**Zero-Day Flaws in SonicWall Appliances Actively Exploited by Threat Actors**
Security researchers have sounded the alarm once again about a pair of zero-day vulnerabilities in SonicWall’s Secure Remote Access (SRA) appliance, known as SMA1000. The company has confirmed that these flaws are being actively exploited by threat actors to launch remote code execution attacks against vulnerable devices. This is not an isolated incident – it’s just the latest example of a critical security vulnerability in a popular secure remote access solution.
The two vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, are being used in tandem by attackers to inject malicious commands into affected appliances. The first flaw is a server-side request forgery (SSRF) weakness that exists in the SMA1000 Appliance WorkPlace interface. When exploited, this vulnerability allows an attacker to execute arbitrary OS commands on vulnerable devices. The second flaw is a command injection vulnerability in the SMA1000 Appliance Management Console that can be exploited by attackers with administrative privileges.
These zero-day flaws affect specific models of the SMA1000 appliance, including the 6210, 7210, and 8200v models. However, it’s worth noting that these vulnerabilities do not impact SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. According to the security watchdog Shadowserver, over 400 SMA1000 appliances are currently exposed online, although some may already have been patched against this exploit chain.
SonicWall is urging all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version as soon as possible. The company also recommends that administrators re-image affected appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise are detected.
This vulnerability is particularly concerning because it targets a secure remote access solution used by large enterprises, government agencies, and critical infrastructure organizations. As we’ve seen in previous incidents, such vulnerabilities are often targeted in attacks due to their potential for widespread exploitation and the sensitive nature of the data being protected.
The SonicWall SMA1000 has been plagued with security issues in recent months. In July, two other flaws (CVE-2026-15409 and CVE-2026-15410) were exploited in zero-day attacks to install custom malware on vulnerable VPN appliances. Last month, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs have begun abusing these vulnerabilities in the wild.
**What Can You Do?**
If you’re a SonicWall customer using the SMA1000 appliance, it’s essential to take immediate action to protect your organization from this actively exploited vulnerability. Follow SonicWall’s guidance and upgrade your appliances to the latest hotfix version as soon as possible. Additionally, consider re-imaging affected devices, changing passwords, and resetting TOTP tokens as a precautionary measure. Remember that prevention scores can be deceiving – once attackers have valid credentials, they often go undetected until it’s too late. Stay vigilant and prioritize timely patching to minimize the risk of exploitation.
Source: Bleeping Computer — 2026-09-02