SonicWall has released security updates addressing two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances. The flaws were discovered internally by SonicWall researchers William Perry and Adam Babis. One of the vulnerabilities, CVE-2026-83548, carries a maximum CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability. The two vulnerabilities may form an attack chain, potentially allowing attackers to escalate their access or impact. Active exploitation in the wild has been confirmed, classifying these as zero-day vulnerabilities. SonicWall has urged users to apply the released patches immediately to mitigate risk.
Two zero-day vulnerabilities affecting SonicWall SMA 1000 series VPN appliances are being actively exploited and may be chained together to achieve remote code execution. CVE-2026-83548 (CVSS 10.0) is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance Work Place interface, allowing remote unauthenticated attackers to gain unauthorized access to sensitive functionality and perform unauthorized operations. CVE-2026-83549 (CVSS 7.8) is a post-authentication OS command injection vulnerability in the Appliance Management Console (AMC), allowing a remote authenticated administrator to execute arbitrary commands under specific conditions. Threat actors are chaining CVE-2026-83548 (to bypass authentication) with CVE-2026-83549 (to achieve RCE), forming a full attack chain. This follows a prior incident where CVE-2026-15409 and CVE-2026-15410 were exploited by threat actor UTA0533 to deploy KNUCKLEBALL malware on the same product line.
1. Upgrade SonicWall SMA 1000 appliances to the patched versions: 12.4.3-03526 (platform-hotfix) or 12.5.0-02952 (platform-hotfix). 2. Review systems for Indicators of Compromise (IoCs). 3. If IoCs are found: re-image or re-deploy the affected appliances, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) configurations.