SonicWall SMA 1000 Zero-Days Exploited in Chained Attacks
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.
SonicWall has released security updates for its Secure Mobile Access (SMA) 1000 series VPN appliances after confirming that attackers are actively exploiting two zero-day vulnerabilities in the wild. The flaws, when chained together, could allow remote attackers to execute arbitrary code on vulnerable devices.
Critical SSRF and Command Injection
The two vulnerabilities are CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and CVE-2026-83549, a post-authentication operating system command injection issue in the Appliance Management Console (AMC).
CVE-2026-83548 carries a CVSS score of 10.0, indicating maximum severity. According to SonicWall, this flaw could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. The second vulnerability, CVE-2026-83549, has a CVSS score of 7.8 and requires an authenticated attacker with administrator privileges to exploit, potentially leading to remote code execution.
Active Exploitation and Attack Chains
SonicWall stated that it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining both bugs together to execute arbitrary code on susceptible devices. The combination of a pre-authentication SSRF with a post-authentication command injection is a typical attack chain, where the first flaw is used to bypass authentication or gain access, and the second is leveraged for full system compromise.
Affected Models and Versions
The vulnerabilities impact the SMA 1000 models 6210, 7210, and 8200v running the following versions:
- 12.4.3-03453 (platform-hotfix) and older versions
- 12.5.0-02835 (platform-hotfix) and older versions
Patches and Remediation
SonicWall has addressed these issues in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). The company is recommending that customers upgrade to the latest hotfix version immediately.
In addition to patching, SonicWall advises administrators to review their systems for indicators of compromise (IoCs). If IoCs are found, the company recommends re-imaging or re-deploying the appliances, changing all user and administrator passwords, and resetting Time-based One-Time Passwords (TOTP). This suggests that a compromised appliance may require full re-imaging to ensure the removal of any backdoors or persistent malware.
Limited Disclosure
SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The lack of detailed attack telemetry or attribution leaves defenders with limited information to assess their own risk beyond the technical indicators provided.
Why This Matters
The active exploitation of these zero-days highlights the ongoing risk posed by edge devices such as VPN appliances, which are often exposed to the internet and serve as a gateway to internal networks. The chaining of a pre-authentication flaw with a post-authentication vulnerability underscores the importance of timely patching and thorough incident response. For organizations running SMA 1000 appliances, the recommended steps go beyond simple patching — the guidance to re-image appliances if IoCs are found suggests that SonicWall considers full system compromise a realistic outcome. Administrators should treat an upgrade to the hotfix versions as an urgent priority and review their environments for any signs of compromise. The absence of public details about the attackers means the window of exposure may be wider than known, and a single fix may not be sufficient if an attacker gained persistent access.
Sources
- The Hacker News Original source
Continue Reading
BGP hijack pushes malware via a 256-IP range
Attackers exploited routing and TLS flaws to abuse a hijacked /24 block in a 22-hour window.
Artifactory Flaw Exploited Within Days of Patch
Attackers are exploiting CVE-2026-82329, a critical Artifactory authentication bypass, to mint admin tokens.
Coast Guard Creates Central Maritime Cyber Policy Office
New CG-MCP office centralizes maritime cybersecurity policy as ports face rising operational technology risks.