ZeroHour
Story · 1 source · 1 articlefirst updated ()

SonicWall SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549 chained for unauthenticated RCE under active exploitation; CISA adds both to KEV

criticalExploit / PoCexploited in the wildimportance 88CVE-2026-83548CVE-2026-83549CVE-2026-15409
What's new: Initial merged summary - no prior summary existed. Developments within this reporting window: SonicWall disclosed the two zero-days September 1, 2026 (Rapid7); both CVEs were confirmed exploited in the wild with chaining yielding unauthenticated RCE and exploitation predating disclosure (Rapid7, Dark Reading, CyberScoop); CISA added both flaws to the KEV catalog September 2, 2026 with a September…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Attackers are chaining a CVSS 10.0 pre-authentication SSRF (CVE-2026-83548) with a CVSS 7.8 authenticated OS command injection (CVE-2026-83549) in SonicWall SMA1000 appliances (models 6210, 7210, 8200v) to achieve unauthenticated remote code execution.…

SonicWall disclosed on September 1, 2026 (per Rapid7) that two zero-days in SMA1000 appliances are being actively exploited: CVE-2026-83548, a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface (which The Register describes as reachable via an unintended alternative access path), and CVE-2026-83549, a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. Rapid7, Dark Reading, and CyberScoop report that chaining the two flaws yields unauthenticated remote code execution on internet-exposed appliances, and Rapid7 says exploitation occurred before public disclosure. Affected are SMA 6210, 7210, and 8200v appliances running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older; fixes are available in 12.4.3-03526 and 12.5.0-02952 platform-hotfixes, and The Register reports no workarounds are available. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, 2026 (Canadian Centre for Cyber Security advisory AV26-872 Update 1; Qualys; CyberScoop), with a September 5, 2026 remediation deadline per Qualys. SonicWall advises customers to check for compromise, reimage or redeploy appliances, and reset all passwords and TOTP tokens; no IOCs or victim counts have been published (CyberScoop). NHS England's CSOC assesses further exploitation as almost certain (The Register). The flaws follow a similar exploited SSRF-plus-command-injection pair in July, when CISA added CVE-2026-15409 to KEV (The Register); Dark Reading notes exploitation follows earlier summer attacks on two other SonicWall edge zero-days, and CyberScoop counts these as the fifth and sixth SMA1000 flaws added to KEV since mid-December 2025 in a product historically targeted by INC and Akira ransomware groups.

  • CVE-2026-83548: pre-authentication SSRF in the SMA1000 Appliance Work Place interface, CVSS 10.0 (Rapid7, Qualys); The Register describes it as arising from an unintended alternative access path.
  • CVE-2026-83549: post-authentication OS command injection in the SMA1000 Appliance Management Console, CVSS 7.8, leading to RCE (The Register, Rapid7, Qualys).
  • Chaining the two flaws yields unauthenticated remote code execution on internet-exposed edge appliances (Rapid7, Dark Reading, CyberScoop); both are confirmed exploited in the wild, with exploitation predating public disclosure (Rapid7).
  • Affected products: SMA1000 models 6210, 7210, and 8200v running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older (Rapid7, Canadian Centre for Cyber Security, Qualys).
  • Fixed in platform-hotfixes 12.4.3-03526 and 12.5.0-02952 (Rapid7, Qualys); The Register reports hotfixes are available with no workarounds.
  • Timeline: SonicWall disclosed the flaws September 1, 2026 (Rapid7); CISA added both to the KEV catalog September 2, 2026 (Canadian Centre for Cyber Security AV26-872 Update 1, Qualys, CyberScoop); KEV remediation deadline is September 5,…
  • SonicWall guidance: check for compromise, reimage or redeploy appliances, and rotate/reset all passwords and TOTP tokens; no IOCs or victim counts have been published (The Register, Rapid7, CyberScoop).
  • NHS England CSOC assesses further exploitation of the flaws as almost certain (The Register).

Coverage timeline

  1. · 13d ago
    The Register · Security· 78
    SonicWall's SMA1000 boxes under active attack again

    SonicWall warns attackers are chaining two SMA1000 zero-days, a CVSS 10.0 SSRF and command injection, to compromise VPN gateways.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15409
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.085% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)