conduct an immediate audit of user accounts and privilege assignments to identify potentially compromised credentials used to exploit CVE-2024-5092.</li>
<li>Monitor network traffic logs for unexpected outbound connections from the management interface of the SMA appliances.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>