








Threat Insight
Two recently disclosed vulnerabilities in SonicWall[1] appliances are actively being exploited in the wild.
CVE-2026-83548: A critical, unauthenticated server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. It allows attackers to reach sensitive internal functionality through an unintended access path.
CVE-2026-83549: A high-severity OS command injection vulnerability in the Appliance Management Console (AMC). It can allow arbitrary operating-system command execution.
These two vulnerabilities can be chained together to achieve unauthenticated remote code execution, allowing attackers to access sensitive functionality and perform unauthorized operations.
CVE-2026-83548
CVE-2026-83549
SMA1000 Models – 6210, 7210, 8200v running the following versions:
Both CVE-2026-83548 and CVE-2026-83549 have recently been added to the CISA database of known exploited vulnerabilities[2].
Truesec recommends upgrading affected SonicWall appliances to the patched versions:
If evidence of compromise is identified we recommend:
Review SMA1000 syslogs for:
Investigate requests involving:
[1] https://www.rapid7.com/blog/post/etr-critical-sonicwall-sma1000-vulnerabilities-cve-2026-83548-cve-2026-83549-exploited-in-the-wild
[2] https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。