CISA confirmed this week that ransomware operators are exploiting two SonicWall SMA1000 vulnerabilities patched earlier this year, including a maximum-severity server-side request forgery flaw that lets an unauthenticated attacker force the appliance into making requests on the attacker's behalf. SMA1000 devices sit at the edge of the network by design, brokering remote access for exactly the kind of enterprise user base that makes an SSRF chain useful for reaching internal services a normal internet scan would never touch. Patches existed before CISA's confirmation.
The gap is not the vulnerability. It is the interval between patch availability and exploitation confirmation, the window CISA's advisory says ransomware crews used to build working chains against a device class enterprises route their VPN and remote access traffic through. Security teams running SMA1000 in front of anything resembling a crown-jewel network should treat "patched" and "not exploitable" as two different facts until they have confirmed the patch actually shipped to their instance, not just to the vendor's changelog.