SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices. "SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory. The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain. SonicWall urged all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version. While the company also advised admins to re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected, it has yet...
SonicWall warns of actively exploited SMA1000 zero-day flaws
Affected Software
Frequently Asked Questions
Which SonicWall devices are affected by the actively exploited vulnerabilities?
The vulnerabilities affect SMA1000 6210, 7210, and 8200v models. They do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.
What should SMA1000 administrators do?
SonicWall strongly urges customers to upgrade to the hotfix release as soon as possible. The company says the hotfix remediates the vulnerability chain.
What is known about exploitation of these flaws?
SonicWall PSIRT investigated a case indicating active exploitation, and the flaws are identified as zero-days. The exploit chain combines CVE-2026-83548 and CVE-2026-83549 to achieve remote code execution.
What access is required to exploit the second vulnerability?
CVE-2026-83549 is a command injection vulnerability in the SMA1000 Appliance Management Console. Attackers need administrator privileges to use it to execute arbitrary operating-system commands on vulnerable devices.
How exposed are SMA1000 appliances on the internet?
Shadowserver tracks more than 400 SMA1000 appliances exposed online. Some of those systems may already have been patched against the exploit chain.