Severity Daily

IT and AI security incidents, checked against the primary source

Tag: SonicWall

  • Four deadlines expire Saturday, which is why the day’s four fresh 9.8s are not the lead

    Four deadlines expire Saturday, which is why the day’s four fresh 9.8s are not the lead

    Four items published today carry a federal remediation deadline of Saturday, September 5. That is two days out, and it is the day’s lead. It outranks the four fresh 9.8s that landed alongside it, because a 9.8 with no confirmed exploitation and no clock attached is a patch you schedule, and a Saturday deadline is a patch somebody has to be at a keyboard for. Two of those 9.8s do not have a release number to install anyway.

    The thread is real, and it is CISA’s. Six of today’s ten stories trace back to one batch of Known Exploited Vulnerabilities additions made on September 2 — four due September 5, two due September 16. Running underneath it is the same problem in three of the four Saturday items: the authoritative record does not cleanly say what to install.

    Deal with SonicWall’s SMA1000 pair first. It is an internet-facing access appliance, it is the third zero-day pair on that product, and the CVE records SonicWall assigned itself list affected builds without naming a fixed one — two days before the deadline. Then JFrog Artifactory, where CISA’s listing is the first government confirmation that the unauthenticated administrative bypass is being exploited, and where the medium-severity Artifactory CVE listed six days earlier is now due five days later than the critical one. Then Sangoma’s Switchvox, where the release notes mark the fix for both cloud and on-premises but the only CPE on the record covers on-premises, so an agency running the cloud edition cannot tell from the record whether it is in scope. Then Kestra, the one of the four whose difficulty is a label rather than a version: CISA files it as OS command injection, and what an attacker actually reaches is a filter asking whether a request path ends with the word configs.

    The two September 16 items are lower on the clock and higher on reach. Starlette’s BadHost is a 6.5 by three independent scorers, which is the number most likely to send a KEV entry to the bottom of a patch queue — and Starlette is what FastAPI is built on, so the inventory question is not “do we run Starlette” but “what did we build on FastAPI.” LiteLLM is the narrower one, and the sharper bug: the MCP endpoint answered a failed key check by substituting an empty authorization object and letting the request through.

    After the clocked items, the 9.8s. Cisco’s Nexus 9000 Silicon One root RCE names ten switch SKUs and points its Fixed Software section at an interactive tool instead of a release number; the record has no CPE data at all. Cisco’s IOS XR hardening release, published the same afternoon, packages an internal audit into seven CVEs across every release, two of them 9.8, with one CVE ID standing for thirteen distinct weakness types. That is Cisco twice in one day, both times with a remediation story that is harder to read than the vulnerability. Delinea’s Secret Server takes a 9.8 at the FIDO2 registration step in a privileged access manager, and NVD deferred the record the following day, leaving it with no machine-matchable version data. And thirteen Craft CMS CVEs arrived from two CNAs, neither of them Craft, onto advisories that say “No known CVE” — with one advisory drawing two IDs and one record carrying a description for a different bug.

    What is still open. SonicWall has not named a fixed build for either SMA1000 CVE with the deadline on Saturday. JFrog has published no in-the-wild statement of its own; the government confirmed exploitation before the vendor did. Sangoma has not resolved the cloud-versus-on-premises scope on the record itself. Cisco’s first IOS XR fix that is not a software maintenance update has not shipped, and it revised the fixed-release list within six hours of publishing it. The Delinea record is deferred, so scanners matching on CPE will not flag an affected install.

  • SonicWall’s third SMA1000 zero-day pair draws a September 5 federal deadline, and its own CVE records name no fixed version

    SonicWall’s third SMA1000 zero-day pair draws a September 5 federal deadline, and its own CVE records name no fixed version

    CISA added both SMA1000 flaws to the Known Exploited Vulnerabilities catalog on September 2, 2026 with a September 5 remediation deadline, and the CVE records SonicWall assigned itself list affected builds without naming a fixed one.

    What happened

    SonicWall published two CVEs for its SMA1000 secure access appliances on September 1, 2026, and CISA added both to the Known Exploited Vulnerabilities catalog the following day. NVD’s records carry CISA’s own fields verbatim: cisaExploitAdd of 2026-09-02 and cisaActionDue of 2026-09-05 on each. That is a three-day federal clock, and it expires this Saturday.

    The first, CVE-2026-83548, is scored 10.0. SonicWall’s own description is short: “A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.” The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — network reachable, no privileges, no user interaction, and a changed scope, which is what carries it to a perfect ten. The record is classified CWE-918 for the request forgery and CWE-441, confused deputy, for the access path itself. CISA catalogs it as “SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability.” The finder credited on the record is Adam Babis of SonicWall PSIRT.

    The second, CVE-2026-83549, is scored 7.8 and sits in the Appliance Management Console rather than the user-facing Work Place. SonicWall describes it as a “Post-authentication Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability … which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.”

    Read on its own, that second record does not look like a three-day emergency. Its vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. AV:L means local attack vector. PR:L means low privileges required. But the prose in the same record says “remote” and says “as administrator.” The vendor’s sentence and the vendor’s vector, on one record, describe two different attacks. Neither NVD nor CISA reconciles them; both simply republish what the CNA supplied.

    The two records together do resolve into something coherent. A pre-authentication request forgery with a changed scope in the Work Place interface is a way to reach things the appliance can reach but you cannot. An administrator-context command injection in the management console is a way to run code once you are there. That is a chain, and CISA’s decision to add both on the same day under the same deadline is consistent with the pair being used together rather than each being used alone.

    The remediation action CISA attached to both is its current standard text: “Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk guidance and CISA’s ‘Forensics Triage Requirements’.” That last clause is not decoration. BOD 26-04’s three-day band includes entries that carry an additional obligation, and the directive states it plainly: “The text ‘& forensic triage’ means that the agency must complete remediation or mitigation action within the timeline (three days) and carry out a forensic triage of the asset to assess whether the system is compromised.” Patching is half of what is being asked here.

    Why it matters

    The version ranges are the part worth sitting with. SonicWall’s CNA record lists the affected builds for the September pair as “12.4.3-03453 (platform-hotfix) and older” and “12.5.0-02835 (platform-hotfix) and older.” In July, the same appliance line took a nearly identical pair: CVE-2026-15409, also a pre-authentication SSRF in the Work Place interface, also scored 10.0 on an identical vector, added to KEV on July 14, 2026 with a cisaActionDue of 2026-07-17 — also three days. That record’s affected ranges topped out at 12.4.3-03434 and 12.5.0-02800.

    Compare the ceilings. July’s affected range ended at build 03434. September’s affected range includes everything up to and including 03453. An administrator who did exactly what the July advisory asked — moved past 03434 onto a later build — landed inside the range that the September advisory now calls vulnerable. The remediation was real and the exposure returned anyway, in the same interface, with the same root class of flaw, seven weeks later.

    This is the third round in nine months for this product line. It is worth being precise about what is and is not established across those rounds. The July pair was attributed by Volexity to an actor it tracks as UTA0533, with a named malware set; that attribution belongs to July and to Volexity, and nothing published so far ties the September pair to the same actor. Trade coverage of the September round also reports that attackers in the earlier intrusions extracted TOTP seed material, and that SonicWall’s guidance advised log review and reimaging rather than patching alone. We could not read SonicWall’s advisory page to confirm that language, and we are not treating it as confirmed. The reason to mention it is that it explains why CISA’s forensic-triage clause is attached rather than a bare patch instruction: on an appliance that terminates remote access, the question of whether the box was already used is separate from the question of whether the hole is closed.

    The second thing worth noting is where the fixed build number lives. Both NVD records point at one authoritative vendor source, SNWLID-2026-0016 on SonicWall’s PSIRT portal. That page returns a document containing a title and no advisory body; the content is assembled by JavaScript after load. Automated tooling — and any reader without a browser — gets nothing from it. SonicWall’s own CVE records, which are machine-readable and which the company controls, list the affected versions and carry no fixed-version field at all. The result is that the build numbers an administrator needs on a three-day clock reach them through third-party transcription. Beazley Security’s advisory gives them as 12.4.3-03526 and 12.5.0-02952. That is very probably right. It is also a security firm reading a vendor’s rendered web page on the vendor’s behalf, which is not where a remediation deadline should get its version numbers.

    Correction, September 3, 2026, 4:10 p.m. CT: The paragraph above is wrong on its central point. SonicWall does publish the fixed builds in a document a non-browser client can read — a product notice carrying the same SNWLID-2026-0016 identifier at sonicwall.com/support/notices/, distinct from the psirt.global.sonicwall.com page the CVE records name as the authoritative reference. That notice, dated September 1, 2026, lists 12.4.3-03526 and 12.5.0-02952 as the remediation builds. The build numbers therefore do not reach administrators only through third-party transcription, and Beazley Security’s advisory agrees with the vendor rather than standing in for it. What remains accurate: SonicWall’s CVE records still carry no fixed-version field, and the reference those records point to is the page that does not render. The same notice also confirms in SonicWall’s own words the guidance this story treated as unverified trade coverage: “Contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IoCs). If IoCs are detected: Re-image (hardware) or re-deploy (virtual) appliances. Change all user and administrator passwords. Reset TOTP tokens.”

    This publication has now seen the same shape three times in a week: HPE’s Aruba bulletin, whose fixed-version page did not render; Amelia’s changelog, which described a critical fix as routine; and now a vendor whose structured record omits the one field that closes the deadline. The fix keeps arriving before the record of it does.

    What to do

    Identify SMA1000 6210, 7210, and 8200v appliances and read the platform-hotfix build, not the marketing version. If it is at or below 12.4.3-03453 or 12.5.0-02835, it is in the affected range on SonicWall’s own record. Move to 12.4.3-03526 or 12.5.0-02952. [Corrected September 3, 2026: these builds are confirmed against SonicWall’s own product notice for SNWLID-2026-0016 at sonicwall.com/support/notices/. The original sentence here told readers to verify them in a browser because we believed only a third-party transcription existed. That was wrong.]

    Federal agencies are past the point where patching alone satisfies the requirement. The required action names forensic triage; plan for the asset assessment alongside the upgrade, not after it.

    Everyone else should treat the appliance as a candidate for review rather than a box that is now fine. Pull Work Place and management console logs back through June and look for requests that reached internal addresses the appliance should never have contacted, and for administrative sessions that do not match a known change. If you find evidence of pre-patch access, reissue MFA enrollment rather than resetting passwords: a rotated password invalidates a stolen password, and neither invalidates a stolen seed.

    Sourcing note

    KEV dates for CVE-2026-83548, CVE-2026-83549, and CVE-2026-15409 were taken from NVD’s API records, which republish CISA’s cisaExploitAdd, cisaActionDue, cisaVulnerabilityName, and cisaRequiredAction fields verbatim. Affected version ranges, CVSS vectors, descriptions, and the finder credit come from SonicWall’s CNA records retrieved from the CVE Program API — SonicWall is the assigner for all of these, so that is the vendor’s own text.

    [Corrected September 3, 2026: we could not read the psirt.global.sonicwall.com vulnerability-detail page for SNWLID-2026-0016, which returns no advisory body without JavaScript execution and which this newsroom does not execute scripts for. We did not find, and should have found, SonicWall’s product notice for the same advisory ID on sonicwall.com, which renders as static HTML and carries the fixed builds, the CVSS scores, and the IoC and TOTP guidance. It was retrieved twice on September 3, 2026 with different prompts and returned the same values both times. The original text of this paragraph follows.] We could not read SNWLID-2026-0016 directly. The page returns no advisory body without JavaScript execution, and this newsroom does not execute page scripts. CISA’s own alert page and KEV catalog feed both return HTTP 403 to automated requests, so the catalog was reached through NVD rather than directly; that is NIST republishing CISA and is a government primary source, but it lags the catalog by hours and is not the catalog itself. The fixed build numbers 12.4.3-03526 and 12.5.0-02952 are transcribed from Beazley Security’s advisory BSL-A1201 and are not confirmed against a SonicWall document we could read.

    The July attribution to UTA0533 is Volexity’s, reported through trade coverage, and applies to the July pair only. The TOTP seed extraction and the reimaging guidance are from trade coverage and are unconfirmed against a primary source; they are reported here as claims and were not used to establish any fact about the September pair. Unresolved: whether the internal conflict on CVE-2026-83549 between “remote … as administrator” in the description and AV:L/PR:L in the vector reflects an error in the vector or an imprecise description, and whether builds between 12.4.3-03434 and 12.4.3-03453 were ever a complete remediation for the July pair.