{"id":5354,"date":"2026-09-29T21:58:00","date_gmt":"2026-09-29T21:58:00","guid":{"rendered":"https:\/\/netguide.io\/news\/2026\/09\/29\/sonicwall-sma-1000-deux-jours-zeros-exploites-activement-permettent-un-rce-non-authentifie\/"},"modified":"2026-09-29T21:58:00","modified_gmt":"2026-09-29T21:58:00","slug":"sonicwall-sma-1000-deux-jours-zeros-exploites-activement-permettent-un-rce-non-authentifie","status":"publish","type":"post","link":"https:\/\/netguide.io\/news\/fr\/2026\/09\/29\/sonicwall-sma-1000-deux-jours-zeros-exploites-activement-permettent-un-rce-non-authentifie\/","title":{"rendered":"SonicWall SMA 1000: Deux jours z\u00e9ros exploit\u00e9s activement permettent un RCE non authentifi\u00e9"},"content":{"rendered":"<div id=\"netgu-3668554800\" class=\"netgu-before-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"3494115342\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p class=\"wp-block-paragraph\"><strong>Le 1er septembre 2026, SonicWall a r\u00e9v\u00e9l\u00e9 deux vuln\u00e9rabilit\u00e9s dans ses appareils SMA 1000 que le vendeur dit \u00eatre d\u00e9j\u00e0 activement exploit\u00e9. Encha\u00een\u00e9s ensemble, ils donnent une ex\u00e9cution de code \u00e0 distance non authentifi\u00e9e \u2013 acc\u00e8s complet \u00e0 la passerelle VPN sans identifiants valides.<\/strong><\/p>\n\n<h3 class=\"wp-block-heading\">Les deux d\u00e9fauts en d\u00e9tail<\/h3>\n\n<p class=\"wp-block-paragraph\"><strong>CVE-2026-83548<\/strong> Il s&#8217;agit d&#8217;une forgerie pr\u00e9-auth Server-Side Request (SSRF) dans l&#8217;interface &#8220;Work Place&#8221;, avec la cote CVSS 10.0 maximale. Il permet aux attaquants non authentifi\u00e9s d&#8217;atteindre des fonctionnalit\u00e9s sensibles. <strong>CVE-2026-83549<\/strong> (CVSS 7.8), une injection de commande OS dans la console de gestion des appareils (AMC) qu&#8217;un attaquant authentifi\u00e9 en tant qu&#8217;administrateur peut abuser pour ex\u00e9cuter des commandes syst\u00e8me arbitraires. Combin\u00e9s, ils contournent l&#8217;authentification et activent le RCE non authentifi\u00e9. En tant que VPN et passerelles d&#8217;acc\u00e8s, les appareils SMA 1000 sont g\u00e9n\u00e9ralement expos\u00e9s directement \u00e0 Internet, ce qui rend le compromis particuli\u00e8rement s\u00e9rieux : celui qui contr\u00f4le l&#8217;appareil se trouve au p\u00e9rim\u00e8tre du r\u00e9seau d&#8217;entreprise.<\/p><div id=\"netgu-1790688965\" class=\"netgu-content netgu-entity-placement\"><aside class=\"deals-top deals-top--compact\">\n\n\t\t\t<h3 class=\"deals-top__title\">Top-Deals<\/h3>\n\t\n\t\t\t<ul class=\"deals-top__list\">\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/moon-knight-digital-watch-face-fuer-wear-os-4\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/deal-27-150x150.png\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">MOON KNIGHT Digital Watch Face f\u00fcr Wear OS 4+<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>0.89 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-100%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t55\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/train-sim-world-7-starter-pack-kostenlos-fuer-ps4-ps5-xbox-pc\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/capsule_616x353-11-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Train Sim World 7: Starter Pack kostenlos f\u00fcr PS4, PS5, Xbox, PC<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t55\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/ml2u-watchfaces-fuer-wearos-im-google-play-store-2\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2844734_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">ML2U Watchfaces f\u00fcr WearOS im Google Play Store<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<s>1.39 \u20ac<\/s>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-discount\">-100%<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/kostenloses-dlc-bundle-fuer-gears-of-war-e-day-liquid-death-bundle\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/2844571_1-150x150.webp\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Kostenloses DLC-Bundle f\u00fcr Gears of War E-Day \u2013 Liquid Death Bundle<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t\t\t<li class=\"deals-top__item\">\n\t\t\t\t\t<a class=\"deals-top__link\" href=\"https:\/\/netguide.io\/deals\/de\/deals\/kostenlose-emote-im-clash-royale-store\/\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<img class=\"deals-top__image\" src=\"https:\/\/netguide.io\/news\/wp-content\/uploads\/sites\/15\/2026\/09\/share-image-clashroyale-150x150.jpg\" alt=\"\" width=\"52\" height=\"52\" loading=\"lazy\" \/>\n\t\t\t\t\t\t\n\t\t\t\t\t\t<span class=\"deals-top__body\">\n\t\t\t\t\t\t\t<span class=\"deals-top__name\">Kostenlose Emote im Clash Royale-Store<\/span>\n\n\t\t\t\t\t\t\t<span class=\"deals-top__meta\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"deals-top__price\">Gratis<\/span>\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t<\/span>\n\n\t\t\t\t\t\t<span class=\"deals-top__temperature\">\n\t\t\t\t\t\t\t54\u00b0\n\t\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/li>\n\t\t\t\t\t<\/ul>\n\n\t\t\t\t\t<p class=\"deals-top__more\">\n\t\t\t\t<a href=\"https:\/\/netguide.io\/deals\/\">Alle Deals ansehen \u2192<\/a>\n\t\t\t<\/p>\n\t\t\t<\/aside>\n<\/div>\n\n<h3 class=\"wp-block-heading\">Versions touch\u00e9es et corrig\u00e9es<\/h3>\n\n<ul class=\"wp-block-list\"><li><strong>Affect\u00e9s :<\/strong> SMA 1000 mod\u00e8les 6210, 7210 et 8200v sur micrologiciel 12.4.3-03453 ou 12.5.0-02835 et pr\u00e9c\u00e9dents<\/li><li><strong>Re\u00e7u :<\/strong> Fixe \u00e0 chaud 12.4.3-03526 ou 12.5.0-02952 et plus<\/li><li>Non affect\u00e9 : la s\u00e9rie SMA 100 et SSL-VPN sur les pare-feu SonicWall<\/li><li><strong>\u00c0 faire :<\/strong> Mettre \u00e0 jour le hotfix imm\u00e9diatement, garder l&#8217;AMC hors de l&#8217;Internet public, examiner les journaux pour le compromis<\/li><\/ul>\n\n<h3 class=\"wp-block-heading\">Exploitation active confirm\u00e9e<\/h3>\n\n<p class=\"wp-block-paragraph\">Le PSIRT de SonicWall d\u00e9clare avoir enqu\u00eat\u00e9 sur un cas d&#8217;exploitation active et exhorte les clients \u00e0 le mettre \u00e0 jour imm\u00e9diatement. La CISA a ajout\u00e9 les deux CVE \u00e0 son catalogue de vuln\u00e9rabilit\u00e9s exploit\u00e9es le 3 septembre 2026. Remarque : cet incident n&#8217;est pas le m\u00eame que dans l&#8217;affaire ant\u00e9rieure de juillet (CVE-2026-15409\/154010). Parce que SonicWall n&#8217;a pas publi\u00e9 d&#8217;indicateurs de compromis (IoCs), les op\u00e9rateurs devraient assumer un \u00e9ventuel compromis pr\u00e9alable apr\u00e8s patching et r\u00e9initialiser les identifiants et les sessions actives.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Sources :<\/strong> <a href=\"https:\/\/psirt.global.sonicwall.com\/vuln-detail\/SNWLID-2026-0016\" rel=\"noopener\" target=\"_blank\">(SNWLID-2026-0016)<\/a> \u00b7 <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws\/\" rel=\"noopener\" target=\"_blank\">Calculateur<\/a> \u00b7 <a href=\"https:\/\/thehackernews.com\/2026\/09\/attackers-exploit-two-sonicwall-sma.html\" rel=\"noopener\" target=\"_blank\">Les nouvelles Hacker<\/a> \u00b7 <a href=\"https:\/\/www.securityweek.com\/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks\/\" rel=\"noopener\" target=\"_blank\">Semaine de la s\u00e9curit\u00e9<\/a><\/p><div id=\"netgu-64923490\" class=\"netgu-after-content netgu-entity-placement\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-6258556257245998\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-6258556257245998\" \ndata-ad-slot=\"4559785002\" \ndata-ad-format=\"auto\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>SonicWall met en garde contre deux d\u00e9fauts dans ses appareils SMA 1000 qui, lorsqu&#8217;ils sont encha\u00een\u00e9s, permettent une ex\u00e9cution de code non authentifi\u00e9e. Le fournisseur confirme les attaques actives \u2013 patch maintenant.<\/p>\n","protected":false},"author":1,"featured_media":1722,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[],"tags":[],"class_list":["post-5354","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/5354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/comments?post=5354"}],"version-history":[{"count":1,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/5354\/revisions"}],"predecessor-version":[{"id":5355,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/posts\/5354\/revisions\/5355"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media\/1722"}],"wp:attachment":[{"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/media?parent=5354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/categories?post=5354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/netguide.io\/news\/wp-json\/wp\/v2\/tags?post=5354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}