← Terug naar overzicht

SonicWall has issued a warning to customers regarding two newly discovered zero-day vulnerabilities affecting its SMA1000 series appliances. Threat actors are actively chaining these two flaws together to achieve remote code execution. The vulnerabilities are being exploited in the wild, making them a critical and immediate threat. SonicWall has urged customers to apply patches or mitigations as soon as possible. The SMA1000 product line is used for secure remote access in enterprise environments, making it a high-value target. The chaining of two zero-days suggests a sophisticated threat actor. No CVE identifiers were specified in the available content. Organizations using SMA1000 devices should treat this as a high-priority incident response situation.

Technical details

Two new zero-day vulnerabilities in SonicWall SMA1000 appliances are being actively chained by threat actors in remote code execution attacks. CVE-2026-83548 is a maximum-severity command injection vulnerability found in the SMA1000 Appliance WorkPlace interface, rooted in a server-side request forgery (SSRF) weakness. CVE-2026-83549 is a command injection vulnerability in the SMA1000 Appliance Management Console that requires admin privileges to exploit, allowing execution of arbitrary OS commands on vulnerable devices. The two flaws are being used in combination as an exploit chain. Over 400 SMA1000 appliances are currently exposed on the internet according to Shadowserver. The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v but do not affect SSL-VPN on SonicWall firewalls or the SMA 100 Series product line. This is part of a broader pattern of SMA1000 exploitation, including prior zero-days (CVE-2026-15409, CVE-2026-15410) used to install custom malware, and CVE-2025-40602 chained for root privilege escalation.

Mitigation steps

1. Upgrade all virtual or physical SMA1000 appliances to the latest hotfix version immediately as directed in SonicWall advisory SNWLID-2026-0016. 2. If indicators of compromise (IOCs) are detected, re-image the appliance entirely. 3. Change all user and administrator passwords if compromise is suspected. 4. Reset TOTP tokens if indicators of compromise are found. 5. Monitor internet-exposed SMA1000 appliances for signs of exploitation. 6. Check Shadowserver dashboards to identify exposed appliances in your organization.

Affected products

  • SonicWall SMA1000 6210
  • SonicWall SMA1000 7210
  • SonicWall SMA1000 8200v

Related CVE's

  • CVE-2025-40602
  • CVE-2026-15409
  • CVE-2026-15410
  • CVE-2026-83548
  • CVE-2026-83549

Related threat actors

  • Ransomware gangs (exploiting CVE-2026-15409 and CVE-2026-15410 per CISA)
  • State-sponsored hackers (linked to September MySonicWall breach)

Categories

  • Critical Infrastructure
  • Network Infrastructure
  • Zero-Day Vulnerabilities