Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities Dark Reading

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

  • What: SonicWall SMA 1000 has zero-days enabling unauthenticated RCE
  • Impact: Critical flaw allows attackers to execute code without authentication
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands An Informa TechTarget Publication Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise Newsletter Sign-Up Newsletter Sign-Up Cybersecurity Topics Related Topics Application Security Cybersecurity Careers Cloud Security Cyber Risk Cyberattacks & Data Breaches Cybersecurity Analytics Cybersecurity Operations Data Privacy Endpoint Security ICS/OT Security Identity & Access Mgmt Security Insider Threats IoT Mobile Security Perimeter Physical Security Remote Workforce Threat Intelligence Vulnerabilities & Threats Recent in Cybersecurity Topics Vulnerabilities & Threats SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE by Alexander Culafi Sep 2, 2026 3 Min Read Application Security Attackers Pounce on Critical Artifactory Bug Following Disclosure Attackers Pounce on Critical Artifactory Bug Following Disclosure by Jai Vijayan Sep 1, 2026 4 Min Read World Related Topics DR Global Asia Pacific Europe Latin America Middle East & Africa Recent in World See All Cyberattacks & Data Breaches Russian Hackers Phish EU Officials Over Messaging Apps Russian Hackers Phish EU Officials Over Messaging Apps by Nate Nelson Aug 27, 2026 5 Min Read Cyberattacks & Data Breaches Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor's Office by Nate Nelson Aug 14, 2026 4 Min Read The Edge DR Technology Events Related Topics Upcoming Events Podcasts Webinars SEE ALL Resources Related Topics Resource Library White Papers Reports Webinars Newsletters Podcasts Heard It From a CISO Reporters' Notebook Dark Reading's 20th Videos Dark Reading Polls Partner Perspectives Meet the Editors Advertise With Us About Us Dark Reading Resource Library Vulnerabilities & Threats Perimeter Application Security Cyberattacks & Data Breaches News SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices. Alexander Culafi , Senior News Writer , Dark Reading September 2, 2026 3 Min Read Source: dzika_mrowka via Getty Images Attackers are exploiting two zero-day vulnerabilities affecting select SonicWall SMA 1000 perimeter devices, and customers are urged to patch immediately. SonicWall disclosed two flaws on Tuesday: pre-authentication server-side request forgery (SSRF) vulnerability CVE-2026-83548 and post-authentication remote code execution (RCE) vulnerability CVE-2026-83549. The former is present in the SMA 1000 Appliance Work Place interface (the user facing portal) and the latter in the SMA 1000 Appliance Management Console (AMC), which is the administrator portal for SMA 1000 remote access gateways. CVE-2026-83548, the SSRF bug, was designated the maximum CVSS 3.0 score of 10. SonicWall said in its advisory that the vulnerability is caused by an unintended alternate access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the advisory read. Related: Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise CVE-2026-83549 carries a score of 7.8. SonicWall referred to it as a "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability"; specific conditions could enable an authenticated remote attacker to execute arbitrary OS commands leading to RCE. In a blog post about the flaws, Rapid7 wrote the vulnerabilities "can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances." Moreover, "No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication." SonicWall noted that the vendor's Product Security Incident Response Team (PSIRT) "investigated a case indicating the active exploitation of the vulnerabilities described in this advisory." The bugs were internally discovered by SonicWall's William Perry and Adam Babis. The current exploitation activity follows attacks on two other SMA 1000 zero-days earlier this summer — CVE-2026-15409 and CVE-2026-15410 — which could similarly be chained together for RCE. SMA 1000 models 6210, 7210, and 8200v are affected, specifically versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. The vendor urged customers to upgrade to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher. SMA 1000 Attacks Are Ongoing, Patch Now A spokesperson for SonicWall tells Dark Reading that these attacks are ongoing. "We have confirmed that these vulnerabilities are being actively exploited in the wild," SonicWall says. "Upon discovery, SonicWall promptly investigated and released fixed firmware. We are directing all customers running affected appliances to install the released firmware (12.4.3-03526 or 12.5.0-02952) immediately, review for indicators of compromise, and contact SonicWall technical support if any are found." Related: The Vulnpocalypse Is Repricing the Bug Bounty Economy If IOCs are detected, the customer should re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens. Remote access gateways such as the SMA 1000 sit at the edge of enterprise networks and are frequently exposed directly to the internet, making them attractive targets for attackers. SonicWall's SMA 1000 appliances specifically have been hit with several zero-day attacks in recent years. Rapid7 noted that the role of these systems as network edge devices makes successful exploitation particularly concerning. SonicWall's guidance that compromised customers re-image hardware appliances or re-deploy virtual appliances suggests the company views successful exploitation as potentially resulting in significant control over affected systems. About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. See more from Alexander Culafi Want more Dark Reading stories in your Google search results? Add Us Now More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice Cyber Risk What We Missed: Delta Flight Disrupted With Wi-Fi Hack What We Missed: Delta Flight Disrupted With Wi-Fi Hack by Rob Wright , Alexander Culafi Aug 20, 2026 Cyberattacks & Data Breaches Agentic AI Presents New Insider Threat Model for Orgs Agentic AI Presents New Insider Threat Model for Orgs Aug 19, 2026 Want more Dark Reading stories in your Google search results? How Organizations Are Managing Incident Response Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. Download Now November 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI Save Your Spot Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. Subscribe Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us Newsletter Sign-Up Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home | Cookie Policy | Privacy | Terms of Use Your Privacy Choices

Share this article