Ethical Hacking News
SonicWall's SMA1000 boxes have once again been compromised by hackers who exploited two chained zero-day vulnerabilities, leaving midsize and large enterprises vulnerable to attack. The vendor has released hotfixes to patch the security breaches, but organizations must take proactive measures to protect their networks and devices against emerging threats.
SonicWall's SMA1000 boxes have been exploited by attackers using chained zero-day vulnerabilities, leaving customers with no choice but to apply hotfixes to patch the security breaches. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, are a pre-authentication server-side request forgery (SSRF) vulnerability and a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC). The flaws affect the SMA 6210, 7210, and 8200v appliances, and SonicWall has released hotfixes to patch the security breaches. The company advises customers to apply hotfixes, identify indicators of compromise, and take steps to prevent unauthorized access to sensitive functionality and perform unauthorized operations.
SonicWall's SMA1000 boxes, designed to provide secure remote access and VPN connections for midsize and large enterprises, have once again found themselves at the center of a high-profile cybersecurity attack. The recent exploitation of two chained zero-day vulnerabilities in the Secure Mobile Access Series 1000 boxes has left SonicWall's customers with no choice but to apply hotfixes to patch the security breaches. The attack, attributed to miscreants who used chained zero-days to compromise the SMA1000 boxes, has sparked concerns about the vulnerabilities of edge devices and the growing risk of attacks against internet-facing gateways.
According to SonicWall, the first zero-day vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0. This vulnerability, attributed to an unintended alternative access path, allows a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. The second vulnerability, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3. Under certain conditions, an attacker authenticated as an administrator can execute arbitrary commands on the appliance.
The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes to patch the security breaches. However, the vendor advised customers to contact its technical support team for help identifying indicators of compromise. If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens.
The disclosures continue a difficult run for SonicWall and its SMA1000 product line, which has faced numerous security breaches in the past year. In July, the vendor disclosed an eerily similar pair of vulnerabilities, which comprised a pre-authentication SSRF vulnerability and a post-authentication OS command injection flaw in the AMC. The SSRF received a maximum CVSS v3 score of 10.0, while the command injection bug was rated in the sevens. CISA later added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns.
The growing risk of attacks against edge devices and internet-facing gateways is a pressing concern for organizations that rely on these devices for secure remote access and VPN connections. The NHS England National CSOC has warned about the growing risk of attacks against these devices, stating that firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers. The CSOC assesses future exploitation of these vulnerabilities as almost certain.
In light of the recent attack, SonicWall advises its customers to take proactive measures to protect their SMA1000 boxes against future attacks. The vendor's recommendations include applying hotfixes, identifying indicators of compromise, and taking steps to prevent unauthorized access to sensitive functionality and perform unauthorized operations.
As the threat landscape continues to evolve, organizations must remain vigilant and take proactive measures to protect their networks and devices against emerging threats. The recent attack on SonicWall's SMA1000 boxes serves as a reminder of the importance of regular security patching, vulnerability assessments, and incident response planning.
Related Information:
https://www.ethicalhackingnews.com/articles/SonicWalls-SMA1000-Boxes-Under-Active-Attack-A-Chained-Zero-Day-Exploit-Leaves-Midsize-and-Large-Enterprises-Vulnerable-ehn.shtml
https://www.theregister.com/security/2026/09/02/sonicwalls-sma1000-boxes-under-active-attack-again/5293969
https://nvd.nist.gov/vuln/detail/CVE-2026-83548
https://www.cvedetails.com/cve/CVE-2026-83548/
https://nvd.nist.gov/vuln/detail/CVE-2026-83549
https://www.cvedetails.com/cve/CVE-2026-83549/
https://nvd.nist.gov/vuln/detail/CVE-2026-15409
https://www.cvedetails.com/cve/CVE-2026-15409/
Published: Wed Sep 2 14:40:05 2026 by llama3.2 3B Q4_K_M