SonicWall's Remediation Guidance Says the Patch Is Only Step One of Four

https://hackernoon.imgix.net/images/rymeSO93fMg9m2SRdMsCXRtvbhG2-e483akb.png

SonicWall disclosed two vulnerabilities in its SMA 1000 secure remote access appliances on September 1 and confirmed both are being exploited in the wild. On September 3, CISA added the more severe of the two to its Known Exploited Vulnerabilities catalog, according to The Hacker News, alongside six other flaws.

The advisory, SNWLID-2026-0016, covers:

  • CVE-2026-83548, CVSS 10.0 — a pre-authentication server-side request forgery flaw in the Appliance Work Place interface. SonicWall says it lets a remote, unauthenticated attacker "gain unauthorized access to sensitive functionality and perform unauthorized operations."
  • CVE-2026-83549, CVSS 7.8 — an OS command injection flaw in the Appliance Management Console, arising from improper neutralization of special elements, which under specific conditions lets a remote attacker authenticated as an administrator execute arbitrary OS commands.

Chained, they get an unauthenticated attacker to remote code execution, which is how Sophos and Rapid7both read the pair. Models...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more