ZeroHour

Search: “OS Investigate”

113 stories

SonicWall's SMA1000 boxes under active attack again

SonicWall warns attackers are chaining two SMA1000 zero-days, a CVSS 10.0 SSRF and command injection, to compromise VPN gateways.

SonicWall says attackers are actively exploiting two chained zero-days in SMA 1000 appliances: CVE-2026-83548, a pre-authentication SSRF rated CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection (CVSS 7.8) in the Appliance Management Console. Hotfixes are available for SMA 6210, 7210, and 8200v appliances with no workarounds; SonicWall recommends reimaging compromised devices, rotating passwords, and resetting TOTP tokens. NHS England assesses further exploitation as almost certain, following a similar exploited pair in July when CISA added CVE-2026-15409 to its KEV catalog.

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Sansec found attackers exploiting an Adobe Commerce/Magento zero-day (StyleSmuggler) since September 4 to deploy Rust backdoors on online stores.

Threat actors are actively exploiting a zero-day RCE in Adobe Commerce and Magento 2.4.7-2.4.9, injecting PHP code via generated failure reports and executing it through Magento's payment-failure email, with no user interaction required. Exploitation began September 4 and succeeds even against stores running the July and August 2026 patches; the Rust backdoor disguises itself as kworker/u:8:0 or fc-cache and hides C&C communication inside fake NTP replies. Adobe's September 8 Patch Tuesday updates may not include a StyleSmuggler fix.

SecurityWeek · 8d agoExploit / PoC in the wild

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall confirms active exploitation of zero-day SSRF (CVE-2026-83548) and command injection (CVE-2026-83549) flaws in SMA 1000 remote access appliances.

SonicWall confirmed attackers are actively exploiting two previously undisclosed vulnerabilities in SMA 1000 SSL VPN appliances, affecting physical and virtual models 6210, 7210, and 8200v but not SMA 100 appliances or SonicWall firewalls. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionality, while CVE-2026-83549 is an OS command injection in the Appliance Management Console that can yield remote code execution under specific conditions for authenticated admins. The vendor urged immediate hotfix deployment, IoC review with technical support, and re-imaging or redeployment plus password and TOTP token resets on confirmed compromise. This is the latest in a series of zero-day attacks against SMA 1000 appliances following waves in late 2025 and June-July 2026.

Help Net Security · 14d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549