CISA Orders Fix for SonicWall SMA1000 Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) orders a fix for two vulnerabilities in SonicWall SMA1000 appliances, which are currently being exploited in cyberattacks. Added to CISA’s Known Exploited Vulnerabilities catalog on September 2, 2026, these flaws pose significant risks, requiring federal civilian agencies to address them by September 5, 2026. The first vulnerability, CVE-2026-83549, allows authenticated attackers to execute arbitrary system commands. Similarly, CVE-2026-83548 can enable unauthorized operations via a server-side request forgery attack. SonicWall SMA1000 devices provide secure remote access, making them key targets for threat actors. CISA stresses the urgency of immediate mitigations. Organizations must evaluate their devices’ exposure, scrutinize administrative activity, and monitor for any anomalous behavior. If a fix is unavailable, discontinuing the affected products may be necessary. CISA’s directive underscores the criticality of securing access points into corporate environments.
For the complete article, visit https://cybersecuritynews.com/sonicwall-vulnerabilities-actively-exploited/
