SonicWall SMA 1000 Hit by Actively Exploited Zero-Day Chain
SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 secure remote access appliances that were already being actively exploited in the wild before a patch was available, continuing a pattern of repeated attacks against the product line that has persisted since late 2025.
The Vulnerabilities
- CVE-2026-83548 (CVSS 10.0) — A critical, pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface, allowing a remote, unauthenticated attacker to reach sensitive functionality through an unintended access path.
- CVE-2026-83549 (CVSS 7.8) — A post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), letting an authenticated administrator run arbitrary commands under specific conditions.
Chained together, the two flaws give an attacker a path to unauthenticated remote code execution on affected appliances.
Discovery and Disclosure
SonicWall identified the exploitation internally and disclosed both vulnerabilities alongside patches on September 1–2, 2026. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on September 3, 2026, with a remediation deadline of September 5 for covered federal agencies — an unusually tight two-day window that underscores the severity of the active exploitation.
Affected Products
The zero-days affect SMA1000 models 6210, 7210, and 8200v. SonicWall's SSL-VPN firewall products and the separate SMA100 series are not affected. Hotfixes 12.4.3-03526, 12.5.0-02952, and later versions remediate both flaws.
A Recurring Target
This is not an isolated incident. SonicWall's SMA 1000 line has had five defects added to CISA's KEV catalog since mid-December 2025. In July 2026, two other SMA1000 flaws — CVE-2026-15409 and CVE-2026-15410 — were exploited as zero-days for weeks to install custom malware before ransomware gangs began abusing them in the wild.
SonicWall did not attribute this latest campaign to a specific threat group, but ransomware operators INC and Akira have previously targeted SonicWall devices; the article notes 10 of 19 SonicWall defects on the CISA KEV list have been used in ransomware campaigns to date.
"Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another path to complete compromise," said Jake Knott of watchTowr.
Response Guidance
SonicWall is urging affected customers to:
- Apply the available hotfixes immediately
- Contact SonicWall Technical Support to check for indicators of compromise
- Reimage affected appliances if compromise is confirmed
- Reset all passwords and tokens tied to the appliance
SonicWall has not disclosed how many customers were affected by exploitation prior to patch availability.
Sources: CyberScoop, SonicWall Security Advisory, CISA Known Exploited Vulnerabilities Catalog