CISA Flags Two SonicWall SMA 1000 Flaws as Actively Exploited, Gives Agencies 3 Days to Patch
CISA added two SonicWall SMA 1000 vulnerabilities — a pre-authentication SSRF flaw (CVE-2026-83548) and an OS command injection flaw (CVE-2026-83549) — to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a federal remediation deadline of September 5. SonicWall responded the same day by publishing advisory SNWLID-2026-0016 alongside patched firmware versions 12.4.3-03526 and 12.5.0-02952. A ZoomEye scan conducted on September 18, 2026, identified only 7 records matching the precise SMA product fingerprint, reflecting that the appliance's management interface is not intended for public exposure. Security researchers caution that broader vendor-name searches returning millions of SonicWall-branded assets do not accurately represent SMA 1000 exposure and should not be conflated with the specific vulnerability surface. Organizations are advised to query their own perimeters using the product-specific fingerprint and treat any internet-reachable SMA 1000 portal as potentially vulnerable until patched versions are confirmed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in