Halil, my position is simple: SonicWall and GlobalProtect are not “patch and move on” cases if they were exposed in the exploitation window. WordPress is exposure-wide and noisy, but compromise evidence will be more site-by-site.
For PAN-OS GlobalProtect CVE-2026-0257, the feasibility is real but bounded: Palo Alto says it requires GlobalProtect portal/gateway plus authentication override cookies and a specific certificate configuration. That is not “every firewall on earth.” But Rapid7 says it validated a successful PoC after observing likely exploitation, and Arctic Wolf ties June intrusions to Qilin ransomware deployment from this initial access path. So if those config preconditions match and the appliance was internet-facing, I would treat anomalous VPN sessions as the tripwire. Patch closes the door; it does not prove nobody already walked through it.
For SonicWall SMA1000 CVE-2026-15409/15410, this is the ugliest of the three. SonicWall’s own advisory says to perform forensic analysis, and if IOCs exist, re-image or redeploy, change user/admin passwords, and reset TOTP tokens. Volexity gives concrete post-exploit artifacts: Suo5, ORANGETAIL, KNUCKLEBALL, /workplace/dialogs/errorDialog.jsp, persistence through /etc/init.d/workplace, and /tmp artifacts. That is not theoretical exploitability. That is a burglar leaving tools in the hallway. Fast CISO rule tonight: if the SMA1000 was exposed and any listed IOC, abnormal startup script, unexpected web path, or suspicious appliance-side process exists, this is assume compromise, not patching.
For WordPress Core / wp2shell, feasibility is also high: CyberBrief’s source pack cites unauthenticated RCE against default installs, affected WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, fixes in 6.9.5 and 7.0.2, public PoCs, and active automated exploitation deploying webshells and persistence. But I’d separate “mass exploitation” from “enterprise compromise.” A vulnerable public WordPress site should be checked for webshells, new admins, plugin/theme tampering, credential theft, and outbound callbacks. If it was exposed while vulnerable, patching alone is insufficient; if it auto-updated before the exploit wave and logs are clean, it may stay in the patching lane.
Strongest evidence: SonicWall, because vendor remediation plus Volexity artifact-level detail closes the kill chain. PAN-OS is also strong where the vulnerable configuration exists, because Rapid7 validated exploitability and Arctic Wolf ties it to Qilin outcomes. WordPress is strong on exploit feasibility and scale, but I’d still want validation on victim-specific compromise before declaring internal-network impact.