Cybersecurity firm SonicWall has issued a dire warning to its customers, revealing that threat actors are actively exploiting two previously unknown vulnerabilities in its Secure Mobile Access (SMA) 1000 appliances. The company’s advisory comes as a stark reminder of the ongoing threat landscape and the importance of timely patching.
The two zero-day flaws, identified as CVE-2026-83548 and CVE-2026-83549, are being exploited by attackers in remote code execution attacks that target the SMA 1000 Appliance WorkPlace interface and the Appliance Management Console. These vulnerabilities are particularly concerning because they can be chained together to allow hackers with admin privileges to execute arbitrary operating system commands on vulnerable devices.
The affected models include the SMA 1000 6210, 7210, and 8200v, but it’s worth noting that SSL-VPN running on SonicWall firewalls and the SMA 100 Series product line are not impacted. However, with over 400 SMA 1000 appliances currently exposed online, according to security watchdog Shadowserver, the potential for exploitation is still significant.
SonicWall has urged all customers to upgrade their virtual or physical SMA 1000 appliances to the latest hotfix version as soon as possible. In addition to patching, the company recommends that administrators re-image appliances, change all user and administrator passwords, and reset Time-Based One-Time Password (TOTP) tokens if indicators of compromise are detected.
The exploitation of these vulnerabilities is particularly worrying given their potential impact on large enterprises, government agencies, and critical infrastructure organizations. It’s not the first time SonicWall has faced a zero-day vulnerability in its SMA 1000 appliances – in July, two other flaws were exploited to install custom malware, and last month, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs had begun abusing these vulnerabilities.
The company’s warning serves as a stark reminder of the importance of timely patching and regular security updates. With many organizations still relying on outdated systems and software, the risk of exploitation remains high. As we’ve seen with previous SonicWall vulnerability exploits, the consequences can be severe – from data breaches to ransomware attacks.
So what can you do to protect yourself? First and foremost, ensure that your SMA 1000 appliances are up-to-date with the latest hotfix version. Regularly monitor your systems for indicators of compromise, and consider implementing a robust security monitoring solution to detect potential threats early on.
Source: Bleeping Computer — 2026-09-02