SonicWall's SMA1000 boxes under active attack again
SonicWall says attackers are actively exploiting two chained zero-days to take over Secure Mobile Access (SMA) Series 1000 boxes.
Aimed at midsize and large enterprises, SMA1000 gateways secure remote access and VPN connections.
Compromising one can therefore provide attackers with a valuable route into corporate networks.
So, get to applying those hotfixes, says SonicWall.
There are no workarounds.
The first zero-day, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability with a maximum CVSS v3 score of 10.0.
SonicWall attributed it to an unintended alternative access path.
"A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the vendor said.
The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC), rated 7.8 on CVSS v3.
Under certain conditions, an attacker authenticated as an administrator could execute arbitrary commands on the appliance.
The flaws affect the SMA 6210, 7210, and 8200v appliances, for which SonicWall has released hotfixes.
SonicWall advised customers to contact its technical support team for help identifying indicators of compromise.
If an appliance appears to have been compromised, SonicWall recommends reimaging or redeploying it, changing all passwords, and resetting TOTP tokens.
NHS England, which published its own advisory, warned about the growing risk of attacks against internet-facing gateways.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.