Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has patched two zero-day vulnerabilities in its SMA 1000 VPN appliances, which were being actively exploited by threat actors. These flaws allowed attackers to gain unauthorized access and execute commands, potentially deploying malware. SonicWall urges customers to update immediately and investigate for signs of compromise.
SonicWall has released security updates to address two critical security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances. These vulnerabilities were being actively exploited in zero-day attacks, allowing attackers to gain unauthorized access and execute arbitrary commands on susceptible devices. The flaws were discovered internally by SonicWall’s William Perry and Adam Babis.
Specifically, CVE-2026-83548 (CVSS score: 10.0) is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance Work Place interface, while CVE-2026-83549 (CVSS score: 7.8) is a post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC). Both vulnerabilities could lead to remote code execution.
The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions: 12.4.3-03453 (platform-hotfix) and older versions, and 12.5.0-02835 (platform-hotfix) and older versions. SonicWall has released fixes in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers upgrade to the latest hotfix version, review their systems for indicators of compromise (IoCs), and if IoCs are found, re-image or re-deploy the appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP).
SonicWall has not disclosed details about the exploitation activity or the threat actor involved, but this follows on from previous vulnerabilities in the same product, CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), which were exploited by a threat actor known as UTA0533 to deploy KNUCKLEBALL malware.
