Unauthenticated RCE in a widely used SSL VPN gateway
Affected: Firmware 7.2.0–7.2.8
Do now: Patch to 7.2.9 today; hunt for new admin accounts.
ADVISORIES & RESOURCES
Affected: Firmware 7.2.0–7.2.8
Do now: Patch to 7.2.9 today; hunt for new admin accounts.
Affected: Agent 12.x
Do now: Update the agent; restrict the service account.
Affected: Versions before 3.4.2
Do now: Update and rotate signing keys.
Affected: Versions before 5.1
Do now: Update within your regular patch window.
Affected: Tool 8.0–8.3 (clients only, TLP:AMBER)
Do now: Segment engineering stations; await vendor fix.
Affected: Plugin 2.x
Do now: Update at next maintenance.
No advisories match these filters. Quiet is good news.
Placeholder CVE IDs and products for demonstration.
RAPID-RESPONSE TEMPLATE
01 · AM I AFFECTED?
Firmware 7.2.0–7.2.8 with the web portal exposed. Check: admin UI → System → Firmware.
02 · DO NOW
Patch to 7.2.9. If you can't today: disable the web portal and restrict management to 198.51.100.0/24-style internal ranges.
03 · HUNT
New local admins since 2026-09-20, unknown files in /tmp, outbound to unfamiliar hosts.
04 · KEEL CLIENTS
MDR clients: detections deployed 2026-09-23 19:10 UTC. We've contacted every affected client directly.
REPORTS · WEBINARS · INSIGHTS