ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

SonicWall SMA 1000 appliances under attack via zero-day flaws

highExploit / PoC exploited in the wildimportance 80CVE-2026-83548CVE-2026-83549
AI summary · glm-5.3-flash

SonicWall confirms active exploitation of zero-day SSRF (CVE-2026-83548) and command injection (CVE-2026-83549) flaws in SMA 1000 remote access appliances.

SonicWall confirmed attackers are actively exploiting two previously undisclosed vulnerabilities in SMA 1000 SSL VPN appliances, affecting physical and virtual models 6210, 7210, and 8200v but not SMA 100 appliances or SonicWall firewalls. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionality, while CVE-2026-83549 is an OS command injection in the Appliance Management Console that can yield remote code execution under specific conditions for authenticated admins. The vendor urged immediate hotfix deployment, IoC review with technical support, and re-imaging or redeployment plus password and TOTP token resets on confirmed compromise. This is the latest in a series of zero-day attacks against SMA 1000 appliances following waves in late 2025 and June-July 2026.

  • CVE-2026-83548: pre-auth SSRF in Appliance Work Place interface, unauthenticated attackers
  • CVE-2026-83549: OS command injection in Appliance Management Console, admin-authenticated RCE
  • Affects SMA 1000 models 6210, 7210, 8200v; not SMA 100 or SonicWall firewalls
  • SonicWall urges hotfix, IoC review, re-imaging, credential and TOTP resets on compromise
  • Third zero-day wave against SMA 1000 since late 2025, following June-July 2026 attacks
VendorsSonicWall
ProductsSMA 1000

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)
Full article310 words · extracted from helpnetsecurity.com · click to collapse

Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday.

The vulnerabilities (CVE-2026-83548, CVE-2026-83549)

The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built for scale. They are used regularly by medium to large enterprises, government agencies, and managed security service providers.

CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and allows remote unauthenticated attackers “to gain unauthorized access to sensitive functionality and perform unauthorized operations.”

CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console that, in specific conditions, can be exploited by authenticated attackers with admin privileges to achieve remote code execution on unpatched appliances.

They affect both physical and virtual SMA 1000 models: 6210, 7210, and 8200v.

They don’t affect SMA 100 appliances or SonicWall firewalls.

William Perry and Adam Babis of SonicWall were credited with discovering the flaws.

What to do?

“SonicWall [Product Security Incident Response Team] has investigated a case indicating the active exploitation of the vulnerabilities,” SonicWall said, and “strongly urged” customers to implement the provided hotfix as soon as possible.

They have also been advised to contact SonicWall Technical Support for help in reviewing the system for indicators of compromise.

In case of a confirmed compromise, customers should re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset time-based one-time password (TOTP) tokens.

SonicWall SMA 1000: A recurring target

SonicWall hasn’t publicly shared a list of known indicators of compromise nor further details about the attacks.

SonicWall SMA 1000 appliances are often targeted by attackers via zero-day vulnerabilities, most recently (before these latest attacks) in June and July 2026 and late 2025.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/02/sonicwall-sma-1000-cve-2026-83548-cve-2026-83549-zero-day-attacks/