Skip to content

Active exploitation hits SonicWall SMA1000 vulnerability chain with unauthenticated RCE path

Share
Source: Badtech.org

Active exploitation is targeting SonicWall SMA1000 appliances through CVE-2026-83548 and CVE-2026-83549, a pre-authentication SSRF flaw and a post-authentication OS command-injection flaw that can be chained to reach unauthenticated remote code execution. Affected models are SMA 6210, SMA 7210 and SMA 8200v on 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier; fixed builds are 12.4.3-03526 and 12.5.0-02952 or later.

These are SonicWall Secure Mobile Access appliances used for enterprise remote access. SonicWall SMA 100 appliances and SSL-VPN functionality on SonicWall firewalls are outside this advisory’s scope.

For exposed affected systems, the supplied guidance is to identify internet-facing appliances, preserve relevant logs, apply the fixed builds, and investigate for compromise rather than treating patching as sufficient closure. If compromise is confirmed or indicators are found, response guidance includes re-imaging physical appliances or redeploying virtual ones, changing user and administrator passwords, and resetting TOTP tokens.

Sources

Read more

Oracle August 2026 CPU ships 943 patches, including critical unauthenticated flaws in Fusion Middlew

Oracle released its August 2026 Critical Security Patch Update on August 18 with 943 new patches across its enterprise software portfolio, including 262 for Fusion Middleware, 120 for E-Business Suite, and 66 for Commerce. Covered products include WebLogic Server, PeopleSoft Enterprise PeopleTools, Oracle Internet Directory, Oracle Identity Manager, WebCenter,

By Adam Field Source: Badtech.org

Microsoft August Patch Tuesday includes exploited Windows privilege-escalation flaw and two publicly

Microsoft’s August 11 Patch Tuesday addressed hundreds of vulnerabilities across Windows, Office, Azure, Exchange Server, SharePoint, .NET, Teams, and other products. Qualys ThreatPROTECT and CyberHub Podcast counted 421 fixes, while other supplied coverage reported lower totals, with the difference attributed to counting method or update scope. The most urgent

By Adam Field Source: Badtech.org