CuraSec

Act active

SonicWall SMA 1000 Two Zero-Days Actively Exploited, May Chain

2026-09-02 15:05 UTC · The Hacker News · read the source ↗ #sonicwall#zero-day#vpn-appliance
  • Engineer — Act: Pre-authentication SSRF (CVSS 10.0) with a public PoC and confirmed active exploitation on SonicWall SMA 1000 series VPN appliances — patch to the vendor-released update immediately and isolate appliances from untrusted networks while patching proceeds.
  • SOC/IR — Act: Active zero-day exploitation of an edge VPN device means assume-breach posture: sweep SMA 1000 access and authentication logs for anomalous pre-auth requests and unusual outbound SSRF-originated connections since disclosure, and tune detections for chained exploit behavior from the appliance.
  • Leader — Act: Confirm whether the organization runs SonicWall SMA 1000 appliances and, if so, brief leadership this week — a CVSS 10.0 pre-auth zero-day under active exploitation on a perimeter VPN is a material risk event that may generate customer or board questions.
  • Signals: CVE-2026-83548 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.