Yesterday, CISA announced that they had added two vulnerabilities in the SonicWall SMA1000 appliances to their Known Exploited Vulnerabilities Catalog (KEV):
- Server-side request forgery - CVE-2026-83548, and
- OS command injection - CVE-2026-83549.
SonicWall published their initial advisory for both vulnerabilities yesterday, noting that they were discovered internally and reporting that their “PSIRT has investigated a case indicating the active exploitation of the vulnerabilities”. A hotfix is available that mitigates the two vulnerabilities.
CISA has directed federal agencies to apply “mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s “Forensics Triage Requirements” [links added]. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable.” CISA has established a compliance date of September 5th, 2026.
No comments:
Post a Comment