Breaking
SecurityConfirmed

SonicWall SMA 1000 Zero-Days Exploited in Chained Attacks

SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.

··1 hour ago·2 min read
An open padlock surrounded by scattered black computer keyboard keys under red and green light
Photo by FlyD on Unsplash

SonicWall has released security updates for its Secure Mobile Access (SMA) 1000 series VPN appliances after confirming that attackers are actively exploiting two zero-day vulnerabilities in the wild. The flaws, when chained together, could allow remote attackers to execute arbitrary code on vulnerable devices.

Critical SSRF and Command Injection

The two vulnerabilities are CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) flaw in the Appliance Work Place interface, and CVE-2026-83549, a post-authentication operating system command injection issue in the Appliance Management Console (AMC).

CVE-2026-83548 carries a CVSS score of 10.0, indicating maximum severity. According to SonicWall, this flaw could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. The second vulnerability, CVE-2026-83549, has a CVSS score of 7.8 and requires an authenticated attacker with administrator privileges to exploit, potentially leading to remote code execution.

Active Exploitation and Attack Chains

SonicWall stated that it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining both bugs together to execute arbitrary code on susceptible devices. The combination of a pre-authentication SSRF with a post-authentication command injection is a typical attack chain, where the first flaw is used to bypass authentication or gain access, and the second is leveraged for full system compromise.

Affected Models and Versions

The vulnerabilities impact the SMA 1000 models 6210, 7210, and 8200v running the following versions:

  • 12.4.3-03453 (platform-hotfix) and older versions
  • 12.5.0-02835 (platform-hotfix) and older versions

Patches and Remediation

SonicWall has addressed these issues in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). The company is recommending that customers upgrade to the latest hotfix version immediately.

In addition to patching, SonicWall advises administrators to review their systems for indicators of compromise (IoCs). If IoCs are found, the company recommends re-imaging or re-deploying the appliances, changing all user and administrator passwords, and resetting Time-based One-Time Passwords (TOTP). This suggests that a compromised appliance may require full re-imaging to ensure the removal of any backdoors or persistent malware.

Limited Disclosure

SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The lack of detailed attack telemetry or attribution leaves defenders with limited information to assess their own risk beyond the technical indicators provided.

Why This Matters

The active exploitation of these zero-days highlights the ongoing risk posed by edge devices such as VPN appliances, which are often exposed to the internet and serve as a gateway to internal networks. The chaining of a pre-authentication flaw with a post-authentication vulnerability underscores the importance of timely patching and thorough incident response. For organizations running SMA 1000 appliances, the recommended steps go beyond simple patching — the guidance to re-image appliances if IoCs are found suggests that SonicWall considers full system compromise a realistic outcome. Administrators should treat an upgrade to the hotfix versions as an urgent priority and review their environments for any signs of compromise. The absence of public details about the attackers means the window of exposure may be wider than known, and a single fix may not be sufficient if an attacker gained persistent access.

#sonicwall#zero-day#sma-1000#vpn#exploit

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories