Back to News
Vulnerabilities

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

Cyber RTSeptember 3, 20263 min read
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has issued security updates for its SMA 1000 series VPN appliances to fix two vulnerabilities exploited in zero-day attacks. The flaws, CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8), allow unauthorized access and remote code execution. Affected models include 6210, 7210, and 8200v. SonicWall advises upgrading to the latest versions and checking for compromise indicators. Previous vulnerabilities were exploited by UTA0533.

SonicWall has recently issued security updates to mitigate two critical vulnerabilities found in its Secure Mobile Access (SMA) 1000 series VPN appliances. These vulnerabilities have been actively exploited in zero-day attacks, posing significant risks to users. The flaws were identified internally by SonicWall's security experts, William Perry and Adam Babis, highlighting the proactive measures taken by the company to address potential security threats. The first vulnerability, identified as CVE-2026-83548, has been assigned a CVSS score of 10.0, indicating its critical nature. This pre-authentication Server-Side Request Forgery (SSRF) vulnerability exists in the Appliance Work Place interface. It allows remote, unauthenticated attackers to gain unauthorized access to sensitive functionalities and perform operations without proper authorization, posing a severe threat to the security of affected systems. The second vulnerability, CVE-2026-83549, has a CVSS score of 7.8 and involves a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). This vulnerability could enable a remote authenticated attacker, particularly those with administrative privileges, to execute arbitrary commands under specific conditions. This could lead to remote code execution, further compromising the security of the affected devices. SonicWall has acknowledged that these vulnerabilities have been actively exploited, with threat actors potentially chaining both flaws to execute arbitrary code on vulnerable devices. This highlights the urgency for users to apply the security patches to protect their systems from potential exploitation. The affected models include SMA 1000 series models 6210, 7210, and 8200v, specifically in versions 12.4.3-03453 and older, as well as 12.5.0-02835 and older. To address these vulnerabilities, SonicWall has released fixes in versions 12.4.3-03526 and 12.5.0-02952. The company strongly recommends that customers upgrade to these latest hotfix versions to secure their systems. Additionally, SonicWall advises users to review their systems for any indicators of compromise (IoCs). If any IoCs are detected, users should re-image or re-deploy the appliances, change all user and administrator passwords, and reset Time-based One-Time Passwords (TOTP). While SonicWall has not disclosed specific details about the exploitation activities or the identities of the attackers, the release of these updates underscores the importance of maintaining robust security measures. This development follows the company's previous efforts to address other vulnerabilities in the same product line, such as CVE-2026-15409 and CVE-2026-15410, which were exploited by a threat actor known as UTA0533 to deploy KNUCKLEBALL malware. SonicWall's proactive approach in identifying and addressing these vulnerabilities demonstrates its commitment to ensuring the security of its products and protecting its users from potential threats. Users are encouraged to stay informed about the latest security updates and follow SonicWall on platforms like Google News, Twitter, and LinkedIn for more exclusive content and updates on cybersecurity developments.