Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall patches two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 VPN appliances, likely chained for code execution.
SonicWall fixed CVE-2026-83548 (CVSS 10.0), a pre-authentication SSRF in the Appliance Work Place interface, and CVE-2026-83549 (CVSS 7.8), a post-authentication OS command injection in the Appliance Management Console. The company investigated a case indicating active exploitation, suggesting attackers chained both bugs to execute arbitrary code on susceptible devices. Affected SMA 1000 models 6210, 7210, and 8200v require hotfixes 12.4.3-03526 or 12.5.0-02952; customers are urged to hunt for IoCs and re-image, reset credentials, and rotate TOTP if found.
- CVE-2026-83548 (CVSS 10.0): pre-auth SSRF enabling unauthorized access to sensitive functionality.
- CVE-2026-83549 (CVSS 7.8): authenticated admin command injection leading to remote code execution.
- SonicWall confirmed active exploitation, possibly chaining both flaws; threat actor still unidentified.
- Fixes shipped in 12.4.3-03526 and 12.5.0-02952 platform hotfixes.
- Follows August fixes for CVE-2026-15409/15410 abused by UTA0533 to deploy KNUCKLEBALL malware.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15409 +1 in the same advisory: …15410 | Unauthenticated SSRF in SonicWall SMA1000 Appliances CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available. Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable. | 10.0 group max | 85% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed appliances (estimate) | |
| CVE-2026-83548 +1 in the same advisory: …83549 | Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known. Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated. | 10.0 group max | 5% | KEV |
| moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate) |
Full article322 words · extracted from thehackernews.com · click to collapse

Ravie Lakshmanan Sep 02, 2026 Vulnerability / Network Security
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks.
The vulnerabilities , discovered internally by SonicWall's William Perry and Adam Babis, are listed below -
CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.
CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution.
SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices.
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions -
12.4.3-03453 (platform-hotfix) and older versions
12.5.0-02835 (platform-hotfix) and older versions
Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers perform the actions outlined below -
Upgrade to the latest hotfix version
Review the system for indicators of compromise (IoCs)
If IoCs are found, re-image or re-deploy the appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP)
SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The development comes more than a month after it shipped fixes to address two other flaws in the same product – CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) – that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware.
Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html