Skip to content
Live newsroom 28 readers online
Thursday, September 3, 2026 Live Sync: Just now
BreakingOnce valued at €750k, a historic Cork City church is back up for sale at half the price
Important AVOID AMZN Stage 4 (Conv: 3/5 | Size: 10%)

SonicWall's SMA1000 boxes under active attack again

Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain' SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes. Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with […]

By deepak · September 2, 2026 · 2 min read

Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'

SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes.

Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections. Compromising one can therefore provide attackers with a valuable route into corporate networks.

So, get to applying those hotfixes, says SonicWall. There are no workarounds.

The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. SonicWall attributed it to an unintended alternative access path.

"A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said.

The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance.

The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes.

SonicWall advised customers to contact its technical support team for help identifying indicators of compromise.

If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens.

NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways.

"Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers," it stated.

"The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain."

The disclosures continue a difficult run for SonicWall and its SMA1000 product line stretching back through 2025.

In July, the vendor disclosed an eerily similar pair of vulnerabilities. That pair also comprised a pre-authentication SSRF vulnerability, this time in the SMA1000 Appliance WorkPlace interface, and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens.

Source: Read the original article on www.theregister.com

Important Legal & Financial Disclaimer

FutureKnowledge is an automated financial intelligence aggregator. The information provided on this website does not constitute investment advice, financial advice, trading advice, or any other sort of advice and you should not treat any of the website's content as such. We are not registered with the SEC, SEBI, or any regulatory agency. Automated AI-generated content may contain errors. Always conduct your own due diligence and consult your financial advisor before making any investment decisions.

© 2026 FutureKnowledge Intelligence. All rights reserved.