SonicWall's SMA1000 boxes under active attack again
- ID
- 20808
- Status
- summarized
- Published
- 03 Sep 2026, 12:05 AM
- Fetched
- 03 Sep 2026, 2:39 AM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/02/sonicwalls-sma1000-boxes-under-active-attack-again/5293969
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 3.5
- Created
- 03 Sep 2026, 2:40 AM
- Tags
- Audience
- developers
What happened
SonicWall disclosed two chained zero-days (CVE-2026-83548, a pre-auth SSRF rated 10.0 CVSS, and CVE-2026-83549, a post-auth OS command injection rated 7.8) being actively exploited against SMA1000 Secure Mobile Access appliances—specifically the SMA 6210, 7210, and 8200v models. There are no workarounds; SonicWall has released hotfixes and recommends reimaging compromised appliances, changing all passwords, and resetting TOTP tokens. Third-party SOCs including NHS England's National CSOC assess further exploitation as 'almost certain.'
Why it matters
If your organization runs SonicWall SMA1000 appliances for VPN/remote access, apply the hotfixes immediately—there is no mitigation path other than patching, and compromised boxes require full reimage plus credential and TOTP resets. For everyone else, this is another data point in the ongoing pattern of internet-facing edge devices being rapidly exploited post-disclosure, which is worth noting if you manage any perimeter infrastructure.
Discussion angle
The broader pattern: edge devices (VPNs, firewalls, gateways) are now the primary entry point for network compromises, and disclosure-to-exploitation windows are shrinking—what does that mean for how teams should prioritize perimeter patching versus internal hardening?