SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warns of actively exploited SMA1000 zero-day flaws used in RCE attacks.
Summary
SonicWall has issued a warning about two actively exploited zero-day vulnerabilities affecting its SMA1000 appliances. Threat actors are chaining these flaws, a command injection vulnerability (CVE-2026-83548) and another command injection flaw (CVE-2026-83549), to achieve remote code execution. The company urges customers to upgrade to the latest hotfix release immediately to mitigate these risks.
Full text
SonicWall warns of actively exploited SMA1000 zero-day flaws By Sergiu Gatlan September 2, 2026 02:39 AM 0 SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices. "SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory. The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain. Internet-exposed SonicWall SMA1000 appliances (Shadowserver) SonicWall urged all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version. While the company also advised admins to re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected, it has yet to share details about these ongoing attacks or a list of IOCs it has found while investigating them. Such vulnerabilities are often targeted in attacks, given that the SMA1000 is a secure remote access appliance used by large enterprises, government, and critical infrastructure organizations. In July, two other SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410) were exploited in zero-day attacks for weeks to install custom malware on vulnerable VPN appliances. Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs have begun abusing the two vulnerabilities in the wild. The company also warned customers in December to patch another SMA1000 zero-day vulnerability (CVE-2025-40602) that hackers were chaining to gain root privileges. One month earlier, SonicWall linked state-backed hackers to a September security breach that exposed customers' firewall configuration backup files after researchers warned of more than 100 SonicWall SSLVPN accounts compromised using stolen credentials. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch nowCISA: SonicWall SMA1000 flaws now exploited by ransomware gangsSonicwall warns of new SMA1000 zero-day exploited in attacksHackers breached over 270 Zimbra servers in ongoing attacksSonicWall SMA1000 flaws exploited as zero-days to push custom malware
Indicators of Compromise
- cve — CVE-2026-83548
- cve — CVE-2026-83549