Zero-day SonicWall SMA 1000 sfruttati in rete

Zero-day SonicWall SMA 1000 exploited in the wild

SonicWall has patched two vulnerabilities in SMA 1000 gateways already exploited in real-world attacks: CVE-2026-83548, a pre-authentication SSRF, and CVE-2026-83549, a post-authentication command injection flaw. Researchers and various advisories cite the possibility that attackers could chain them to achieve code execution and, in some cases, root access to the devices. SMA 1000 versions are used for secure remote access in companies, public agencies, and providers, so the potential impact is broad. SonicWall has released updates, while ACN, Help Net Security, The Hacker News, and Security Affairs have confirmed exploitation activity in the wild. The problem is particularly serious because it affects appliances exposed on the Internet, that is, a very attractive entry point for the initial compromise of corporate networks.

Source: Security Affairs

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment