Attackers are exploiting two zero-day vulnerabilities affecting select SonicWall SMA 1000 perimeter devices, and customers are urged to patch immediately.
SonicWall disclosed two flaws on Tuesday: pre-authentication server-side request forgery (SSRF) vulnerability CVE-2026-83548 and post-authentication remote code execution (RCE) vulnerability CVE-2026-83549. The former is present in the SMA 1000 Appliance Work Place interface (the user facing portal) and the latter in the SMA 1000 Appliance Management Console (AMC), which is the administrator portal for SMA 1000 remote access gateways.
CVE-2026-83548, the SSRF bug, was designated the maximum CVSS 3.0 score of 10. SonicWall said in its advisory that the vulnerability is caused by an unintended alternate access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the advisory read.
Related:Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
CVE-2026-83549 carries a score of 7.8. SonicWall referred to it as a "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability"; specific conditions could enable an authenticated remote attacker to execute arbitrary OS commands leading to RCE.
In a blog post about the flaws, Rapid7 wrote the vulnerabilities "can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances." Moreover, "No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication."
SonicWall noted that the vendor's Product Security Incident Response Team (PSIRT) "investigated a case indicating the active exploitation of the vulnerabilities described in this advisory." The bugs were internally discovered by SonicWall's William Perry and Adam Babis.
The current exploitation activity follows attacks on two other SMA 1000 zero-days earlier this summer — CVE-2026-15409 and CVE-2026-15410 — which could similarly be chained together for RCE.
SMA 1000 models 6210, 7210, and 8200v are affected, specifically versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. The vendor urged customers to upgrade to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher.
SMA 1000 Attacks Are Ongoing, Patch Now
... continue reading