ZeroHour
Security Affairspublished ()ingested @securityaffairs1

SonicWall Patches Two New Actively Exploited Zero

AI summary · glm-5.3-flash

SonicWall patches two actively exploited SMA 1000 VPN zero-days: CVSS 10.0 pre-auth SSRF CVE-2026-83548 and post-auth command injection CVE-2026-83549, chained for RCE.

SonicWall released hotfixes for two zero-day vulnerabilities in its SMA 1000 VPN appliances, with SonicWall PSIRT confirming active exploitation in the wild. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF in the Appliance Work Place interface allowing unauthenticated unauthorized operations; CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection in the Appliance Management Console enabling arbitrary command execution and RCE. The flaws affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier, fixed in versions 12.4.3-03526 and 12.5.0-02952. This follows a July Volexity report on threat actor UTA0533 chaining two SMA 1000 zero-days to gain root access and deploy the KNUCKLEBALL Python backdoor.

  • CVE-2026-83548: CVSS 10.0 pre-auth SSRF in Appliance Work Place interface enabling unauthenticated unauthorized operations.
  • CVE-2026-83549: CVSS 7.8 post-auth OS command injection in Appliance Management Console enabling arbitrary command execution.
  • SonicWall says attackers likely chain both flaws to achieve arbitrary code execution on vulnerable appliances.
  • Affects models 6210, 7210, 8200v; fixed in 12.4.3-03526 and 12.5.0-02952; re-image and reset credentials if compromised.
  • Second SMA incident in a month; Volexity's UTA0533 previously chained zero-days to deploy the KNUCKLEBALL backdoor.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15409
+1 in the same advisory: …15410
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.0
group max
85% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)
Full article395 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 02, 2026

SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation.

SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild.

  • CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthorized operations.
  • CVE-2026-83549 (CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). A remote attacker authenticated as an administrator could exploit it under specific conditions to execute arbitrary commands and achieve remote code execution. SonicWall’s investigation suggests attackers may be chaining the two flaws to compromise vulnerable appliances.

SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that the two SMA 1000 flaws are being exploited in the wild, with attackers likely chaining them to achive arbitrary code execution.

“SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.” reads the advisory.

The vulnerabilities affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier. 12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.

SonicWall recommends that customers first install the latest hotfix and check their systems for any signs of compromise. If they find indicators of compromise, they should re-image or redeploy the affected appliances, change all user and administrator passwords, and reset their time-based one-time passwords (TOTP).

SonicWall hasn’t disclosed technical details of the attack or said who is behind them. This is also the second recent security incident affecting the SMA product line in a month, recently the company patched two other flaws, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2).

In July, Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities to achieve root-level access on the devices before patches existed.

UTA0533 had exploited to deploy a malicious Python script named KNUCKLEBALL.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SMA 1000)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/198303/security/sonicwall-patches-two-new-actively-exploited-zero-days-in-sma-1000-vpns.html