SonicWall SMA 1000 Is Under Attack: Two Zero-Days Can Open the Door to RCE
- The Mess: SonicWall has confirmed that attackers are actively exploiting two zero-day vulnerabilities in its SMA 1000 remote-access appliances. CVE-2026-83548 is a pre-authentication SSRF with a CVSS score of 10.0, while CVE-2026-83549 is an OS command-injection flaw rated 7.8. The two bugs can potentially be chained into remote code execution.
- The Damage: These appliances sit on the network perimeter and provide remote access to corporate resources, making a compromised SMA 1000 a potentially valuable foothold inside an organization.
- The Fix: Patch affected SMA 1000 appliances immediately, check for indicators of compromise, and re-image or redeploy any appliance showing signs of compromise instead of treating the incident as a routine update.
SonicWall has another problem at the edge.
And this time it is not theoretical.
The company confirmed active exploitation of two previously undisclosed vulnerabilities affecting its SMA 1000 Series secure remote access appliances. The affected models are SMA 6210, SMA 7210 and SMA 8200v. SonicWall firewalls and the separate SMA 100 series are not affected.
The first vulnerability is CVE-2026-83548, a pre-authentication server-side request forgery flaw in the SMA 1000 Appliance Work Place interface.
Its CVSS score is 10.0.
That number is not the interesting part.
The interesting part is that the vulnerable interface can allow an unauthenticated remote attacker to reach sensitive functionality through an unintended access path. In other words, the attacker does not need a valid account just to start abusing the flaw.
The second bug, CVE-2026-83549, lives in the Appliance Management Console.
It is an OS command injection vulnerability with a CVSS score of 7.8. Under the affected conditions, an authenticated administrator can execute arbitrary operating-system commands, potentially resulting in remote code execution.
Individually, both bugs are serious.
Together, they are considerably uglier.
Security researchers believe the vulnerabilities can be chained so that the pre-authentication SSRF provides a path toward the functionality needed to exploit the command-injection flaw. That creates a route from an unauthenticated external attacker toward code execution on the appliance. Rapid7 describes the pair as capable of being chained for unauthenticated RCE.
And SonicWall has confirmed something that matters more than any theoretical exploit chain:
someone is already doing it.
The company’s PSIRT investigated an incident indicating that the vulnerabilities were being exploited in the wild. The disclosure therefore arrived after attackers had already found a way to abuse the flaws.
The affected firmware versions include:
- 12.4.3-03453 and earlier
- 12.5.0-02835 and earlier
SonicWall has released fixes in:
- 12.4.3-03526
- 12.5.0-02952
and recommends upgrading to the appropriate hotfix immediately.
But patching is not the end of the story.
If an appliance is internet-facing and vulnerable, administrators should assume that exploitation is possible. SonicWall recommends reviewing systems for indicators of compromise. If compromise is discovered, the recommended response includes re-imaging hardware or redeploying virtual appliances, changing user and administrator passwords, and resetting TOTP tokens.
That distinction matters.
Installing a hotfix fixes the vulnerability.
It does not remove an attacker who may already have established persistence.
And SonicWall’s SMA 1000 has already been a target for zero-day exploitation this year. In July, attackers exploited a separate pair of SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410. Those flaws were also potentially chainable into remote code execution.
So this is not simply another VPN appliance receiving another security update.
It is the second confirmed zero-day exploitation episode targeting the same SMA 1000 product line in a matter of weeks.
The lesson is painfully simple: internet-facing remote-access infrastructure is a prime target, and “it’s patched now” is not the same thing as “it was never compromised.”
CISA has also added the two vulnerabilities to its Known Exploited Vulnerabilities catalog, putting them firmly into the category of flaws defenders should treat as actively weaponized rather than merely high severity.
Bugstoday’s take: SonicWall SMA 1000 is sitting exactly where attackers want it — on the edge, exposed to the internet and trusted to open a path into corporate networks. Two zero-days, active exploitation and a possible SSRF-to-RCE chain make this a patch-now situation. If you run one of the affected appliances, don’t just update it and walk away. Check whether somebody was already inside.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
- SonicWall Security Advisory — SNWLID-2026-0016
- SonicWall Product Notice
- Rapid7 — Analysis of CVE-2026-83548 and CVE-2026-83549
- CISA KEV coverage




