SonicWall SMA1000 Zero-Days Under Active Attack: Patch Now

SonicWall says attackers are actively exploiting two SMA1000 vulnerabilities that can be chained for unauthenticated remote code execution.

Sep 3, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

SonicWall is urging SMA1000 customers to patch immediately after confirming active exploitation of two newly disclosed vulnerabilities, including a critical pre-authentication server-side request forgery flaw.

The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affect SMA1000 6210, 7210, and 8200v secure remote access appliances. SonicWall released fixed hotfixes on September 1 and recommends investigating affected systems for signs of compromise.

CVE-2026-83548 and CVE-2026-83549 can lead to RCE

According to SonicWall’s security advisory, CVE-2026-83548 is a pre-authentication SSRF vulnerability caused by an unintended forward-proxy function in the SMA1000 WorkPlace interface.

The flaw carries a maximum CVSS score of 10.0 and requires no authentication.

CVE-2026-83549 is a post-authentication remote code execution vulnerability in the Appliance Management Console. It has a CVSS score of 7.8 and requires administrator access when exploited on its own.

Rapid7 says the two flaws can be chained so CVE-2026-83548 provides unauthenticated access to functionality that can then be used to exploit CVE-2026-83549 and execute operating system commands without prior authentication.

SonicWall has confirmed active exploitation of both vulnerabilities but has not published attack details, attribution, or public indicators of compromise for the current activity.

Patch affected SMA1000 appliances immediately

The flaws affect SMA1000 6210, 7210, and 8200v appliances running the following vulnerable platform-hotfix versions:

  • 12.4.3-03453 and earlier

  • 12.5.0-02835 and earlier

Organizations should update to:

  • 12.4.3-03526 or later

  • 12.5.0-02952 or later

SonicWall also recommends contacting its technical support team to review affected appliances for indicators of compromise.

If compromise is detected, administrators should:

  • Re-image physical appliances or redeploy virtual appliances.

  • Change all user and administrator passwords.

  • Reset TOTP tokens.

Because SMA1000 appliances provide remote access to internal resources, organizations should prioritize exposed systems for both patching and investigation rather than treating the hotfix alone as sufficient remediation.

Advertisement

SMA1000 was also targeted in July

The disclosure follows another actively exploited SMA1000 vulnerability chain patched in July.

CVE-2026-15409 and CVE-2026-15410 affected the same appliance family and could be chained for remote code execution. The July fixes were 12.4.3-03453 and 12.5.0-02835, the same builds now listed as vulnerable to the newly disclosed flaws.

Volexity’s investigation found that threat actor UTA0533 had been exploiting the July vulnerabilities since at least June 22. Attackers gained root-level command execution and deployed malware including KNUCKLEBALL and the ORANGETAIL webshell.

eSecurity Planet previously covered the actively exploited July SMA1000 vulnerabilities, which were also added to CISA’s Known Exploited Vulnerabilities catalog.

Organizations that patched after the July incident still need the new hotfixes. The versions that fixed July’s vulnerabilities are now affected by CVE-2026-83548 and CVE-2026-83549.

Also read: China-linked hackers compromised Cisco IOS XR routers and used the infrastructure to create covert paths into other networks.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.