**Critical SonicWall Vulnerabilities Enable Unauthenticated Remote Code Execution**
A fresh wave of attacks is targeting select SonicWall SMA 1000 perimeter devices, leveraging two zero-day vulnerabilities that can be chained together to achieve unauthenticated remote code execution (RCE). The exploitation activity follows earlier this summer’s attacks on two other zero-day vulnerabilities in the vendor’s edge devices.
The affected devices are SonicWall’s SMA 1000 Appliance Work Place interface and Management Console. Specifically, the vulnerabilities were found in models 6210, 7210, and 8200v, with versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older being impacted. SonicWall has urged customers to upgrade to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher immediately.
The pre-authentication server-side request forgery (SSRF) vulnerability, designated CVE-2026-83548, carries the maximum CVSS 3.0 score of 10. This bug is present in the SMA 1000 Appliance Work Place interface, allowing a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. The post-authentication RCE vulnerability, designated CVE-2026-83549, carries a score of 7.8. This flaw affects the SMA 1000 Appliance Management Console (AMC) and enables an authenticated remote attacker to execute arbitrary OS commands leading to RCE.
According to Rapid7’s analysis, these vulnerabilities can be chained together to achieve unauthenticated RCE on affected appliances. While no public proof-of-concept exploit or indicators of compromise were identified at the time of publication, SonicWall has confirmed that the vendor’s Product Security Incident Response Team (PSIRT) investigated a case indicating active exploitation of the vulnerabilities.
The ongoing attacks follow earlier this summer’s attacks on two other SMA 1000 zero-days – CVE-2026-15409 and CVE-2026-15410. These devices sit at the edge of enterprise networks, making them attractive targets for attackers. SonicWall has provided guidance for customers who have been compromised, recommending that they re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens.
This latest round of attacks serves as a reminder of the importance of keeping devices up-to-date with the latest security patches. Organizations using SonicWall SMA 1000 perimeter devices should take immediate action to mitigate these vulnerabilities. By upgrading to the recommended firmware versions and following SonicWall’s guidance, customers can minimize their exposure to potential attacks.
In light of this incident, it is essential for organizations to review their remote access gateways’ configurations and ensure that they are patched against known vulnerabilities. Regularly updating devices and monitoring for indicators of compromise will help prevent future attacks.
Source: Dark Reading — 2026-09-02