SonicWall Issues Alert: Two Major Security Vulnerabilities Under Active Exploitation

SonicWall has reported two critical security vulnerabilities in its Secure Mobile Access 1000 series appliances, which are currently being exploited. The company has issued patches for these issues and warns that there are no workarounds available.

The first vulnerability, identified as CVE-2026-83548, is rated as critical and allows unauthenticated remote attackers to access sensitive functionality due to an unintended access path in the SMA1000 Appliance Work Place interface. The second vulnerability, CVE-2026-83549, is rated high and permits attackers to impersonate administrators and execute arbitrary commands, leading to remote code execution.

Affected firmware versions include 12.4.3-03453 and 12.5.0-02835. SonicWall has advised customers to contact technical support to check if their devices have been compromised and recommends swift patching due to the serious nature of these exploits.

Security consultants have emphasized the severity of these vulnerabilities. Mike Wilkes, a CISO at Aikido Security, noted the alarming potential for full system control by attackers. Flavio Villanustre from LexisNexis Risk Solutions Group described the vulnerabilities as “red hot” and in need of immediate attention due to how the SMA1000 appliance is deployed.

The SSRF vulnerability in particular allows attackers to change system settings without authentication, making it easy for them to gain repeated access even after repairs, according to Villanustre. Cybersecurity consultant Brian Levine reiterated these concerns, highlighting the systemic risks posed by these appliances being at the network’s edge.

The timing of these disclosures has caused concern, as they follow a recent chain of similar exploitation that has already affected a number of organizations. SonicWall has faced scrutiny, with 18 to 22 publicly disclosed CVEs regarding its products over the last year, which have led to increases in cyberattacks against its devices.

For further details and updates, refer to the SonicWall security alert here.

Total
0
Shares
Leave a Reply

Your email address will not be published. Required fields are marked *

Previous Article

OpenAI Set to Unveil Groundbreaking AI Model with 'Critical' Cyber Capabilities

Next Article

Nvidia's $12.9 Billion Bet: The Strategic Acquisition of Hugging Face and Its Impact on Open-Source AI

Related Posts