THREATOPS
THREAT OPSThreat News › [0day-Rubbish] SonicWall SMA 1000 — Pre-Auth Deserialization RCE (CVSS 9.8) via Struts 1 Property Injection and Auth-Filter Rewrite

[0day-Rubbish] SonicWall SMA 1000 — Pre-Auth Deserialization RCE (CVSS 9.8) via Struts 1 Property Injection and Auth-Filter Rewrite

lowfulldisclosurePublished 2026-08-06

<p>Posted by disclosure via Fulldisclosure on Aug 06</p>Full-Disclosure List,<br /> <br /> An unauthenticated remote code execution vulnerability chain in SonicWall SMA 1000 series appliances is being disclosed <br /> here. The chain yields code execution as the `mgmt-server` user (uid=1011) on the management plane, with no credentials <br /> and no prior knowledge of the appliance beyond a reacha

MITRE ATT&CK techniques

Original source: https://seclists.org/fulldisclosure/2026/Aug/2