Back Cybernews SonicWall SMA1000 zero-day exploited, CISA orders patches
CISA warns that attackers are actively exploiting two SonicWall SMA1000 vulnerabilities.
The most severe flaw lets unauthenticated attackers access sensitive gateway functions remotely.
SonicWall says no workaround exists; affected customers should install the latest hotfix.
ShadowServer sees at least 420 SMA 1000 devices exposed to the public internet.
Key Takeaways by nexos.ai , reviewed by Cybernews staff.
Cyber authorities are ringing alarm bells over a “perfect” 10/10 zero-day vulnerability affecting the SonicWall SMA1000. Attackers can compromise enterprise-grade gateways without any authentication.
SonicWall alerted on the 1st of September to 2 critical vulnerabilities affecting SMA1000 Series Appliances – one of them carries a 10 out of 10 severity rating and enables remaining attackers to gain unauthorized access without any authentication.
The US Cybersecurity and Infrastructure Security Agency (CISA) flagged the newly disclosed vulnerabilities as actively exploited and added them to its Known Exploited Vulnerabilities catalog.
CISA told federal agencies to patch the affected models within 72 hours – SonicWall’s advisory leaves no workarounds other than upgrading to the latest hotfix version .
SonicWall’s SMA (Secure Mobile Access) 1000 Series appliances are gateways that let remote employees safely connect to corporate networks. These devices are at the edge of the corporate network and often reachable from the public internet.
The pre-authentication flaw, tracked as CVE-2026-83548 , is a server-side request forgery (SSRF) vulnerability, meaning that attackers can specially craft a request or a URL that causes the vulnerable server to make an internal network request to a destination chosen by the attacker. This may include internal systems that aren’t intended to be accessible from the internet.
“A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations,” the vulnerability description reads.
The high-impact cyberattack can be carried out over a network, it is low-complexity, requires no privileges or user interaction, and exploitation can affect resources beyond the vulnerable component itself.
The second bug, CVE-2026-83549 , is a post-authentication remote code execution vulnerability in the SMA1000 Appliance Management Console (AMC). Once authenticated access is obtained, a remote attacker can exploit it to execute arbitrary OS commands as an administrator.
Both vulnerabilities were zero-days at the time of disclosure – SonicWall itself detected an ongoing active exploitation.
“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability,” the advisory reads.
The affected SMA 1000 models include 6210, 7210, and 8200v.
According to ShadowServer scans, at least 420 devices identified as SMA 1000 are reachable from the public internet.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
