Today’s Field Note

Three edge-and-infrastructure bugs are live today, and all three sit in places attackers love. SonicWall is warning that CVE-2026-83548 (CVSS 10.0 pre-auth SSRF) and CVE-2026-83549 chain together for unauthenticated RCE on SMA1000 VPN appliances, exploited as zero-days before the patch shipped. JFrog Artifactory’s CVE-2026-82329 (CVSS 9.8 auth bypass) is being weaponized to mint admin tokens within days of disclosure, per watchTowr, and Langflow’s CVE-2026-0768 is being used to steal OpenAI and AWS keys from AI build environments. None of these are theoretical. If you run a SonicWall VPN, a build artifact repo, or a low-code AI platform exposed to the internet, assume someone is already looking.

Today’s Action

  • Patch SonicWall SMA1000 immediately, then hunt for pre-patch compromise: review appliance logs for anomalous SSRF requests and outbound connections, not just apply-and-move-on.
  • Update JFrog Artifactory to the fixed release and audit for rogue admin tokens or accounts created in the disclosure window; rotate any that look off.
  • Patch Langflow and rotate every credential it could reach: OpenAI, AWS, and any tokens stored in or accessible to that environment.
  • Pull all four instances off direct internet exposure where possible; front them with VPN or IP allowlisting until you have confirmed clean.
  • Check egress logs on these hosts for connections to unfamiliar destinations as your fastest tripwire for prior exploitation.

Resources

Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.

Patch is a verb. Do it before the next incident makes it one for you.

More: Issues · Field Notes · RTFM


Daily field notes, weekly Issues. Follow @itsalreadywhen or subscribe via RSS.