SonicWall Issues Critical Patch for SMA 1000 Series to Stop SQL Injection and MFA Bypasses
ID: 7a5eb91c-54f7-5074-ad6f-432df840e249
STIX ID: report--7a5eb91c-54f7-5074-ad6f-432df840e249
Feed Name: securityonline.info
**Executive Summary:** SonicWall released patches addressing four vulnerabilities in SMA 1000 series appliances (CVE-2026-4112, CVE-2026-4113, CVE-2026-4114, CVE-2026-4116), the most severe being a CVSS 7.2 SQL injection that allows a remote authenticated user with read-only admin privileges to escalate to primary administrator; two Unicode-based TOTP MFA bypasses let authenticated SSLVPN users or admins bypass TOTP, and an observable response discrepancy can be used to enumerate SSL VPN credentials; SonicWall urges immediate upgrade to fixed releases and reports no observed in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
