SonicWall SMA 1000 zero-days exploited in the wild

Attackers are actively chaining two previously unknown vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 Series appliances to seize control of the devices, the vendor has confirmed.[1][3] The flaws, tracked as CVE-2026-83548 and CVE-2026-83549, are already being used in attacks against exposed gateways that provide remote access and VPN connectivity for midsize and large enterprises.[1][2][3] SonicWall describes the incident as active exploitation with no available workaround and is urging customers to apply emergency hotfixes immediately.[1][3]

The first bug, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) vulnerability in the SMA 1000 Appliance WorkPlace interface, caused by an unintended alternate access path that effectively turns the gateway into an unauthorized forward proxy.[1][2][4][5] With a maximum CVSS v3 score of 10.0, the flaw allows a remote, unauthenticated attacker to send crafted requests through the device to internal resources and “gain unauthorized access to sensitive functionality and perform unauthorized operations,” according to SonicWall’s advisory.[1][3][5] Security trackers describe the issue as a known exploited vulnerability that can let attackers pivot from the edge into internal services once the device is exposed to the internet.[4][5]

The second vulnerability, CVE-2026-83549, is a post-authentication operating system command injection flaw in the SMA 1000 Appliance Management Console (AMC), rated 7.8 under CVSS v3.[1][3] Under certain conditions, a logged-in administrator can be tricked or coerced into triggering malicious input, enabling an attacker to execute arbitrary commands on the underlying appliance.[1][3] When combined with the pre-auth SSRF bug, the two issues form a reliable exploit chain that can deliver full administrative control of affected gateways.[1][2][3]

According to SonicWall, only SMA 1000 models 6210, 7210 and 8200v—both physical and virtual—are affected, and only when running specific platform-hotfix firmware builds.[1][2][3][4] Impacted versions include SMA 1000 firmware 12.4.3-03453 and 12.5.0-02835 and earlier platform-hotfix releases, with fixes provided in hotfix builds 12.4.3-03526 and 12.5.0-02952.[1][2][4] SonicWall stresses that its SMA 100 Series appliances and SonicWall firewall SSL-VPN features are not impacted by these CVEs, a distinction that has caused confusion in past advisories.[2][3][6]

The company’s product notice states there is no mitigation short of patching: customers are instructed to upgrade to the latest hotfix available via their support portal, then contact SonicWall Technical Support for assistance reviewing their appliances for indicators of compromise.[1][4] If signs of compromise are found, SonicWall recommends fully reimaging or redeploying affected hardware or virtual appliances, changing all user and administrator passwords, and resetting time-based one-time password (TOTP) tokens to evict attackers and restore trust in the environment.[1][4]

The new zero-days extend a difficult run for the SMA 1000 line, which has faced multiple waves of critical vulnerabilities and active exploitation in the last two years, including prior pre-auth SSRF and post-auth command injection flaws disclosed in mid-2026.[9][14][15] Security advisories from national cybersecurity agencies and independent researchers have repeatedly warned that internet-facing VPN and remote access gateways are high-value targets, and that SonicWall’s SMA 1000 issues have been rapidly weaponized in previous campaigns.[8][10][14][15] With fresh exploitation now confirmed, organizations still running unpatched SMA 1000 appliances should treat them as at-risk edge infrastructure, assume potential compromise, and move quickly to patch, harden access, and increase monitoring around these devices.[1][3][4]

References

  1. SMA 1000 Series affected by Multiple Vulnerabilities …
  2. CVE-2026-83548 and CVE-2026-83549
  3. SonicWall SMA 1000 appliances under attack via zero-day …
  4. CVE-2026-83548 Exploited in the Wild — SMA1000 | Previdian
  5. CVE-2026-83548 – Vulnerability Details – OpenCVE
  6. Exploitation of Critical Vulnerability CVE-2025-23006 in SonicWall SMA1000 Series Appliances – NHS England Digital
  7. Multiple Vulnerabilities in SonicWall SMA1000 Series
  8. Product Notice: SMA 1000 Series affected by Multiple Vulnerabilities
  9. Objet: Multiples vulnérabilités dans Sonicwall Secure Mobile Access
  10. SonicWall SMA1000 vulnerabilities in active exploitation
  11. SonicWall SMA Zero-Days: Edge Appliance Root Returns

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply