SonicWall's SMA1000 boxes under active attack again
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
SonicWall has warned that attackers are currently exploiting two zero-day vulnerabilities in its Secure Mobile Access (SMA) Series 1000 boxes. These gateways are used by midsize and large enterprises to secure remote access and VPN connections. Compromising a single gateway could give attackers access to corporate networks. SonicWall has released hotfixes for the affected versions - SMA 6210, 7210, and 8200v. There are currently no workarounds for the issues.
The first vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) flaw with a maximum CVSS v3 score of 10.0. A remote, unauthenticated attacker could potentially exploit this to gain unauthorized access to sensitive functionality and carry out unauthorized operations. The second vulnerability, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the SMA1000 Appliance Management Console (AMC).
Under certain conditions, an authenticated administrator could execute arbitrary commands on the appliance.
NHS England has warned about the growing risk of attacks against internet-facing gateways, which are highly attractive targets for attackers due to their design. The NHS England National Cyber Security Operations Centre (NCSOC) assesses the future exploitation of these vulnerabilities as almost certain. SonicWall advises customers to contact technical support if they suspect an appliance has been compromised, recommending re-imaging or redeploying the device, changing all passwords, and resetting TOTP tokens.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- SonicWall's SMA1000 boxes under active attack again theregister.com