← Terug naar overzicht

SonicWall has released security updates addressing two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances. The flaws were discovered internally by SonicWall researchers William Perry and Adam Babis. One of the vulnerabilities, CVE-2026-83548, carries a maximum CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability. The two vulnerabilities may form an attack chain, potentially allowing attackers to escalate their access or impact. Active exploitation in the wild has been confirmed, classifying these as zero-day vulnerabilities. SonicWall has urged users to apply the released patches immediately to mitigate risk.

Technical details

Two zero-day vulnerabilities affecting SonicWall SMA 1000 series VPN appliances are being actively exploited and may be chained together to achieve remote code execution. CVE-2026-83548 (CVSS 10.0) is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance Work Place interface, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), allowing a remote authenticated administrator to execute arbitrary commands under specific conditions. Threat actors are chaining CVE-2026-83548 (to bypass authentication) with CVE-2026-83549 (to achieve RCE), forming a full attack chain. This follows a prior incident where CVE-2026-15409 and CVE-2026-15410 were exploited by threat actor UTA0533 to deploy KNUCKLEBALL malware on the same product line.

Mitigation steps

1. Upgrade SonicWall SMA 1000 appliances to the patched versions: 12.4.3-03526 (platform-hotfix) or 12.5.0-02952 (platform-hotfix). 2. Review systems for Indicators of Compromise (IoCs). 3. If IoCs are found: re-image or re-deploy the affected appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) configurations.

Affected products

  • SonicWall SMA 1000 Model 6210 - versions 12.4.3-03453 (platform-hotfix) and older
  • SonicWall SMA 1000 Model 6210 - versions 12.5.0-02835 (platform-hotfix) and older
  • SonicWall SMA 1000 Model 7210 - versions 12.4.3-03453 (platform-hotfix) and older
  • SonicWall SMA 1000 Model 7210 - versions 12.5.0-02835 (platform-hotfix) and older
  • SonicWall SMA 1000 Model 8200v - versions 12.4.3-03453 (platform-hotfix) and older
  • SonicWall SMA 1000 Model 8200v - versions 12.5.0-02835 (platform-hotfix) and older

Related CVE's

  • CVE-2026-15409
  • CVE-2026-15410
  • CVE-2026-83548
  • CVE-2026-83549

Related threat actors

  • UTA0533

Categories

  • Network Infrastructure
  • Zero-Day Vulnerabilities