VYPR
kevPublished Sep 2, 2026· 1 source

SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000 Appliances

SonicWall has issued an urgent warning about two zero-day vulnerabilities in its SMA1000 series appliances that are being actively exploited in the wild, potentially allowing for unauthenticated remote code execution.

SonicWall has alerted its customers to two critical zero-day vulnerabilities affecting its SMA1000 series secure remote access gateway and SSL-VPN appliances. The company has confirmed that both flaws are being actively exploited by threat actors, necessitating immediate action from users to patch their systems.

The first vulnerability, designated CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) flaw within the Appliance Work Place interface. With a critical CVSS score of 10, this vulnerability allows unauthenticated remote attackers to access sensitive functionalities and perform unauthorized operations on the affected appliances. This type of vulnerability can often be used as an initial foothold for further network compromise.

The second vulnerability, CVE-2026-83549, is an OS command injection flaw impacting the Appliance Management Console (AMC) component. This vulnerability carries a CVSS score of 7.8 and requires authentication, but it allows an attacker to execute arbitrary operating system commands. When chained with the SSRF vulnerability, it can lead to full remote code execution, giving attackers complete control over the compromised device.

SonicWall's advisory explicitly states that exploitation of both vulnerabilities has been observed, strongly indicating that attackers are chaining them together to achieve a more severe impact. While specific details about the attacks or indicators of compromise (IoCs) have not yet been released by SonicWall, the active exploitation underscores the urgency of the situation.

The affected models include the SMA1000 series 6210, 7210, and 8200v. SonicWall has released hotfixes to address these vulnerabilities, specifically hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions. Importantly, the company has clarified that its SSL-VPN on SonicWall firewalls and SMA100 series products are not affected by these particular zero-days.

This incident highlights a recurring challenge for organizations relying on vendor-provided remote access solutions. SonicWall products have been frequent targets in the past, with numerous vulnerabilities being exploited in the wild, sometimes for extended periods before patches are applied. The inclusion of these two new CVEs in active exploitation campaigns adds to a growing list of security concerns for SonicWall users.

As of the advisory's publication, neither CVE-2026-83548 nor CVE-2026-83549 had been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. However, given the active exploitation, it is highly probable they will be added soon, which would mandate federal agencies to patch them within a specific timeframe. This situation serves as a critical reminder for all organizations to stay vigilant and promptly apply security updates, especially for internet-facing devices like secure remote access appliances.

Synthesized by Vypr AI