• News/
  • bleepingcomputer-20260902063929

SonicWall warns of actively exploited SMA1000 zero-day flaws

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 2, 2026
·
Updated

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. The first is a maximum-severity command injection flaw (CVE-2026-83548) found in the SMA1000 Appliance WorkPlace interface that stems from a server-side request forgery (SSRF) weakness. This actively exploited zero-day chain also targets a command injection vulnerability (CVE-2026-83549) in the SMA1000 Appliance Management Console that attackers with admin privileges can exploit to execute arbitrary OS commands on vulnerable devices. "SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company warned in a Tuesday advisory. The two security flaws affect SMA1000 6210, 7210, and 8200v models, but they don't affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line. Internet security watchdog Shadowserver currently tracks over 400 SMA1000 appliances exposed online, although some may already have been patched against this exploit chain. SonicWall urged all customers to upgrade their virtual or physical SMA1000 appliances to the latest hotfix version. While the company also advised admins to re-image appliances, change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected, it has yet...

Read full article

Affected Software

2 affected components
SonicWall SMA1000 Appliance WorkPlace interface=SMA1000 6210, =SMA1000 7210, =SMA1000 8200v
SonicWall SMA1000 Appliance Management Console=SMA1000 6210, =SMA1000 7210, =SMA1000 8200v

Frequently Asked Questions

1

Which SonicWall devices are affected by the actively exploited vulnerabilities?

The vulnerabilities affect SMA1000 6210, 7210, and 8200v models. They do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 Series product line.

2

What should SMA1000 administrators do?

SonicWall strongly urges customers to upgrade to the hotfix release as soon as possible. The company says the hotfix remediates the vulnerability chain.

3

What is known about exploitation of these flaws?

SonicWall PSIRT investigated a case indicating active exploitation, and the flaws are identified as zero-days. The exploit chain combines CVE-2026-83548 and CVE-2026-83549 to achieve remote code execution.

4

What access is required to exploit the second vulnerability?

CVE-2026-83549 is a command injection vulnerability in the SMA1000 Appliance Management Console. Attackers need administrator privileges to use it to execute arbitrary operating-system commands on vulnerable devices.

5

How exposed are SMA1000 appliances on the internet?

Shadowserver tracks more than 400 SMA1000 appliances exposed online. Some of those systems may already have been patched against the exploit chain.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203