{"id":9286,"date":"2026-09-02T23:22:10","date_gmt":"2026-09-02T23:22:10","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9286"},"modified":"2026-09-02T23:22:10","modified_gmt":"2026-09-02T23:22:10","slug":"sonicwall-reports-two-major-security-holes-under-active-exploit","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9286","title":{"rendered":"SonicWall reports two major security holes under active exploit"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling.<\/p>\n<p class=\"wp-block-paragraph\">In its <a href=\"https:\/\/www.sonicwall.com\/support\/notices\/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities-snwlid-2026-0016\/kA1VN000002AXmQ0AW\" target=\"_blank\" rel=\"noopener\">security alert<\/a>, SonicWall described the first hole, tracked as <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-83548\" target=\"_blank\" rel=\"noopener\">CVE-2026-83548<\/a> and rated 10 (critical) in severity, as a \u201cPre-authentication SSRF vulnerability [that] exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The alert described the second hole (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-83549\" target=\"_blank\" rel=\"noopener\">CVE-2026-83549<\/a>), in the SMA1000 Appliance Management Console (AMC), as one allowing an attacker to impersonate an administrator and to then \u201cexecute arbitrary OS commands, resulting in remote code execution.\u201d\u00a0Its severity rating is 7.8 (High).<\/p>\n<p class=\"wp-block-paragraph\">There is no workaround for either bug, which affects versions 12.4.3-03453 and 12.5.0-02835 of the firmware. The company advised customers to contact technical support for assistance in determining whether a device has already been compromised.<\/p>\n<h2 class=\"wp-block-heading\">Swift patching recommended<\/h2>\n<p class=\"wp-block-paragraph\">Cybersecurity consultants and specialists encouraged IT and cybersecurity teams to patch as quickly as possible, given the nature of these holes.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/eclectiqus\/\" target=\"_blank\" rel=\"noopener\">Mike Wilkes<\/a>, enterprise CISO at Aikido Security, said the potential for an attacker gaining full system control, not just access, is frightening.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSonicWall\u2019s own recommendation to re-image compromised appliances and reset user and administrator passwords and TOTP tokens illustrates how seriously that possibility should be taken,\u201d he said, adding that SonicWall\u2019s recent past should encourage CISOs to move quickly.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThese are as critical as it gets. I would classify them as red hot and require immediate attention,\u201d added <a href=\"https:\/\/www.linkedin.com\/in\/fvillanustre\/\" target=\"_blank\" rel=\"noopener\">Flavio Villanustre<\/a>, CISO for the LexisNexis Risk Solutions Group.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">He said the reason he sees these holes as so severe is partly due to the nature of how the SMA1000, a secure mobile access appliance, is deployed, and how accessible it is to random Web visitors.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCVE-2026-83548 allows a threat actor to perform any changes to the system without the need for any authentication. In a nutshell, an attacker could connect to the system and modify security configuration settings without needing valid credentials,\u201d Villanustre said. \u201cThis vulnerability completely subverts the controls, provides an attacker with a wide range of opportunities, and allows them to establish persistence after the vulnerability is fixed.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Cybersecurity consultant <a href=\"https:\/\/formergov.com\/directory\/brianlevine\" target=\"_blank\" rel=\"noopener\">Brian Levine<\/a>, executive director of FormerGov, agreed.<\/p>\n<p class=\"wp-block-paragraph\">The pre-authentication SSRF \u201clets an unauthenticated attacker reach controls they should never touch, and the command injection flaw converts that reach into full code execution on the appliance,\u201d Levine said. \u201cBecause these boxes sit at the network edge and broker remote access, the worst case is an attacker owning a trusted gateway and pivoting straight into the internal network, stealing credentials and configurations, planting persistence and moving laterally.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF005506\" target=\"_blank\" rel=\"noopener\">Philip Harris<\/a>, an IDC research director, concurred with Levine\u2019s assessment.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThese two holes are about as serious as it gets for an edge access appliance, and the fact that SonicWall is disclosing them as already under active exploitation removes any question about whether this is theoretical,\u201d he said.<\/p>\n<p class=\"wp-block-paragraph\">On its own, the pre-authentication SSRF lets an outsider reach internal functionality that the appliance was never supposed to expose, Harris noted. \u201cPaired with the OS command injection in the Appliance Management Console, the two form a chain: the unauthenticated SSRF gets an attacker into position to trigger the command injection flaw, and the end result is remote code execution, in practice as root, on a device that sits at the perimeter of the network by design.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Repeats a June attack chain<\/h2>\n<p class=\"wp-block-paragraph\">What makes this issue especially significant is the timing and the pattern, he pointed out. \u201cThis is essentially a rerun of what happened with the same appliance line just weeks ago,\u201d he said, citing the July disclosure of a \u201cnearly identical\u201d SSRF-plus-command-injection chain in SMA1000 that researchers at Volexity traced to exploitation starting June 22, weeks before a patch existed.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThat earlier chain was picked up by a threat cluster tracked as UTA0533 and then weaponized at scale by the INC ransomware operation, which has claimed roughly 900 victims globally since,\u201d he noted. In those operations, attackers were harvesting local credentials, session databases, and TOTP MFA seeds to gain persistent, hard-to-evict access before moving laterally into victim networks.<\/p>\n<p class=\"wp-block-paragraph\">And, Wilkes pointed out, that hasn\u2019t been the only reported vulnerability; there have been 18 \u2013 22 publicly disclosed CVEs impacting SonicWall products over the past 12 months, resulting in other <a href=\"https:\/\/www.csoonline.com\/article\/4209606\/akira-ransomware-reboots-into-windows-safe-mode-to-knock-edr-offline.html\" target=\"_blank\" rel=\"noopener\">cybersecurity issues<\/a> which have included <a href=\"https:\/\/www.csoonline.com\/article\/4097078\/sonicwall-ransomware-attacks-offer-an-ma-lesson-for-csos.html\" target=\"_blank\" rel=\"noopener\">ransomware attacks<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">He quipped, \u201cit\u2019s a bit tongue-in-cheek to remark that, from a product stickiness point of view, it\u2019s not a great feature that your PSIRT portal is getting more traffic than the rest of your website.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><em>This article originally appeared on <a href=\"https:\/\/www.networkworld.com\/article\/4217671\/sonicwall-reports-two-major-security-holes-under-active-exploit.html\" target=\"_blank\" rel=\"noopener\">Network World<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>SonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authentication, highly troubling. In its security alert, SonicWall described the first hole, tracked [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9287,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9286"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9286"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9286\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9287"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}