Threat Response - Two serious security flaws affect SonicWall SMA1000 appliances
Dutch follows English
On September 1st 2026 critical vulnerabilities have been discovered in SonicWall SMA1000 appliances that are being actively exploited by attackers. One vulnerability allows complete system takeover without any authentication required [1].
Description
Two serious security flaws affect SonicWall SMA1000 appliances:
- Pre-authentication Server-Side Request Forgery (SSRF) (CVE-2026-83548) - An attacker can abuse the Work Place interface to access internal systems without needing a username or password. This happens because the appliance unintentionally acts as a proxy server.
- Post-authentication Remote Code Execution (CVE-2026-83549) - An attacker who has administrator access to the Appliance Management Console can inject malicious commands that the system will execute.
SonicWall has confirmed that attackers are already actively exploiting these vulnerabilities in real-world attacks.
Impact
We estimate the impact of these vulnerabilities as HIGH.
The first vulnerability received the maximum severity score of CVSS 10. An attacker can exploit this flaw remotely over the internet without any authentication. Successful exploitation allows the attacker to access sensitive internal systems, steal confidential information, modify data, and disrupt services. The second vulnerability allows an attacker with administrator credentials to execute any command on the system, leading to complete control over the appliance.
Risk
We estimate the risk of these vulnerabilities as HIGH.
SonicWall has explicitly warned that these vulnerabilities are being actively exploited by attackers right now. The first vulnerability requires no authentication and can be exploited remotely, making it extremely easy for attackers to abuse. SMA1000 appliances are commonly used for secure remote access, meaning they are directly exposed to the internet and accessible by attackers. Organisations using these appliances are at immediate risk of compromise.
Mitigation
SonicWall has released hotfix updates that fix these vulnerabilities. Apply the latest hotfix release for your SMA1000 appliance immediately. If you cannot patch immediately, consider temporarily disconnecting SMA1000 appliances from the internet until patches can be applied. Review administrator accounts and access logs for any suspicious activity.What should you do?
If you use SonicWall SMA1000 appliances, treat this as urgent. Install the available hotfix updates as soon as possible - preferably within 24 hours. Check your appliances for any signs of compromise, such as unexpected administrator logins or unusual network traffic. If you need assistance identifying affected systems or applying patches, contact your IT team or Northwave immediately.
What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1]https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Op 1 september 2026 zijn kritieke kwetsbaarheden ontdekt in SonicWall SMA1000-appliances die momenteel actief worden misbruikt door aanvallers. Eén van deze kwetsbaarheden maakt een volledige compromittering van het systeem mogelijk zonder dat hiervoor enige vorm van authenticatie vereist is [1].
BeschrijvingTwee ernstige beveiligingslekken hebben invloed op SonicWall SMA1000-appliances:
- Pre-authentication Server-Side Request Forgery (SSRF) (CVE-2026-83548)
Een aanvaller kan misbruik maken van de Work Place-interface om toegang te krijgen tot interne systemen zonder een gebruikersnaam of wachtwoord nodig te hebben. Dit is mogelijk doordat het apparaat onbedoeld als proxyserver fungeert. - Post-authentication Remote Code Execution (CVE-2026-83549)
Een aanvaller met beheerdersrechten op de Appliance Management Console kan kwaadaardige commando’s injecteren die vervolgens door het systeem worden uitgevoerd.
SonicWall heeft bevestigd dat deze kwetsbaarheden al actief worden misbruikt door aanvallers in daadwerkelijke aanvallen.
Impact
Wij schatten de impact van deze kwetsbaarheden in als HOOG.
De eerste kwetsbaarheid heeft de maximale score van CVSS 10. Een aanvaller kan dit lek op afstand via internet misbruiken zonder authenticatie. Een succesvolle aanval kan leiden tot toegang tot gevoelige interne systemen, diefstal van vertrouwelijke informatie, wijziging van gegevens en verstoring van diensten. De tweede kwetsbaarheid stelt een aanvaller met beheerderstoegang in staat om willekeurige opdrachten uit te voeren op het systeem, waardoor volledige controle over de appliance kan worden verkregen.
Risico
Wij schatten het risico van deze kwetsbaarheden in als HOOG.
SonicWall heeft expliciet gewaarschuwd dat deze kwetsbaarheden momenteel actief worden misbruikt. De eerste kwetsbaarheid vereist geen authenticatie en kan op afstand worden misbruikt, wat het voor aanvallers bijzonder eenvoudig maakt om hiervan gebruik te maken. SMA1000-appliances worden veel gebruikt voor veilige externe toegang en zijn daardoor vaak rechtstreeks via internet bereikbaar. Organisaties die deze appliances gebruiken lopen hierdoor een direct risico op compromittering.
Mitigatie
SonicWall heeft hotfix-updates uitgebracht die deze kwetsbaarheden verhelpen. Installeer zo spoedig mogelijk de meest recente hotfix voor uw SMA1000-appliance. Indien directe patching niet mogelijk is, overweeg dan om de SMA1000-appliances tijdelijk van het internet los te koppelen totdat de updates kunnen worden geïnstalleerd. Controleer daarnaast beheerdersaccounts en toegangslogboeken op verdachte activiteiten.
Wat moet u doen?
Als u gebruikmaakt van SonicWall SMA1000-appliances, behandel dit bericht dan als urgent. Installeer de beschikbare hotfix-updates zo snel mogelijk, bij voorkeur binnen 24 uur. Controleer uw appliances op mogelijke tekenen van compromittering, zoals onverwachte beheerder-aanmeldingen of ongebruikelijk netwerkverkeer. Heeft u hulp nodig bij het identificeren van getroffen systemen of het implementeren van patches, neem dan direct contact op met uw IT-team of met Northwave.
Wat zal Northwave doen?
Wij blijven de ontwikkelingen rondom deze kwetsbaarheid monitoren. Indien er nieuwe kritieke informatie beschikbaar komt over deze dreiging, nemen wij contact met u op. Voor aanvullende informatie kunt u telefonisch of per e-mail contact met ons opnemen.
E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Neem dan contact op met ons Incident Response Team via: 00800 1744 0000
Disclaimer van toepassing, zie hieronder.
Bronnen
[1] ]https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016

