SonicWall's SMA1000 boxes under active attack again
ID: 9c591c51-4f2e-5ac6-a430-157f30aaaf85
STIX ID: report--9c591c51-4f2e-5ac6-a430-157f30aaaf85
Feed Name: The Register (Security)
Threat Score
SonicWall reports active exploitation of two chained zero-days in SMA1000 appliances (CVE-2026-83548 SSRF and CVE-2026-83549 command injection) that can enable remote takeover of enterprise VPN/remote-access gateways; hotfixes are available and vendors advise reimaging compromised devices, credential resets, and contacting support, while authorities warn further exploitation is highly likely.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
