Attackers are actively exploiting two new zero-day vulnerabilities in SonicWall SMA 1000 devices, allowing for unauthenticated remote code execution. Immediate patching is required for affected models.
- Two critical zero-day flaws (CVE-2026-83548 and CVE-2026-83549) discovered in SonicWall SMA 1000.
- Vulnerabilities allow for unauthenticated Remote Code Execution (RCE).
- Affected models include 6210, 7210, and 8200v.
- Active exploitation in the wild has been confirmed by SonicWall.
The cybersecurity landscape is facing a significant threat as SonicWall has disclosed the discovery of two critical zero-day vulnerabilities affecting its SMA 1000 perimeter devices. These flaws are being actively exploited by threat actors to achieve unauthenticated remote code execution (RCE), posing a massive risk to enterprise network security.
The first vulnerability, CVE-2026-83548, is a Server-Side Request Forgery (SSRF) flaw located in the SMA 1000 Appliance Work Place interface. It has been assigned a maximum CVSS score of 10.0. The second, CVE-2026-83549, is an OS Command Injection vulnerability within the Appliance Management Console (AMC), carrying a CVSS score of 7.8.
Why This Matters
BozokMedia analysis shows that because SMA 1000 appliances serve as network edge gateways, they are directly exposed to the internet. This makes them high-value targets for attackers. When these vulnerabilities are 'chained' together, as noted by Rapid7, they allow an attacker to bypass authentication entirely and take full control of the device.
By chaining these flaws, attackers can effectively bypass the perimeter defense and execute arbitrary commands on the internal network.
This latest wave of exploitation follows a pattern of similar attacks seen earlier this summer on other SMA 1000 vulnerabilities. The fact that these attacks are ongoing underscores the urgent need for organizations to move beyond reactive security and implement proactive patch management.
Affected Models and Remediation
| Affected Model | Vulnerable Versions | Recommended Patch Version |
|---|---|---|
| SMA 1000 6210 | 12.4.3-03453 / 12.5.0-02835 or older | 12.4.3-03526 or higher |
| SMA 1000 7210 | 12.4.3-03453 / 12.5.0-02835 or older | 12.5.0-02952 or higher |
| SMA 1000 8200v | 12.4.3-03453 / 12.5.0-02835 or older | 12.5.0-02952 or higher |
SonicWall's Product Security Incident Response Team (PSIRT) has advised that if indicators of compromise (IOCs) are detected, customers should immediately re-image hardware, re-deploy virtual appliances, and reset all administrator credentials and TOTP tokens.
Frequently Asked Questions
1. Is there an active exploit for these vulnerabilities?
Yes, SonicWall has confirmed that these vulnerabilities are being actively exploited in the wild.
2. What should I do if I suspect a breach?
You should immediately install the latest firmware, change all passwords, and contact SonicWall technical support for assistance.