SonicWall urges immediate patching of chained vulnerabilities
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Vendors and products
- SonicWall
- Reported by
- 1 outlet
An article from
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.
Published Sept. 3, 2026
Security researchers warn that hackers are chaining a maximum-severity vulnerability in the SonicWall SMA1000 appliances with a high-severity flaw to achieve remote code execution.
A critical server-side request forgery flaw in the Appliance Work Place interface, tracked as CVE-2026-83548, allows an attacker to access sensitive functions and perform unauthorized actions. The vulnerability has a severity score of 10, the maximum on the scale.
That vulnerability is being chained with CVE-2026-83549, a high-severity OS command-injection vulnerability in the Appliance Management Console. The vulnerability has a severity score of 7.8.
SonicWall on Tuesday confirmed the flaws are being exploited in the wild and urged all users to upgrade to the latest hotfix.
The Cybersecurity and Infrastructure Security Agency on Wednesday added CVE-2026-83548 and CVE-2026-84549 to the Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have until Saturday to mitigate the vulnerabilities.
Rapid7 researchers noted that SonicWall SMA appliances are often used in environments where workers and other authorized parties have secure access to internal applications and resources. Appliance Work Place applications are often exposed to the public internet in these environments.
The current exploitation activity comes less than two months after SonicWall SMA1000 appliances were targeted in July. Researchers at Volexity traced exploitation of CVE-2026-15409 and CVE-2026-15410 to threat activity that began in June.
Volexity researchers tracked that activity to an actor it identified as UTA0533. Researchers have not linked the current activity to a specific threat group.
Reproduced in full under licence from Cybersecurity Dive. © Cybersecurity Dive. Written by David Jones.
Coverage
One outlet has carried this so far.
2026-09-03 15:03 UTC
Related stories
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News · 2026-09-16
- Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News · 2026-09-16
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Infosecurity Magazine · 2026-09-16
- The true cost of a ransomware attack, with and without BCDR
BleepingComputer · 2026-09-16
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News · 2026-09-16