Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2659+ Articles
165+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Attackers Chain Two New Zero-Days in SonicWall's Besieged SMA 1000
Attackers Chain Two New Zero-Days in SonicWall's Besieged SMA 1000
NEWS

Attackers Chain Two New Zero-Days in SonicWall's Besieged SMA 1000

CVE-2026-83548 and CVE-2026-83549 chain into unauthenticated RCE on SonicWall SMA 1000 — the fifth SMA 1000 KEV entry since December.

Dylan H.

News Desk

September 4, 2026
3 min read

Another Round for SonicWall's Most Battered Appliance

SonicWall customers are once again dealing with active exploitation of the company's SMA 1000 remote-access appliance, after researchers confirmed attackers are chaining two newly disclosed zero-days into unauthenticated remote code execution. It's the fifth SMA 1000 defect added to CISA's Known Exploited Vulnerabilities (KEV) catalog since mid-December 2025, capping off nine months of near-continuous vulnerability disclosures against the product line.


Vulnerability Summary

FieldDetails
CVE-2026-83548Max-severity, pre-authentication server-side request forgery (SSRF)
CVE-2026-83549High-severity OS command injection
Chained ImpactUnauthenticated remote code execution
ProductSonicWall SMA 1000 series
StatusActively exploited in the wild as of disclosure (September 3, 2026)
KEV History5th SMA 1000 entry since mid-December 2025

According to researchers at Rapid7, the two flaws can be chained together: the SSRF bug lets an attacker reach internal-only request paths without authenticating, and the command injection flaw then lets that attacker execute arbitrary OS commands — no credentials, no user interaction required.


A Product Under Constant Siege

The SMA 1000 line has had a rough nine months. Per CyberScoop's reporting, this is the fifth SMA 1000 vulnerability added to CISA's KEV catalog since mid-December 2025 alone, part of a broader pattern where SonicWall's remote-access products have drawn sustained attacker interest:

  • State-sponsored actors have previously stolen firewall configuration data affecting SonicWall's entire customer base
  • July 2026 — Huntress researchers found roughly 30 customers compromised within a two-day window
  • July 2026 — A separate SonicWall zero-day was exploited for three weeks before public disclosure
  • Multiple years-old SonicWall defects continue to be re-exploited by opportunistic attackers long after patches are available

Of the 19 SonicWall vulnerabilities added to the KEV catalog since late 2021, ten have documented use in ransomware campaigns — most notably by the INC and Akira ransomware operations, both of which have shown a specific, sustained interest in SonicWall gateway products as an initial-access vector.


Who Should Care

Any organization running an internet-facing SMA 1000 appliance should treat this as an active-exploitation event, not a routine patch cycle. Given the chain requires no authentication and no user interaction, exposed appliances are exploitable the moment an attacker identifies them.

  • VPN/remote-access gateways are a favored ransomware entry point precisely because compromising one grants a foothold deep inside the corporate network
  • SonicWall has not disclosed the number of directly affected customers as of publication
  • SonicWall has released patches; no public indicators of compromise (IOCs) were available at time of disclosure

Recommended Actions

  1. Patch immediately — apply SonicWall's fixes for CVE-2026-83548 and CVE-2026-83549 without delay
  2. Restrict management/remote-access exposure — SMA 1000 administrative and gateway interfaces should not be reachable from the open internet where avoidable
  3. Hunt for compromise — given the appliance's history, assume exploitation attempts are already occurring; review logs for anomalous SSRF-style requests or unexpected command execution on the appliance
  4. Rotate credentials tied to the appliance and any systems it can reach, given the track record of SonicWall compromises leading to lateral movement
  5. Track CISA KEV — SMA 1000 owners should treat any future KEV entry for this product line as a near-certainty given the pattern of the last nine months

Sources

  • CyberScoop — Attackers exploit zero-days in consistently besieged SonicWall product
  • CISA Known Exploited Vulnerabilities Catalog
#SonicWall#Zero-Day#SSRF#Remote Code Execution#CISA KEV#Ransomware

Related Articles

Attackers Exploit Two Chained Zero-Days in SonicWall SMA 1000 Appliances

SonicWall discloses two SMA 1000 zero-days, one CVSS 10.0, chained for unauthenticated RCE and now on CISA's KEV list with active exploitation.

3 min read

Attackers Chain Two SonicWall SMA 1000 Zero-Days in Active Attacks

SonicWall confirms active exploitation of two chained SMA 1000 zero-days — a pre-auth SSRF (CVSS 10.0) and post-auth command injection.

3 min read

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

SonicWall confirms active exploitation of a chained SSRF and OS command injection pair in SMA 1000 appliances, its third such attack chain in a year.

3 min read
Back to all News