SonicWall warns two actively exploited SMA1000 zero-days are being chained by attackers
SonicWall disclosed two new SMA1000 zero-day flaws - a maximum-severity SSRF bug (CVSS 10.0) and an admin-level command injection bug (CVSS 7.8) - and said it found evidence attackers are chaining them for remote code execution. Per BleepingComputer and The Hacker News.
SonicWall warned on September 2, 2026 that two newly disclosed zero-day vulnerabilities in its SMA1000 secure remote access appliances are being actively exploited, and that its PSIRT investigated a case indicating attackers are chaining the two flaws together. CVE-2026-83548 (CVSS 10.0) is a pre-authentication server-side request forgery flaw in the SMA1000 Appliance WorkPlace interface, discovered internally by SonicWall researchers William Perry and Adam Babis, that lets a remote unauthenticated attacker gain unauthorized access to sensitive functionality. CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection flaw in the Appliance Management Console that lets a remote attacker with admin privileges execute arbitrary commands, leading to remote code execution. The flaws affect SMA1000 models 6210, 7210, and 8200v on platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 or older; SonicWall has released fixes in versions 12.4.3-03526 and 12.5.0-02952 and is urging customers to upgrade immediately, check for indicators of compromise, and reset passwords and TOTP tokens if compromise is found. Internet-monitoring group Shadowserver currently tracks more than 400 SMA1000 appliances still exposed online, though some may already be patched. SonicWall has not disclosed who is behind the attacks. This is a separate incident from two other SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) that SonicWall patched in July 2026 after threat actor UTA0533 exploited them to deploy KNUCKLEBALL malware. Sources: BleepingComputer, The Hacker News.