Cybersecurity

CISA Sets Sept. 5 Deadline for Critical SonicWall Flaw

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

CISA Sets Sept. 5 Deadline for Critical SonicWall Flaw
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

SonicWall has confirmed that hackers are actively exploiting two vulnerabilities in its SMA1000 series of remote-access appliances, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until September 5 to patch or take the affected devices offline.

The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery bug in the SMA1000's Appliance Work Place interface. It scores a maximum 10.0 on the CVSS severity scale, meaning an attacker needs no credentials to abuse it. A second flaw, CVE-2026-83549, is an OS command injection bug in the Appliance Management Console rated 7.8; on its own it requires an authenticated administrator, but chained with the first flaw it lets an outside attacker run commands on the device without logging in at all.

SonicWall disclosed both issues in advisory SNWLID-2026-0016 on September 1 and said it has already observed the vulnerabilities being exploited together in real attacks. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, requiring forensic triage of affected appliances and setting September 5 as the remediation deadline for U.S. federal civilian agencies.

The stakes are high because SMA1000 appliances, sold in the 6210, 7210 and 8200v models, sit at the edge of corporate networks and authenticate remote employees' VPN connections. A successful attack on one can hand an intruder a direct path into everything behind it. SonicWall has not published indicators of compromise, so many administrators currently have no reliable way to check whether their appliance has already been breached, which is why the company and CISA are both urging immediate patching rather than waiting for a security audit to confirm exposure.

Affected organizations should update to hotfix version 12.4.3-03526 or 12.5.0-02952 or later, SonicWall said. Because the flaws have already been used in live attacks and no compromise indicators exist yet, the company is also advising customers to contact its support team for a manual review of their systems, which in confirmed cases could mean re-imaging physical appliances or redeploying virtual ones from a clean state.

While the CISA deadline formally applies only to U.S. federal agencies, the active-exploitation status means any organization running SMA1000 gear faces the same risk today, regardless of sector or location.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.