Sep 2: SonicWall Zero-Days, Langflow Theft, Sality Down
SonicWall SMA1000 zero-days exploited. Langflow CVE-2026-0768 drains cloud credentials. Nutex Health SEC disclosure. DOJ takes down Sality botnet.
- SonicWall confirms two SMA1000 zero-days under active exploitation. CVE-2026-83548 (SSRF) and CVE-2026-83549 (command injection) chain for unauthenticated RCE on enterprise VPN hardware.
- Langflow CVE-2026-0768 (CVSS 9.8): attackers hitting exposed instances for OpenAI API keys and AWS credentials. No authentication required.
- JFrog Artifactory CVE-2026-82329: active exploitation continues. Authentication bypass, admin access, no credentials needed.
- Nutex Health files SEC 8-K: ransomware group accessed patient, employee, provider, and financial data. August 2026 incident.
- DOJ and international partners dismantle Sality P2P botnet. Infrastructure seized. Long-running Windows malware operation offline.
Two SonicWall zero-days confirmed exploited. A ransomware group hit a healthcare operator and triggered an SEC filing. A long-running P2P botnet is offline. This is September 2.
SonicWall SMA1000: Chained Zero-Days, Unauthenticated RCE
CVE-2026-83548 and CVE-2026-83549 are under active exploitation. SonicWall confirmed the activity on September 1. CVE-2026-83548 is a pre-authentication SSRF in the SMA1000 Workplace interface. CVE-2026-83549 is an OS command injection in the Appliance Management Console, CVSS 7.8. Chained, they deliver unauthenticated remote code execution on enterprise SSL VPN hardware. Confidence: confirmed by vendor. Threat actor attribution: none established publicly as of this briefing.
SMA1000 has been a sustained target throughout 2026. Two confirmed exploitation waves preceded this one.
Developer and AI Tooling Under Fire
Langflow CVE-2026-0768 (CVSS 9.8) is actively exploited. Attackers are targeting exposed instances to extract OpenAI API keys, AWS access tokens, and other stored cloud credentials. No authentication required. Confidence: confirmed per BleepingComputer and SecurityWeek.
The credential theft is the objective. Langflow instances aggregate keys from multiple services in one place. A single unauthenticated hit drains all of them.
JFrog Artifactory CVE-2026-82329 remains under active attack. The authentication bypass grants admin-level access on unpatched instances without credentials. Patch released August 28; exploitation confirmed within days of disclosure.
Ransomware and Healthcare
Nutex Health filed an SEC 8-K. A ransomware group breached the Houston-based emergency hospital operator, accessing patient, employee, provider, and financial data. Incident occurred in August 2026. Threat actor: unconfirmed by name in public reporting. Data volume: undisclosed. HHS OCR breach notification not confirmed as of this briefing.
McKesson’s ShinyHunters extortion deadline remains active. 284 million records claimed. Record count unverified.
Law Enforcement: Sality Botnet Dismantled
The DOJ and international partners seized Sality botnet infrastructure on September 2. Sality is a long-running Windows malware family that maintained a peer-to-peer relay network for command-and-control. Law enforcement poisoned the P2P relay nodes to cut off payload delivery and C2 traffic, then seized the infrastructure. Infected endpoints remain in the wild. Cleanup of those systems is ongoing. Confidence: confirmed, DOJ announcement.
Also Noted
- Switchvox: active exploitation of a critical unauthenticated RCE in Sangoma’s enterprise VoIP platform. Attackers deploying reverse shells. CVE identifier not disclosed in public reporting as of this briefing.
- GeoNetwork: two vulnerabilities chained for unauthenticated RCE on open-source geospatial software used across government agency backends.
- PaperCut: data theft attacks continue. CISA added CVE-2026-82078 and CVE-2026-81578 to KEV on August 31. Active intrusions confirmed.
- Philippines nuclear agency: attackers exploited unpatched ownCloud vulnerabilities to access reactor databases, personnel records, and credential stores.
- SecurityWeek — SonicWall SMA1000 zero-days exploited
- BleepingComputer — Langflow CVE-2026-0768 credential theft
- SecurityWeek — JFrog Artifactory CVE-2026-82329 exploited
- SecurityWeek — Nutex Health ransomware breach
- The Hacker News — Sality botnet takedown
- BleepingComputer — Sality botnet infrastructure dismantled
- The Hacker News — Switchvox unauthenticated RCE exploited
- The Hacker News — GeoNetwork RCE chain, government backends