Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2655+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Attackers Exploit Two Chained Zero-Days in SonicWall SMA 1000 Appliances
Attackers Exploit Two Chained Zero-Days in SonicWall SMA 1000 Appliances
NEWS

Attackers Exploit Two Chained Zero-Days in SonicWall SMA 1000 Appliances

SonicWall discloses two SMA 1000 zero-days, one CVSS 10.0, chained for unauthenticated RCE and now on CISA's KEV list with active exploitation.

Dylan H.

News Desk

September 4, 2026
3 min read

SonicWall SMA 1000 Hit by Actively Exploited Zero-Day Chain

SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 secure remote access appliances that were already being actively exploited in the wild before a patch was available, continuing a pattern of repeated attacks against the product line that has persisted since late 2025.

The Vulnerabilities

  • CVE-2026-83548 (CVSS 10.0) — A critical, pre-authentication server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface, allowing a remote, unauthenticated attacker to reach sensitive functionality through an unintended access path.
  • CVE-2026-83549 (CVSS 7.8) — A post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), letting an authenticated administrator run arbitrary commands under specific conditions.

Chained together, the two flaws give an attacker a path to unauthenticated remote code execution on affected appliances.

Discovery and Disclosure

SonicWall identified the exploitation internally and disclosed both vulnerabilities alongside patches on September 1–2, 2026. CISA added both CVEs to its Known Exploited Vulnerabilities (KEV) catalog on September 3, 2026, with a remediation deadline of September 5 for covered federal agencies — an unusually tight two-day window that underscores the severity of the active exploitation.

Affected Products

The zero-days affect SMA1000 models 6210, 7210, and 8200v. SonicWall's SSL-VPN firewall products and the separate SMA100 series are not affected. Hotfixes 12.4.3-03526, 12.5.0-02952, and later versions remediate both flaws.

A Recurring Target

This is not an isolated incident. SonicWall's SMA 1000 line has had five defects added to CISA's KEV catalog since mid-December 2025. In July 2026, two other SMA1000 flaws — CVE-2026-15409 and CVE-2026-15410 — were exploited as zero-days for weeks to install custom malware before ransomware gangs began abusing them in the wild.

SonicWall did not attribute this latest campaign to a specific threat group, but ransomware operators INC and Akira have previously targeted SonicWall devices; the article notes 10 of 19 SonicWall defects on the CISA KEV list have been used in ransomware campaigns to date.

"Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another path to complete compromise," said Jake Knott of watchTowr.

Response Guidance

SonicWall is urging affected customers to:

  • Apply the available hotfixes immediately
  • Contact SonicWall Technical Support to check for indicators of compromise
  • Reimage affected appliances if compromise is confirmed
  • Reset all passwords and tokens tied to the appliance

SonicWall has not disclosed how many customers were affected by exploitation prior to patch availability.


Sources: CyberScoop, SonicWall Security Advisory, CISA Known Exploited Vulnerabilities Catalog

#SonicWall#Zero-Day#SMA 1000#CVE-2026-83548#CVE-2026-83549#VPN Security#CISA KEV

Related Articles

Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks

SonicWall confirms active exploitation of two chained SMA 1000 zero-days — a pre-auth SSRF (CVSS 10.0) and post-auth command injection.

3 min read

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

SonicWall confirms active exploitation of a chained SSRF and OS command injection pair in SMA 1000 appliances, its third such attack chain in a year.

3 min read

Inc Ransomware Exploits Chained SonicWall SMA Zero-Days for Root Access

The Inc ransomware group is actively exploiting two chained zero-day vulnerabilities in SonicWall Secure Mobile Access appliances. When combined, the...

4 min read
Back to all News