VYPR
kevPublished Sep 2, 2026· 8 sources

SonicWall Warns of Two Actively Exploited Zero-Days in SMA1000 Appliances

SonicWall has issued an urgent warning about two zero-day vulnerabilities in its SMA1000 series appliances that are being actively exploited in the wild, potentially allowing for unauthenticated remote code execution.

SonicWall has alerted its customers to two critical zero-day vulnerabilities affecting its SMA1000 series secure remote access gateway and SSL-VPN appliances. The company has confirmed that both flaws are being actively exploited by threat actors, necessitating immediate action from users to patch their systems.

The first vulnerability, designated CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) flaw within the Appliance Work Place interface. With a critical CVSS score of 10, this vulnerability allows unauthenticated remote attackers to access sensitive functionalities and perform unauthorized operations on the affected appliances. This type of vulnerability can often be used as an initial foothold for further network compromise.

The second vulnerability, CVE-2026-83549, is an OS command injection flaw impacting the Appliance Management Console (AMC) component. This vulnerability carries a CVSS score of 7.8 and requires authentication, but it allows an attacker to execute arbitrary operating system commands. When chained with the SSRF vulnerability, it can lead to full remote code execution, giving attackers complete control over the compromised device.

SonicWall's advisory explicitly states that exploitation of both vulnerabilities has been observed, strongly indicating that attackers are chaining them together to achieve a more severe impact. While specific details about the attacks or indicators of compromise (IoCs) have not yet been released by SonicWall, the active exploitation underscores the urgency of the situation.

The affected models include the SMA1000 series 6210, 7210, and 8200v. SonicWall has released hotfixes to address these vulnerabilities, specifically hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions. Importantly, the company has clarified that its SSL-VPN on SonicWall firewalls and SMA100 series products are not affected by these particular zero-days.

This incident highlights a recurring challenge for organizations relying on vendor-provided remote access solutions. SonicWall products have been frequent targets in the past, with numerous vulnerabilities being exploited in the wild, sometimes for extended periods before patches are applied. The inclusion of these two new CVEs in active exploitation campaigns adds to a growing list of security concerns for SonicWall users.

As of the advisory's publication, neither CVE-2026-83548 nor CVE-2026-83549 had been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. However, given the active exploitation, it is highly probable they will be added soon, which would mandate federal agencies to patch them within a specific timeframe. This situation serves as a critical reminder for all organizations to stay vigilant and promptly apply security updates, especially for internet-facing devices like secure remote access appliances.

The new advisory from SonicWall, SNWLID-2026-0016, provides specific details on the affected versions, including SMA1000 6210, 7210, and 8200v appliances running version 12.4.3-03453 or earlier, and version 12.5.0-02835 or earlier. It also specifies the patched versions as 12.4.3-03526 and 12.5.0-02952, respectively, and emphasizes that there are no workarounds, necessitating immediate patching or appliance re-imaging if compromise is suspected.

This new advisory from SonicWall details two specific zero-day vulnerabilities, CVE-2024-5571 and CVE-2024-5572, affecting the SMA 100 series. The previous report mentioned active exploitation of unspecified zero-days in SMA1000 appliances, but this update provides the exact CVE identifiers and confirms the affected product line is the SMA 100 series, which can be chained for unauthorized access.

This new report provides specific details on the two zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, affecting SonicWall SMA 1000 appliances. CVE-2026-83548 is identified as a pre-authentication SSRF flaw in the Appliance Work Place interface, while CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console that can lead to remote code execution under specific conditions. The article also notes that both physical and virtual SMA 1000 models (6210, 7210, and 8200v) are affected, and outlines recommended remediation steps including applying a hotfix, reviewing for indicators of compromise, and in confirmed cases, re-imaging/re-deploying appliances and resetting credentials and TOTP tokens.

The new article provides specific details on the two zero-day vulnerabilities affecting SonicWall SMA 1000 series VPN appliances, identifying them as CVE-2026-83548, a critical pre-authentication SSRF flaw, and CVE-2026-83549, an authentication bypass vulnerability. It also notes that these flaws are being actively exploited, with attackers potentially chaining them together to achieve unauthorized access.

The latest advisory from SonicWall details that attackers are actively exploiting two chained zero-day vulnerabilities in its SMA 1000 Series appliances, specifically CVE-2026-83548 (a pre-authentication SSRF flaw) and CVE-2026-83549 (a post-authentication OS command injection flaw). These vulnerabilities affect the SMA 6210, 7210, and 8200v models, and while hotfixes are available, no workarounds exist, necessitating immediate patching or appliance redeployment if compromise is suspected.

This new report from Rapid7 details the specific technical mechanisms of the SonicWall SMA1000 vulnerabilities, CVE-2026-83548 and CVE-2026-83549. It clarifies that CVE-2026-83548 is a critical pre-authentication SSRF flaw with a CVSS score of 10.0, while CVE-2026-83549 is an OS command injection vulnerability that, when chained with the SSRF flaw, allows for unauthenticated remote code execution. The article also lists the specific vulnerable and patched versions for both the 12.4.3 and 12.5.0 branches.

This new report from Dark Reading indicates that exploitation of the SonicWall SMA 1000 zero-days is ongoing, with attackers actively leveraging these vulnerabilities for unauthenticated remote code execution. The article also notes that this activity follows earlier attacks this summer on other SonicWall edge devices, suggesting a persistent and evolving threat landscape targeting the vendor's product line.

Synthesized by Vypr AI