SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks.

The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness.

This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices.

"SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory.

The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.

Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain.

Internet-exposed SonicWall SMA1000 appliances
Internet-exposed SonicWall SMA1000 appliances (Shadowserver)

SonicWall urged all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version.

While the company also advised admins to re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected, it has yet to share details about these ongoing attacks or a list of IOCs it has found while investigating them.

Such vulnerabilities are often targeted in attacks, given that the SMA1000 is a secure remote access appliance used by large enterprises, government, and critical infrastructure organizations.

In July, two other SonicWall SMA1000 flaws (CVE-2026-15409 and CVE-2026-15410) were exploited in zero-day attacks for weeks to install custom malware on vulnerable VPN appliances. Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs have begun abusing the two vulnerabilities in the wild.

The company also warned customers in December to patch another SMA1000 zero-day vulnerability (CVE-2025-40602) that hackers were chaining to gain root privileges.

One month earlier, SonicWall linked state-backed hackers to a September security breach that exposed customers' firewall configuration backup files after researchers warned of more than 100 SonicWall SSLVPN accounts compromised using stolen credentials.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report
source: BleepingComputer