SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

A Critical Alert for SonicWall Customers: Zero-Day Vulnerabilities Exploited in the Wild

SonicWall is sounding the alarm for its customers, urging them to patch two newly discovered zero-day vulnerabilities that have been exploited by attackers. The flaws affect the SMA1000 series of secure remote access gateways and SSL-VPN appliances, putting sensitive data at risk.

The first vulnerability, tracked as CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit this flaw remotely without authentication to access sensitive functionality and conduct unauthorized operations. This means that an attacker doesn’t need any credentials or login information to gain access to the affected device.

The second vulnerability, CVE-2026-83549, is a more serious issue – an OS command injection flaw in the Appliance Management Console (AMC) component of SMA1000 appliances. An authenticated attacker can exploit this vulnerability to execute arbitrary operating system commands, potentially leading to remote code execution and further attacks.

SonicWall has observed exploitation of both vulnerabilities, indicating that they have been chained together in attacks. The affected products are SMA1000 models 6210, 7210, and 8200v, and patching is recommended immediately. However, SSL-VPN on SonicWall firewalls and SMA100 series products are not affected by these vulnerabilities.

It’s worth noting that this is not the first time SonicWall product vulnerabilities have been exploited in the wild. Ransomware attackers have been known to target such flaws, highlighting the importance of timely patching and vulnerability management. The US Cybersecurity and Infrastructure Security Agency (CISA) has listed 17 SonicWall product flaws in its Known Exploited Vulnerabilities catalog, but these two new vulnerabilities are not yet included.

As a result, it’s essential for SMA1000 customers to act quickly to protect their systems from potential attacks. Applying hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions will patch the vulnerabilities. It’s also crucial to maintain up-to-date security awareness and ensure that all devices are properly configured to prevent unauthorized access.

In summary, SonicWall customers must take immediate action to protect their SMA1000 appliances from these newly discovered zero-day vulnerabilities. Patches are available, but prompt action is necessary to prevent potential attacks. As always, cybersecurity vigilance is key to preventing breaches and protecting sensitive data.


Source: SecurityWeek — 2026-09-02