Back to Feed
Zero-daySep 2, 2026

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall releases fixes for two chained zero-day flaws in SMA 1000 VPN appliances under active exploitation.

Summary

SonicWall has patched two critical zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its Secure Mobile Access (SMA) 1000 series VPN appliances that are being actively exploited in coordinated attacks. The pre-authentication SSRF flaw (CVSS 10.0) chains with a post-authentication command injection vulnerability (CVSS 7.8) to enable unauthenticated remote code execution. The company recommends immediate upgrades to patched versions 12.4.3-03526 or 12.5.0-02952, system reviews for indicators of compromise, and credential resets.

Full text

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain Ravie LakshmananSep 02, 2026Vulnerability / Network Security SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution. SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices. The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions - 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers perform the actions outlined below - Upgrade to the latest hotfix version Review the system for indicators of compromise (IoCs) If IoCs are found, re-image or re-deploy the appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The development comes more than a month after it shipped fixes to address two other flaws in the same product – CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) – that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  network security, Vulnerability, Zero-Day ⚡ Top Stories This Week Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account ⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication Learn How to Build Security Operations Ready for AI-Powered Attacks Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Frontier AI: Vulnerability Management's Systemic Revolution Why AI Teams Need Verifiable Search Data Instead of Black-Box Signals Why Threat Intelligence Needs OT Context to Protect Critical Infrastructure ⭐ Featured Resources See How Keeper Secrets Manager Removes Hard-Coded Credentials Download the CISO's Guide to Smarter AI Security Investment Phishing Is Costing Security Teams More Than Ever — Read the New Report Build AI Agents and Automations Without Losing Security Control

Indicators of Compromise

  • cve — CVE-2026-83548
  • cve — CVE-2026-83549
  • cve — CVE-2026-15409
  • cve — CVE-2026-15410
  • malware — KNUCKLEBALL

Entities

SonicWall (vendor)Secure Mobile Access (SMA) 1000 (product)UTA0533 (threat_actor)