惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
D
DataBreaches.Net
J
Java Code Geeks
月光博客
月光博客
MyScale Blog
MyScale Blog
博客园 - Franky
Jina AI
Jina AI
量子位
博客园 - 聂微东
博客园 - 叶小钗
M
MIT News - Artificial intelligence
N
Netflix TechBlog - Medium
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
S
SegmentFault 最新的问题
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
博客园 - 【当耐特】
Blog — PlanetScale
Blog — PlanetScale
I
InfoQ
小众软件
小众软件
B
Blog RSS Feed
Hugging Face - Blog
Hugging Face - Blog
博客园_首页

Truesec

Russia Recruits Members of “The Com” for Sabotage Operations - Truesec CVE-2026-76461 – Critical Cisco Secure Email Gateway Vulnerability Exploited - Truesec The Ryde Data Breach - Truesec CRA Reporting Starts on 11 September: What Businesses Need To Know - Truesec Privilege Escalation Vulnerability in Falcon Crowdstrike - Truesec Privileged Access Management (PAM) Is No Longer Optional  - Truesec Australian Arrests Allegedly Disrupt TeamPCP, but the Shai-Hulud Threat Persists - Truesec DDoS Attacks Against Norwegian Government Sites - Truesec Critical Citrix NetScaler Memory-Overflow Vulnerability - Truesec Iranian Cyberattacks Against Critical Infrastructure - Truesec Russia Targets Businesses and Officials Behind Europe’s Ukraine Defense Supply Chain - Truesec The World Is Moving at Machine Speed. Are We Ready? - Truesec False CVE in Overwhelmed Verification System - Truesec LLMjacking Is a New Cyber Threat - Truesec Rogue AI Agent Allegedly Hack Hugging Face - Truesec Microsoft SharePoint Server Vulnerabilities Actively Exploited - Truesec Russian Intelligence Targets SOHO Routers - Truesec Cyber Warfare in the Iran War - Truesec Organized Cybercrime Merging with Other Crime - Truesec AI Used in Ransomware Attack The Fortibleed Campaign: Truesec's Experience Fortibleed: Truesec's Experience Supply Chain Attack Compromising Arch Linux AUR Packages with Infostealer and Rootkit - Truesec FortiNet SSO Vulnerability CVE-2025-59718 and CVE-2025-59719 Leading to Full System Compromise - Truesec Critical Vulnerabilities in Ivanti Sentry Allows Code Execution as Root (CVE-2026-10520 & CVE-2026-10523) Typosquatting: When Your Domain Is Used Against You AI in Cybersecurity: Separating Operational Reality from Speculation Compromised @redhat-Cloud-Services Npm Packages Distribute Credential-Stealing Worm GitHub Hacks Highlights Need for Repository Security Installation of a Syslog Log Collector
SonicWall Vulnerabilities Exploited in the Wild - Truesec
Hjalmar Desmond · 2026-09-03 · via Truesec

Threat Insight

Two recently disclosed vulnerabilities in SonicWall[1] appliances are actively being exploited in the wild.

CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path.

CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution.

These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations.

CVE

CVE-2026-83548
CVE-2026-83549

Affected Products

SMA1000 Models – 6210, 7210, 8200v running the following versions:

  • 12.4.3-03453 platform-hotfix and earlier
  • 12.5.0-02835 platform-hotfix and earlier
    Exploitation

Both CVE-2026-83548 and CVE-2026-83549 have recently been added to the CISA database of known exploited vulnerabilities[2].

Recommended Actions

Truesec recommends upgrading affected SonicWall appliances to the patched versions:

  • 12.4.3-03526 platform-hotfix, for systems on the 12.4.3 branch
  • 12.5.0-02952 platform-hotfix, for systems on the 12.5.0 branch

If evidence of compromise is identified we recommend:

  • Re-imaging affected hardware appliances or re-deploying affected virtual appliances.
  • Changing all user and administrator passwords.
  • Resetting Time-based One-Time Password (TOTP) tokens.
    Detection

Review SMA1000 syslogs for:

  • POST requests to /workplace/ containing URL-encoded internal IP addresses, loopback addresses, or management hostnames in query parameters or request bodies.
  • AMC access originating from the appliance’s own workplace process instead of approved administrator workstations or management networks.

Investigate requests involving:

  • /workplace/
  • /appliance/
  • 127.0.0.1
    References

[1] https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
[2] https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog