ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Hackers Chain Two New SonicWall Zero-Day Vulnerabilities

highExploit / PoC exploited in the wildimportance 78CVE-2026-83548CVE-2026-83549
AI summary · glm-5.3-flash

SonicWall warns two zero-days (CVE-2026-83548 SSRF, CVE-2026-83549 post-auth RCE) in SMA1000 appliances are being actively exploited.

A September 1 SonicWall advisory discloses actively exploited zero-days in SMA1000 appliance models 6210, 7210 and 8200v, affecting platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 and older. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF in the Appliance Work Place interface via an unintended alternate access path; CVE-2026-83549 (CVSS 7.8) is post-authentication OS command injection enabling RCE in the Appliance Management Console. SonicWall urges hotfix upgrades, IOC checks with SonicWall support, and re-imaging plus credential and TOTP resets if compromise is found.

  • Pre-auth SSRF allows unauthenticated unauthorized access to sensitive functionality
  • Post-auth RCE requires administrator-level authentication but yields arbitrary OS command execution
  • SMA1000 edge appliances are frequent targets of state-sponsored and ransomware actors
  • Guidance: upgrade hotfixes, hunt IOCs, re-image/redeploy, change all passwords, reset TOTP tokens
VendorsSonicWall
ProductsSMA1000

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)
Full article339 words · extracted from infosecurity-magazine.com · click to collapse

SonicWall has notified customers of two new zero-day vulnerabilities that are being exploited in the wild, one of which is a maximum-severity flaw.

A security advisory published by the vendor on September 1 revealed that the bugs affect SMA1000 appliances, specifically models 6210, 7210 and 8200v.

Impacted versions are 12.4.3-03453 (platform-hotfix) and older, and 12.5.0-02835 (platform-hotfix) and older.

The SMA or Secure Mobile Access appliances are gateway devices designed to enable remote workers to securely connect to corporate networks.

Read more on SonicWall SMA appliances: SonicWall Probes Attack Using Zero-Days in Own Products.

The more critical of the two zero days is CVE-2026-83548: a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface.

It exists due to an “unintended alternate access path,” SonicWall said in its advisory. “A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations,” it added.

The flaw has a CVSS score of 10.0.

The second zero day is CVE-2026-83549: a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console, which has a CVSS score of 7.8.

It’s described as a “post-authentication improper neutralization of special elements used in an OS command” which “in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.”

Remediation Guidance for SonicWall Customers

SonicWall urged customers to take action, whether they’re running virtual or physical SMA1000 appliances.

It said they should:

Upgrade to the latest hotfix version

Contact SonicWall Technical Support for assistance in looking for indicators of compromise (IoCs)

If IOCs are detected on the system: re-image hardware or re-deploy appliances, change all user and admin passwords, and reset TOTP tokens

SonicWall SMA1000 appliances are popular targets for state-sponsored and ransomware actors because, as edge devices, they provide remote access to sensitive corporate resources.

Security agencies regularly warn of threats to these devices. In February 2025, Five Eyes agencies published guidance for manufacturers of edge devices designed to improve baseline security.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/hackers-chain-sonicwall-zeroday/