ZeroHour
Story · 1 source · 1 articlefirst updated ()

Actively exploited SonicWall SMA1000 zero-days CVE-2026-83548 and CVE-2026-83549 chain to unauthenticated RCE; hotfixes released, CISA KEV deadline September 5

What's new: Added Canada's Cyber Centre advisory AV26-884 (published September 4, 2026), which flags SonicWall Network Security Manager On-Prem 4.3.0 and earlier across VMware, Hyper-V, Azure and KVM deployments as affected by multiple vulnerabilities, with no CVE identifiers or exploitation details provided. No changes to the SMA1000 CVE-2026-83548/CVE-2026-83549 facts from the previous summary.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

SonicWall disclosed on September 1, 2026 two actively exploited zero-days in SMA1000 appliances (models 6210, 7210, 8200v): CVE-2026-83548 (CVSS 10.0 pre-authentication SSRF) and CVE-2026-83549 (CVSS 7.8 post-authentication OS command injection), which Rapid7…

On September 1, 2026, SonicWall disclosed two actively exploited zero-days in its SMA1000 secure access appliances (models 6210, 7210 and 8200v) running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older. CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF in the Appliance Work Place interface, reachable via an unintended alternate access path, allowing unauthenticated access to sensitive functionality. CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection in the Appliance Management Console that requires administrator-level authentication and enables arbitrary OS command execution. SonicWall investigated a case indicating active exploitation and suggested attackers chained the two bugs (The Hacker News described chaining as likely); Rapid7 states the chain yields unauthenticated remote code execution and that exploitation occurred before public disclosure. Infosecurity Magazine's account did not report chaining. The threat actor remains unidentified, and SonicWall published no IOCs or victim counts (CyberScoop). Fixed versions are platform-hotfix 12.4.3-03526 and 12.5.0-02952; The Register reports no workarounds are available. CISA added both CVEs to the Known Exploited Vulnerabilities catalog on September 2, 2026, with a September 5, 2026 remediation deadline per Qualys. Rapid7 is shipping detection content in its September 3 release; Qualys detects vulnerable assets via QID 388624. Guidance: apply the hotfixes, check for compromise and IOCs with SonicWall support, re-image or redeploy appliances, and reset all passwords and TOTP tokens. NHS England CSOC assesses further exploitation as almost certain. Context: these are the fifth and sixth SMA1000 flaws added to KEV since mid-December 2025 (CyberScoop); they follow CVE-2026-15409 and CVE-2026-15410, abused by UTA0533 to deploy KNUCKLEBALL malware (The Hacker News dates those fixes to August, while The Register says CISA added CVE-2026-15409 to KEV in July), and INC and Akira ransomware groups have historically targeted SonicWall devices. Separately, Canada's Cyber Centre published advisory AV26-884 on September 4, 2026, flagging multiple vulnerabilities in SonicWall Network Security Manager (NSM) On-Prem 4.3.0 and earlier across VMware, Hyper-V, Azure and KVM deployments; that advisory lists no CVE identifiers or exploitation details and urges applying available updates.

  • CVE-2026-83548: CVSS 10.0 pre-authentication SSRF in the SMA1000 Appliance Work Place interface, via an unintended alternate access path; enables unauthenticated access to sensitive functionality.
  • CVE-2026-83549: CVSS 7.8 post-authentication OS command injection in the SMA1000 Appliance Management Console; requires administrator-level authentication and enables remote code execution.
  • Rapid7 states chaining the two flaws yields unauthenticated RCE; SonicWall's investigation suggested chaining and The Hacker News called it likely; Infosecurity Magazine did not report chaining.
  • Both vulnerabilities are confirmed exploited in the wild; Rapid7 says exploitation occurred before public disclosure.
  • Affected: SMA1000 models 6210, 7210 and 8200v running platform-hotfix 12.4.3-03453 or 12.5.0-02835 and older.
  • Fixed in platform-hotfixes 12.4.3-03526 and 12.5.0-02952; The Register reports no workarounds are available.
  • Disclosure: September 1, 2026 (SonicWall advisory); CISA added both CVEs to the KEV catalog on September 2, 2026, with a September 5, 2026 remediation deadline (Qualys).
  • Threat actor unidentified; SonicWall published no IOCs or victim counts (CyberScoop).

Coverage timeline

  1. · 14d ago
    Infosecurity Magazine· 78
    Hackers Chain Two New SonicWall Zero-Day Vulnerabilities

    SonicWall warns two zero-days (CVE-2026-83548 SSRF, CVE-2026-83549 post-auth RCE) in SMA1000 appliances are being actively exploited.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15409
+1 in the same advisory: …15410
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.0
group max
85% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)
CVE-2026-83548
+1 in the same advisory: …83549
Pre-Authentication SSRF in SonicWall SMA1000 Appliance Workplace Interface

CVE-2026-83548 is a critical (CVSS 3.1 score 10.0) server-side request forgery (SSRF) vulnerability in the Workplace interface of SonicWall SMA1000 appliances, caused by an unintended alternate access path (unprotected alternate channel, CWE-441; SSRF, CWE-918). Because it is pre-authentication, any remote unauthenticated attacker who can reach the interface can trigger it and gain unauthorized access to sensitive functionality and perform unauthorized operations. CISA lists all SonicWall SMA1000 appliances as affected, with CPE data naming the SMA 8200v and SMA 6210/7210 firmware; internet-exposed units are at highest risk. The flaw is being actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-02 alongside companion zero-day CVE-2026-83549, which reporting suggests may form an attack chain with this SSRF. Exploitation probability is elevated (EPSS 4.7%, 91st percentile) and no public proof-of-concept is known.

Do: Apply the fixes/mitigations from SonicWall security advisory AV26-872 (Update 1) immediately, prioritizing internet-exposed SMA 1000 appliances, and treat companion zero-day CVE-2026-83549 as requiring remediation in the same maintenance window. Review SMA 1000 logs for signs of exploitation (unexpected access to or requests against the Workplace interface) and reduce internet exposure of that interface where feasible. Per the CISA KEV required action and BOD 26-04, patch per vendor instructions or, where mitigations are unavailable, evaluate each asset's internet exposure and discontinue use of the product until remediated.

10.0
group max
5% KEV
  • SonicWall SMA1000 appliance Workplace interface
  • SonicWall SMA 8200v
  • SonicWall SMA 6210 firmware
  • +1 more
moderate≈1,000–10,000 internet-exposed SMA 1000 appliances (order-of-magnitude estimate)