A perfect CVSS 10.0 in a widely deployed SSL VPN gateway, an FBI alert about attackers locking defenders out of their own FortiGate infrastructure, and an Atlassian Data Center flaw exploited two hours after a proof-of-concept went public. Three separate stories, one shared lesson: the window between disclosure and exploitation is now measured in hours, and the window for remediation is shrinking faster than most patching cycles can keep up.

In the News

SonicWall SMA1000 Pre-Auth SSRF Scores a Perfect CVSS 10.0

SonicWall disclosed a maximum-severity server-side request forgery vulnerability in its SMA1000 series SSL VPN gateways. The flaw is pre-authentication - an external attacker can craft requests that reach internal appliance functions without any credentials. The CVSS score is 10.0, the highest possible rating.

Hotfixes are available now, but SonicWall has not yet received a CVE assignment. That creates an operational gap: automated vulnerability scanners that key on CVE IDs will not flag this flaw until an ID is issued. Organizations running SMA1000 gateways need to verify hotfix deployment manually or through asset inventory tools that can match firmware versions against the SonicWall advisory.

Pre-auth vulnerabilities in SSL VPN gateways are among the most reliably exploited vulnerability classes in enterprise networks. SonicWall SMA appliances have been targeted repeatedly - the SMA100 series saw active exploitation chains in 2021 and 2023. Any SMA1000 exposed to the internet is a priority-zero patching target.

What defenders should do: Apply the SonicWall hotfix immediately. Do not wait for the CVE assignment. Verify deployment through firmware version checks, not scanner output. Monitor SMA1000 access logs for anomalous internal function calls that could indicate exploitation attempts.

FBI: FortiBleed Attackers Locking Out FortiGate VPN Admins After Harvesting 86K Credentials

A joint FBI and U.S. Secret Service alert warns that threat actors exploiting the FortiBleed vulnerability chain have moved well beyond initial access. Attackers have harvested over 86,000 FortiGate VPN credentials, and in ongoing incidents they are creating rogue administrator accounts while deleting legitimate admin credentials - effectively locking defenders out of their own infrastructure to prevent remediation.

This is not a theoretical post-exploitation scenario. The FBI alert describes active campaigns where organizations discover the compromise only after losing administrative access. The technique is operationally devastating: even if defenders identify the intrusion, they cannot remediate through the management plane because their accounts no longer exist.

The 86,000-credential figure represents the scale of harvested credentials across the campaign, not a single organization. But the lockout technique means that any FortiGate VPN environment with compromised credentials faces a dual problem - the initial breach and the loss of administrative control.

What defenders should do: Audit every FortiGate VPN admin account today. Verify that no unfamiliar accounts exist. Rotate all admin credentials. Enable phishing-resistant MFA on all management access. If rogue accounts are found, treat the appliance as compromised and initiate incident response - do not assume that deleting the rogue account resolves the situation. The attacker had administrative access and may have modified configurations, installed persistence, or exfiltrated additional credentials.

Atlassian Data Center CVE-2026-21589 Exploited Within 2 Hours of Public PoC

CVE-2026-21589 is a CVSS 9.3 arbitrary file access vulnerability affecting Atlassian Data Center products - Jira, Confluence, Bitbucket, and five additional products in the Data Center suite. The vulnerability requires no authentication. An attacker can read arbitrary files from the server without logging in.

Within two hours of a public proof-of-concept release, exploitation was confirmed in the wild. Two hours. That is the current operational reality for critical on-premises software vulnerabilities: the gap between “PoC available” and “actively exploited” has collapsed to the length of a lunch break.

Arbitrary file access on a Confluence or Bitbucket server is not just a confidentiality issue. These systems store source code, internal documentation, API keys, database connection strings, and authentication tokens. A single unauthenticated read of the right file can cascade into full environment compromise.

What defenders should do: Patch all Atlassian Data Center products immediately. If patching requires a maintenance window that cannot be scheduled within 24 hours, deploy web application firewall rules to block the exploitation pattern as a compensating control. Audit access logs for unauthenticated file-read requests that predate your patch deployment - the two-hour exploitation window means some environments were compromised before most teams saw the advisory.

Talos: UAT-11985 Uses AI-Generated Lures and Real-Time AitM to Bypass MFA

Cisco Talos published research on UAT-11985, a threat actor targeting Taiwanese research organizations with a novel combination of techniques. The campaign uses AI-generated event invitation lures delivered via email, QR codes that redirect to adversary-in-the-middle proxy infrastructure, and a hybrid HTTP/WebSocket relay that intercepts authentication sessions in real time - capturing session tokens after the victim successfully completes MFA.

The Talos analysis documents how the AitM proxy sits between the victim and the legitimate authentication provider. The user sees a real login page, enters real credentials, completes real MFA, and receives a real session. But the proxy captures the session token during the relay, giving the attacker a fully authenticated session without ever needing the second factor.

This is the operational proof that MFA alone does not stop adversary-in-the-middle attacks. Phishing-resistant MFA (FIDO2/WebAuthn) resists this technique because the cryptographic challenge is bound to the legitimate domain - the proxy cannot relay it. But push-based and OTP-based MFA methods remain fully vulnerable to real-time session interception.

What defenders should do: Deploy FIDO2/WebAuthn for any authentication flow protecting high-value systems. Implement device trust verification that validates endpoint posture before granting session tokens. Monitor for anomalous session origins - a session that authenticates from one IP and immediately appears from another is a strong indicator of AitM relay.

Defender Action Items

  • Apply the SonicWall SMA1000 hotfix now - do not wait for CVE assignment. Verify via firmware version, not scanner output.
  • Audit all FortiGate VPN admin accounts for rogue entries. Rotate credentials. Enable phishing-resistant MFA on management interfaces.
  • Patch Atlassian Data Center products (Jira, Confluence, Bitbucket) for CVE-2026-21589. Deploy WAF virtual patching if the patch window exceeds 24 hours.
  • Evaluate FIDO2/WebAuthn deployment for authentication flows protecting research, intellectual property, and administrative systems.
  • Review AI/LLM server exposure - PoeLLM has infected 3,400+ exposed AI infrastructure instances. Ensure GPU workloads are not internet-accessible without authentication.

Detection Queries

The following Splunk SPL query detects new local administrator account creation on FortiGate devices - the specific technique described in the FBI/USSS FortiBleed alert. It correlates account creation events with the absence of a corresponding change request, surfacing rogue admin accounts created by attackers.

index=fortigate sourcetype="fgt_event" action="user-add" user_type="admin"
| eval account_created=_time
| lookup approved_change_requests ticket_id OUTPUT approved_by
| where isnull(approved_by)
| stats count by src_ip, user, account_created
| where count > 0
| sort -account_created

Adapt the approved_change_requests lookup to your change management system. Any hit without a matching change ticket is a high-fidelity indicator of unauthorized admin account creation. False positive rate is low if the lookup is maintained - legitimate admin provisioning should always have a corresponding ticket.

For Atlassian Data Center CVE-2026-21589, monitor web server access logs for unauthenticated requests containing path traversal sequences targeting known sensitive file paths:

index=web sourcetype="atlassian:access"
| where like(uri_path, "%../%") AND http_status=200 AND (user="anonymous" OR isnull(user))
| stats count by src_ip, uri_path, http_status
| where count > 3
| sort -count

References


Subscribe to it-learn Brief

Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.