Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2647+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks
Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks
NEWS

Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks

SonicWall confirms active exploitation of two chained SMA 1000 zero-days — a pre-auth SSRF (CVSS 10.0) and post-auth command injection.

Dylan H.

News Desk

September 3, 2026
3 min read

Two Chained Zero-Days, Confirmed Active Exploitation

SonicWall has released emergency security updates addressing two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances — and confirmed that attackers are actively chaining both flaws together to achieve remote code execution on internet-facing devices.

SonicWall said it "has investigated a case indicating the active exploitation of the vulnerabilities," with threat actors combining an unauthenticated request-forgery bug with a post-authentication command injection to fully compromise vulnerable appliances.


The Two Vulnerabilities

CVECVSSTypeAuth RequiredComponent
CVE-2026-8354810.0 (Critical)Server-Side Request Forgery (SSRF)None (pre-auth)Appliance Work Place interface
CVE-2026-835497.8 (High)OS Command InjectionYes (post-auth)Appliance Management Console

CVE-2026-83548 allows an unauthenticated remote attacker to reach sensitive internal functionality through the Work Place interface — a pre-auth SSRF that can be used as a foothold. CVE-2026-83549 then allows an authenticated administrator-level session (potentially obtained via the first flaw or via stolen credentials) to inject and execute arbitrary OS commands through the Management Console, resulting in full remote code execution on the appliance.

Both flaws were discovered internally by SonicWall researchers William Perry and Adam Babis.


Affected Products and Fixed Versions

ComponentAffected VersionsFixed Version
SMA 1000 (models 6210, 7210, 8200v)12.4.3-03453 (platform-hotfix) and earlier12.4.3-03526
SMA 1000 (models 6210, 7210, 8200v)12.5.0-02835 (platform-hotfix) and earlier12.5.0-02952

Attack Chain

1. Attacker sends crafted request to the Appliance Work Place interface (no auth)
2. CVE-2026-83548 SSRF is used to reach internal management functionality
3. Attacker leverages the resulting access to reach the Management Console
4. CVE-2026-83549 command injection executes arbitrary OS commands
5. Full remote code execution on the SMA appliance

SonicWall's Guidance

SonicWall is urging all SMA 1000 customers to treat this as an emergency patching event:

  1. Upgrade immediately to 12.4.3-03526 or 12.5.0-02952 (platform-hotfix), whichever branch applies.
  2. Review appliances for indicators of compromise — SonicWall has confirmed real-world exploitation, not just theoretical risk.
  3. If compromise is found or suspected, re-image the appliance rather than attempting to clean in place.
  4. Reset all passwords for accounts associated with the appliance.
  5. Reset all Time-based One-Time Passwords (TOTP) tied to the device, since session/token material may have been exposed.
  6. Restrict management interface exposure — the Work Place and Management Console should not be reachable from the open internet where avoidable.

Why This Matters

SMA appliances sit at the network perimeter as remote-access gateways, making them a high-value target: a single successful chain gives an attacker a foothold with visibility into internal network resources reachable through the VPN tunnel. The CVSS 10.0 rating on the SSRF component reflects that it requires zero credentials and zero user interaction — combined with confirmed in-the-wild exploitation, this places SMA 1000 devices in the same urgency tier as previously exploited perimeter VPN/gateway CVEs from Citrix, Ivanti, and Fortinet earlier this year.


References

  • The Hacker News — Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Related Reading

  • FalconFlank PoC Claims Zero-Day Privilege Escalation in CrowdStrike Falcon
  • Citrix Urges Admins to Patch NetScaler Flaws As Soon As Possible
  • Ivanti Customers Confront Yet Another Actively Exploited Zero-Day
#SonicWall#VPN#Zero-Day#SSRF#Command Injection#Active Exploitation#Network Security

Related Articles

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

SonicWall confirms active exploitation of a chained SSRF and OS command injection pair in SMA 1000 appliances, its third such attack chain in a year.

3 min read

Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root Access

The Inc ransomware group is actively exploiting two chained zero-day vulnerabilities in SonicWall Secure Mobile Access appliances. When combined, the...

4 min read

SonicWall SMA 1000 Zero-Days Exploited in the Wild Before Public Disclosure

A previously undocumented threat actor tracked as UTA0215 by Volexity exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access 1000...

3 min read
Back to all News