โ Back to FeedAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
CVE-2026-83548CVE-2026-83549
September 2, 2026 ยท The Hacker News ยท Severity: CRITICAL
Two zero-day vulnerabilities, a pre-auth SSRF (CVE-2026-83548, CVSS 10.0) and a post-auth OS command injection (CVE-2026-83549, CVSS 7.8), are being actively exploited in a chain against SonicWall SMA 1000 series VPN appliances. SonicWall has released hotfixes (versions 12.4.3-03526 and 12.5.0-02952) and recommends immediate patching, checking for IoCs, and re-imaging compromised devices. The vulnerabilities affect SMA 1000 models 6210, 7210, and
๐ **Analyst Note:** This attack chain highlights the critical risk of combining a pre-auth SSRF with a post-auth command injection, enabling full device compromise without credentials. Organizations using SonicWall SMA 1000 series should prioritize patching and thoroughly investigate for signs of
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities , discovered internally by SonicWall's William Perry and Adam Babis, are listed below - CVE-2026-83548 (CVSS score: 10.0) - A pre-authentication SSRF vulnerability in the Appliance Work Place interface that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC) that could allow a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution. SonicWall said it has "investigated a case indicating the active exploitation of the vulnerabilities," suggesting that threat actors are chaining together both the bugs to execute arbitrary code on susceptible devices. The flaws impact the SMA 1000 models 6210, 7210, and 8200v in the following versions - 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions Fixes have been released in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that customers perform the actions outlined below - Upgrade to the latest hotfix version Review the system for indicators of compromise (IoCs) If IoCs are found, re-image or re-deploy the appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) SonicWall has not shared any specifics about the nature of the exploitation activity or who is behind it. The development comes more than a month after it shipped fixes to address two other flaws in the same product CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2) that were exploited by a threat actor dubbed UTA0533 to deploy KNUCKLEBALL malware. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Key Takeaways
- The pre-authentication SSRF vulnerability (CVE-2026-83548, CVSS 10.0) in SonicWall SMA 1000's Appliance Work Place interface allows an unauthenticated attacker to gain unauthorized access to sensitive functionality.
- The post-authentication OS command injection vulnerability (CVE-2026-83549, CVSS 7.8) in the Appliance Management Console requires admin access but can lead to remote code execution when chained with the SSRF flaw.
- SonicWall confirmed active exploitation chaining both bugs, releasing hotfixes for SMA 1000 models 6210, 7210, and 8200v in versions 12.4.3-03526 and 12.5.0-02952, and urging customers to check for compromise and re-image devices if needed.