Customers of Palo Alto Networks and SonicWall are being urged to patch their firewalls immediately, as threat actors actively exploit authentication bypass vulnerabilities in both products. Security researchers warn that proof-of-concept exploits are now public, significantly increasing the risk of attacks.
SonicWall vulnerability (CVE-2024-53704) allows attackers to bypass authentication in SSL VPNs, potentially leading to stolen data and disrupted VPN sessions.
(View Details on PwnHub)
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.