ZeroHour
Story · 1 source · 1 articlefirst updated ()

SonicWall patches two actively exploited SMA 1000 zero-days (CVE-2026-83548, CVE-2026-83549) chained to unauthenticated RCE; CISA adds both to KEV with September 5 deadline

What's new: First consolidated summary of this story; no previous merged summary exists. All items below are new in this reporting window (September 2-3, 2026).
Merged summary · glm-5.3-flash · rewritten as coverage arrives

SonicWall patched two actively exploited zero-days in SMA 1000 VPN appliances: CVE-2026-83548 (CVSS 10.0, pre-authentication SSRF in the Appliance Work Place interface) and CVE-2026-83549 (CVSS 7.8, post-authentication OS command injection in the Appliance…

SonicWall disclosed on September 1, 2026 (date per Rapid7) and patched two zero-day vulnerabilities in its SMA 1000 secure access appliances: CVE-2026-83548, a critical (CVSS 10.0) pre-authentication SSRF in the Appliance Work Place interface that The Register describes as arising from an unintended alternative access path, and CVE-2026-83549, a high (CVSS 7.8) post-authentication OS command injection in the Appliance Management Console. SonicWall confirmed both flaws are being actively exploited and said its investigation of one case indicates attackers chain the two bugs to execute arbitrary code; Rapid7 assessed that chaining yields unauthenticated remote code execution on internet-exposed edge appliances, with exploitation occurring before public disclosure. The threat actor has not been identified, and CyberScoop reported the vendor published no indicators of compromise or victim counts. Affected devices are SMA 1000 models 6210, 7210, and 8200v running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older; fixes ship in hotfixes 12.4.3-03526 and 12.5.0-02952, and The Register reported no workarounds are available. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, 2026, with a remediation deadline of September 5, 2026 (per Canada's Cyber Centre advisory AV26-872 Update 1 and Qualys). SonicWall urged customers to hunt for compromise, re-image or redeploy appliances, and reset all passwords and rotate/reset TOTP tokens; NHS England's CSOC assesses further exploitation of the flaws as 'almost certain.' Qualys detects vulnerable assets via QID 388624, and Rapid7 is shipping detection content in its September 3, 2026 release. The episode extends a string of SonicWall edge attacks: CyberScoop counts these as the fifth and sixth SMA 1000 flaws added to KEV since mid-December 2025 and notes INC and Akira ransomware groups have historically targeted SonicWall devices. Sources differ on the earlier exploited pair CVE-2026-15409 and CVE-2026-15410: The Hacker News says SonicWall fixed them in August and attributes their abuse to threat actor UTA0533 deploying KNUCKLEBALL malware, while The Register dates a similar SSRF-plus-command-injection pair to July, when CISA added CVE-2026-15409 to KEV, and links it to ransomware campaigns.

  • CVE-2026-83548 (CVSS 10.0): pre-authentication SSRF in the SMA 1000 Appliance Work Place interface; The Register reports it stems from an unintended alternative access path.
  • CVE-2026-83549 (CVSS 7.8): post-authentication OS command injection leading to RCE in the SMA 1000 Appliance Management Console.
  • SonicWall confirmed active exploitation; Rapid7 assessed that chaining the two flaws yields unauthenticated remote code execution on internet-exposed appliances, and that exploitation occurred before public disclosure. The threat actor…
  • SonicWall disclosed the flaws on September 1, 2026 (per Rapid7); CISA added both CVEs to the KEV catalog on September 2, 2026, with a September 5, 2026 remediation deadline (Qualys).
  • Affected: SMA 1000 models 6210, 7210, and 8200v on platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older; fixed in 12.4.3-03526 and 12.5.0-02952 hotfixes; The Register reports no workarounds are available.
  • SonicWall urged customers to hunt for compromise, re-image or redeploy appliances, and reset all passwords and rotate TOTP tokens; CyberScoop reports the vendor published no IOCs or victim counts.
  • NHS England CSOC assesses further exploitation of the flaws as 'almost certain' (The Register).
  • Detection: Qualys QID 388624 identifies vulnerable assets; Rapid7 ships detection content in its September 3, 2026 release.

Coverage timeline

  1. · 13d ago
    The Hacker News· 85
    Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

    SonicWall patches two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 VPN appliances, likely chained for code execution.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15409
+1 in the same advisory: …15410
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.0
group max
85% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)