SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation.
SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild.
- CVE-2026-83548 (CVSS 10.0) is a pre-authentication SSRF vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could exploit it to access sensitive functionality and perform unauthorized operations.
- CVE-2026-83549 (CVSS 7.8) is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). A remote attacker authenticated as an administrator could exploit it under specific conditions to execute arbitrary commands and achieve remote code execution. SonicWall’s investigation suggests attackers may be chaining the two flaws to compromise vulnerable appliances.
SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that the two SMA 1000 flaws are being exploited in the wild, with attackers likely chaining them to achive arbitrary code execution.
“SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.” reads the advisory.
The vulnerabilities affect models 6210, 7210 and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier. 12.4.3-03526 and 12.5.0-02952 versions addressed the flaws.
SonicWall recommends that customers first install the latest hotfix and check their systems for any signs of compromise. If they find indicators of compromise, they should re-image or redeploy the affected appliances, change all user and administrator passwords, and reset their time-based one-time passwords (TOTP).
SonicWall hasn’t disclosed technical details of the attack or said who is behind them. This is also the second recent security incident affecting the SMA product line in a month, recently the company patched two other flaws, CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2).
In July, Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks as UTA0533, chained two vulnerabilities to achieve root-level access on the devices before patches existed.
UTA0533 had exploited to deploy a malicious Python script named KNUCKLEBALL.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SMA 1000)
