SonicWall SMA1000 hit by second zero-day chain in a year

SonicWall patched a fresh SMA1000 zero-day chain — a pre-auth SSRF (CVSS 10.0) feeding a post-auth command-injection bug (7.8) — that CISA added to its KEV catalog with a September 5 federal deadline. Exploitation continued even after hotfixes shipped, and defenders note the appliance's internet-…

SonicWall SMA1000 hit by second zero-day chain in a year