← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI KEV ✓ EPSS 0.09

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

Číst originál na BleepingComputer →

13 zpráv z 11 zdrojů · první 2. 9. 02:00 · poslední 3. 9. 04:00 CZ · EN/orig

SonicWall FI US CA IT NL AT GB FR

tg: zneužíváno tg: zranitelnost

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-83548 10.0 3.1 · CISA-ADP KEV ✓ 0.05
CVE-2026-83549 7.8 3.1 · CISA-ADP KEV ✓ 0.09

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Zmíněno jen v textu zpravodajského článku, ne jako identifikátor téhle události: CVE-2025-40602, CVE-2026-15409, CVE-2026-15410. Fakta z katalogů jsou na jejich stránkách, v tabulce výš ne.

Jak se o tom psalo 13

  1. · NCSC-FI FI

    SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities 10

    Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 10.0, CVEs: CVE-2026-83548, CVE-2026-83549, Summary: 1) CVE-2026-83548 - Pre-authentication SSRF via unintended forward-proxy A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform…

  2. · Rapid7 US

    Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

    OverviewOn September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances.CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base…

  3. · Cyber Centre Kanada CA

    SonicWall security advisory (AV26-872)

    Serial Number: AV26-872Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: SMA1000 - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548, CVE-2026-83549 are being exploited. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security…

  4. · CSIRT Itálie (ACN) IT

    SonicWall: rilevato sfruttamento in rete delle CVE-2026-83548 e CVE-2026-83549

    Rilevato lo sfruttamento attivo in rete delle vulnerabilità CVE-2026-83548 e CVE-2026-83549 – già sanate dal vendor – presenti nel prodotto Secure Mobile Access (SMA) 1000 Series, soluzione per l'accesso remoto sicuro alle risorse aziendali.

  5. · CSIRT Itálie (ACN) IT

    Vulnerabilità in prodotti SonicWall

    Aggiornamenti di sicurezza SonicWall sanano 2 vulnerabilità di cui una con gravità "critica" e una con gravità "alta" presenti in SonicWall SMA1000, serie di appliance per l'accesso remoto sicuro. Tali vulnerabilità, qualora sfruttate da un attaccante remoto, potrebbero consentire di accedere a informazioni riservate sui sistemi interessati o di iniettare comandi di sistema al fine di eseguire codice arbitrario.

  6. · NCSC-NL NL

    NCSC-2026-0337 [1.00] [H/H] Zero-Day kwetsbaarheden verholpen in SMA1000 Appliance van SonicWall

    SonicWall heeft kwetsbaarheden verholpen in de SMA1000 Appliance. De SMA1000 Appliance bevat twee kwetsbaarheden. De eerste is een pre-authenticatie Server-Side Request Forgery (SSRF) in de Work Place interface, waarmee een externe, niet-geauthenticeerde aanvaller ongeautoriseerde acties kan uitvoeren. De tweede kwetsbaarheid betreft post-authenticatie remote code execution, waarbij een aanvaller met geldige inloggegevens willekeurige code op afstand kan uitvoeren. Beide kwetsbaarheden zijn als…

  7. · CERT.at AT

    Kritische Sicherheitslücken in SonicWall SMA1000 Series - aktiv ausgenutzt - Updates verfügbar

    2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung, die Appliance dazu zu bringen, serverseitig Anfragen an eigentlich nicht erreichbare interne Endpunkte zu senden (Server-Side Request Forgery). Laut SonicWall PSIRT werden die in diesem Advisory beschriebenen Schwachstellen bereits aktiv ausgenutzt. CVE-Nummer…

  8. · BleepingComputer US nadpis události

    SonicWall warns of actively exploited SMA1000 zero-day flaws

    SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

  9. · CISA KEV US

    SonicWall SMA1000 Appliances OS Command Injection Vulnerability (CVE-2026-83549)

    CISA added CVE-2026-83549 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.

  10. · CISA KEV US

    SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-83548)

    CISA added CVE-2026-83548 to the Known Exploited Vulnerabilities catalog. Affected product: SonicWall SMA1000 Appliances. Remediation due date: 2026-09-05.

  11. · Sophos Threat Research GB

    SonicWall 83548 83549

    Categories: Threat ResearchTags: advisory, vulnerability, SonicWall

  12. · CERT-FR – alerty FR

    Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

    Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...

  13. · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits SonicWall (02 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits SonicWall. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF). L'éditeur indique que les vulnérabilités CVE-2026-83548 et CVE-2026-83549...