AI Weekly Malaysia

Back to items Summaries

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

ID
20634
Status
summarized
Published
02 Sep 2026, 6:53 PM
Fetched
02 Sep 2026, 8:11 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
02 Sep 2026, 8:13 PM
Tags
Audience
developers

What happened

SonicWall patched two actively exploited zero-days in its SMA 1000 series VPN appliances (models 6210, 7210, 8200v): CVE-2026-83548 (CVSS 10.0, pre-auth SSRF) and CVE-2026-83549 (CVSS 7.8, post-auth OS command injection). Attackers are likely chaining both to achieve remote code execution. Fixes are in platform-hotfix versions 12.4.3-03526 and 12.5.0-02952; older versions are vulnerable.

Why it matters

If your company or a client runs SonicWall SMA 1000 appliances on versions 12.4.3-03453 or older / 12.5.0-02835 or older, patch now and check for IoCs — SonicWall advises re-imaging the appliance, rotating all credentials, and resetting TOTP if compromise is found. This is the second zero-day cluster in the same product line in two months (prior flaws CVE-2026-15409/15410 were exploited by UTA0533 to deploy KNUCKLEBALL malware), so the product is a repeated target.

Discussion angle

Whether your org or clients use SonicWall SMA 1000 appliances specifically — if not, this is a monitoring note, not an action item; if yes, the repeated targeting of this product line warrants a conversation about whether to keep it internet-facing.

Top