Another Round for SonicWall's Most Battered Appliance
SonicWall customers are once again dealing with active exploitation of the company's SMA 1000 remote-access appliance, after researchers confirmed attackers are chaining two newly disclosed zero-days into unauthenticated remote code execution. It's the fifth SMA 1000 defect added to CISA's Known Exploited Vulnerabilities (KEV) catalog since mid-December 2025, capping off nine months of near-continuous vulnerability disclosures against the product line.
Vulnerability Summary
| Field | Details |
|---|---|
| CVE-2026-83548 | Max-severity, pre-authentication server-side request forgery (SSRF) |
| CVE-2026-83549 | High-severity OS command injection |
| Chained Impact | Unauthenticated remote code execution |
| Product | SonicWall SMA 1000 series |
| Status | Actively exploited in the wild as of disclosure (September 3, 2026) |
| KEV History | 5th SMA 1000 entry since mid-December 2025 |
According to researchers at Rapid7, the two flaws can be chained together: the SSRF bug lets an attacker reach internal-only request paths without authenticating, and the command injection flaw then lets that attacker execute arbitrary OS commands — no credentials, no user interaction required.
A Product Under Constant Siege
The SMA 1000 line has had a rough nine months. Per CyberScoop's reporting, this is the fifth SMA 1000 vulnerability added to CISA's KEV catalog since mid-December 2025 alone, part of a broader pattern where SonicWall's remote-access products have drawn sustained attacker interest:
- State-sponsored actors have previously stolen firewall configuration data affecting SonicWall's entire customer base
- July 2026 — Huntress researchers found roughly 30 customers compromised within a two-day window
- July 2026 — A separate SonicWall zero-day was exploited for three weeks before public disclosure
- Multiple years-old SonicWall defects continue to be re-exploited by opportunistic attackers long after patches are available
Of the 19 SonicWall vulnerabilities added to the KEV catalog since late 2021, ten have documented use in ransomware campaigns — most notably by the INC and Akira ransomware operations, both of which have shown a specific, sustained interest in SonicWall gateway products as an initial-access vector.
Who Should Care
Any organization running an internet-facing SMA 1000 appliance should treat this as an active-exploitation event, not a routine patch cycle. Given the chain requires no authentication and no user interaction, exposed appliances are exploitable the moment an attacker identifies them.
- VPN/remote-access gateways are a favored ransomware entry point precisely because compromising one grants a foothold deep inside the corporate network
- SonicWall has not disclosed the number of directly affected customers as of publication
- SonicWall has released patches; no public indicators of compromise (IOCs) were available at time of disclosure
Recommended Actions
- Patch immediately — apply SonicWall's fixes for CVE-2026-83548 and CVE-2026-83549 without delay
- Restrict management/remote-access exposure — SMA 1000 administrative and gateway interfaces should not be reachable from the open internet where avoidable
- Hunt for compromise — given the appliance's history, assume exploitation attempts are already occurring; review logs for anomalous SSRF-style requests or unexpected command execution on the appliance
- Rotate credentials tied to the appliance and any systems it can reach, given the track record of SonicWall compromises leading to lateral movement
- Track CISA KEV — SMA 1000 owners should treat any future KEV entry for this product line as a near-certainty given the pattern of the last nine months