The Third Time
THE THIRD TIME
SonicWall's SMA1000 appliances are being exploited in the wild. Again. This is the third time in recent months that these enterprise VPN/SSL appliances have been compromised – the MFA seeds stolen in July are still out there, outlasting the patches rolled out in September.
CVE-2026-83548 (CVSS 10.0) is an unauthenticated server-side request forgery vulnerability in the SMA1000 WorkPlace interface. The /wsproxy endpoint accepts attacker-supplied destination host and port parameters without authentication, backend whitelist enforcement, or origin validation. The appliance becomes a forward proxy to reach services designed to be reachable only from localhost.
CVE-2026-83549 (CVSS 7.8) is an OS command injection flaw in the Appliance Management Console. An attacker authenticated as an administrator can execute arbitrary OS commands.
Chain them: the SSRF bypasses authentication to reach the AMC endpoint, which executes arbitrary commands. Unauthenticated RCE with root-level access from a single HTTP request. SonicWall confirmed active exploitation on September 2, 2026.
What SonicWall shipped: A forward proxy to the internet with no access controls. The WorkPlace interface was designed without an authentication requirement, without whitelist enforcement, and without origin validation on proxy parameters. The AMC command injection meant an authenticated admin path could be reached via SSRF. These aren't edge-case bugs – this is a design that never asked whether the /wsproxy endpoint should be reachable without credentials.
This is the third compromise. MFA seeds were stolen from SMA1000 appliances in July 2026. Those credentials outlasted September's patches because the seeds themselves – the shared secrets used to generate time-based one-time passwords – were exfiltrated. Patching the appliance doesn't revoke the seeds. Every organization running SMA1000 needed to regenerate and re-enroll every MFA token. That didn't happen everywhere, which means the July compromise is still active.
Then this. Two zero-days chained for unauthenticated RCE, exploitation confirmed in the wild before patches were available, and the appliances themselves sit at the perimeter protecting critical infrastructure.
The point of failure: SonicWall is a security vendor. These appliances are sold to protect enterprise networks. The /wsproxy flaw – accepting attacker-controlled proxy parameters without authentication – is the kind of mistake you catch in threat modeling before the product ships. The command injection in AMC is a twenty-year-old vulnerability class. These aren't sophisticated attacks exploiting subtle race conditions or memory-safety edge cases. This is "we didn't ask whether this endpoint should require authentication" and "we didn't validate input before passing it to a shell."
Organizations running SMA1000 appliances are facing their third patching cycle in three months, and this time the window between disclosure and exploitation was zero – the vulnerabilities were being exploited in the wild when SonicWall confirmed them. Federal agencies have until September 9, 2026 to remediate per CISA's KEV catalog addition (CVE-2026-83548 and CVE-2026-83549 were added September 2).
What this costs: Incident response. Threat hunting to determine whether the July MFA seeds are still being used. Forensics to see if the September zero-days were exploited before patches landed. Re-enrollment of every MFA token if that wasn't done in July. And the operational risk of pulling perimeter appliances offline to patch them during active exploitation.
SonicWall has a problem. Three compromises in three months, two of them zero-days, one of them credential theft that survives patching. That's not bad luck. That's a security posture problem in a company whose product is security.
The appliances protecting your network shouldn't be the appliances attackers are lining up to exploit.