CISA Sets Sept. 5 Deadline for Critical SonicWall Flaw

SonicWall has confirmed that hackers are actively exploiting two vulnerabilities in its SMA1000 series of remote-access appliances, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given federal agencies until September 5 to patch or take the affected devices offline.
The more severe flaw, CVE-2026-83548, is a pre-authentication server-side request forgery bug in the SMA1000's Appliance Work Place interface. It scores a maximum 10.0 on the CVSS severity scale, meaning an attacker needs no credentials to abuse it. A second flaw, CVE-2026-83549, is an OS command injection bug in the Appliance Management Console rated 7.8; on its own it requires an authenticated administrator, but chained with the first flaw it lets an outside attacker run commands on the device without logging in at all.
SonicWall disclosed both issues in advisory SNWLID-2026-0016 on September 1 and said it has already observed the vulnerabilities being exploited together in real attacks. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, requiring forensic triage of affected appliances and setting September 5 as the remediation deadline for U.S. federal civilian agencies.
The stakes are high because SMA1000 appliances, sold in the 6210, 7210 and 8200v models, sit at the edge of corporate networks and authenticate remote employees' VPN connections. A successful attack on one can hand an intruder a direct path into everything behind it. SonicWall has not published indicators of compromise, so many administrators currently have no reliable way to check whether their appliance has already been breached, which is why the company and CISA are both urging immediate patching rather than waiting for a security audit to confirm exposure.
Affected organizations should update to hotfix version 12.4.3-03526 or 12.5.0-02952 or later, SonicWall said. Because the flaws have already been used in live attacks and no compromise indicators exist yet, the company is also advising customers to contact its support team for a manual review of their systems, which in confirmed cases could mean re-imaging physical appliances or redeploying virtual ones from a clean state.
While the CISA deadline formally applies only to U.S. federal agencies, the active-exploitation status means any organization running SMA1000 gear faces the same risk today, regardless of sector or location.
Sources
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- Two New Islands Rise by Anak Krakatau After 25-Hour Eruption
- New Gut Bacterium C. immunis Cut Visceral Fat in Obese Mice
- Meta's 100-Gram VR Glasses Cost $1,299.99, Ship Spring 2027
- Kurihara, 11, One Win From Youngest Asian Games Medal
- Yu Zidi, 13, Wins Third Asian Games Gold in 4:28.56 400 IM
- Haaland Passes Ronaldo and Zlatan With 64th Norway Goal
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- SEC Grants 5-Year Exemption for Tokenized Stock Trading
Comments
No comments yet. Be the first.