Security advisoryView advisory
CybersecurityCriticalActiveUpdated Sep 2, 2026

SonicWall confirms two SMA1000 zero-days chained in active attacks

A pre-authentication SSRF rated CVSS 10.0 pairs with a management console command injection, and SonicWall's PSIRT says it has already seen the chain used in the wild.

Emanuel De AlmeidaSep 2, 2026, 3:17 PM10 min read
Severity
Critical
Status
Active
Entity
SonicWall SMA1000 series
Confirmed by
SonicWall PSIRT advisory SNWLID-2026-0016

SonicWall is telling SMA1000 customers to install a hotfix immediately after finding that attackers are chaining two previously unknown flaws in its remote access appliances. The vendor's product security incident response team published advisory SNWLID-2026-0016 on Tuesday, 1 September 2026, saying it investigated a case that indicates active exploitation. The chain pairs CVE-2026-83548, a pre-authentication server-side request forgery flaw carrying a maximum CVSS score of 10.0, with CVE-2026-83549, an OS command injection issue in the appliance management console. There's no workaround.

SMA1000 boxes terminate VPN sessions at the network edge for large enterprises, government bodies and service providers. When the first link in the chain needs no credentials, an internet-facing appliance becomes a direct route into the trusted network, and these devices usually carry far less monitoring than the servers behind them.

Key takeaways

  • SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549 in advisory SNWLID-2026-0016, published 1 September 2026.
  • CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, rated CVSS 10.0. CVE-2026-83549 is an OS command injection in the Appliance Management Console, rated 7.8.
  • Affected models are the SMA1000 6210, 7210 and 8200v, physical and virtual. SMA 100 appliances and firewall SSL-VPN aren't affected.
  • A hotfix is available through MySonicWall and there's no workaround. SonicWall hasn't published indicators of compromise or details of the attacks.
  • Shadowserver data cited by BleepingComputer showed more than 400 SMA1000 appliances reachable from the internet, some of which may already be patched.

Affected

Vendors
SonicWall
Products
SonicWall SMA1000 6210SonicWall SMA1000 7210SonicWall SMA1000 8200v
Geography
global
Industry
Enterprise ITGovernmentCritical infrastructureManaged service providers
CVEs
CVE-2026-83548CVE-2026-83549

SonicWall confirms exploitation of two new SMA1000 flaws

SonicWall disclosed two previously unknown SMA1000 vulnerabilities on 1 September 2026 and said both are being exploited. Advisory SNWLID-2026-0016 states that the company's product security incident response team investigated a case indicating active exploitation, and it urges customers onto the hotfix release as fast as they can manage.

The two issues work as a chain. CVE-2026-83548 gets an attacker in without credentials, and CVE-2026-83549 turns that access into command execution on the appliance. Per Help Net Security's 2 September report, SonicWall credited its own researchers, William Perry and Adam Babis, with finding the flaws, which means the vendor spotted the activity internally rather than learning of it from a customer report.

The company hasn't described the attacks, named an actor, or released indicators of compromise.

  • Advisory ID: SNWLID-2026-0016, published 1 September 2026.
  • Discovery credited to SonicWall's William Perry and Adam Babis.
  • No IoCs, no attribution, and no attack details published so far.

How the exploit chain works

The chain starts with CVE-2026-83548, a pre-authentication server-side request forgery flaw in the SMA1000 Appliance Work Place interface. Server-side request forgery is a class of bug where an attacker gets a server to make network requests on their behalf. SonicWall describes the root cause as an unintended alternate access path that lets the appliance act as a forward proxy.

That flaw carries a CVSS score of 10.0 and maps to CWE-918 and CWE-441, the confused deputy pattern. CVE-2026-83549 is the second link: an OS command injection issue in the Appliance Management Console, scored 7.8, exploitable in specific conditions by an attacker holding admin privileges.

On its own the second bug is a post-authentication problem. Chained behind an unauthenticated SSRF, the authentication requirement stops being much of a barrier, which is why the pair adds up to unauthenticated remote code execution.

Why SSRF hits harder on edge appliances

The appliance sits on the network boundary and can usually reach internal services the internet can't. Requests made from the device inherit trust the attacker never earned.

  • CVE-2026-83548: pre-auth SSRF in the Appliance Work Place interface, CVSS 10.0, CWE-918 and CWE-441.
  • CVE-2026-83549: OS command injection in the Appliance Management Console, CVSS 7.8, requires admin privileges.
  • Chained, the two give unauthenticated remote code execution on the appliance.

Which appliances and builds are in scope

The flaws affect SMA1000 models 6210, 7210 and 8200v, in both hardware and virtual form. SonicWall states that SMA 100 series appliances and SSL-VPN running on SonicWall firewalls aren't affected, which rules out a large share of the installed base.

Reporting on the advisory puts the affected builds at platform hotfix 12.4.3-03453 and earlier, and 12.5.0-02835 and earlier. Fixed builds are given as 12.4.3-03526 and 12.5.0-02952. Check your branch against the advisory itself before planning the upgrade, because build numbers move between hotfix rounds.

Exposure is the other half of the picture. Shadowserver data cited by BleepingComputer on 2 September showed more than 400 SMA1000 appliances reachable from the internet, though some may already run a fixed build. The install base skews toward organisations that make attractive targets: large enterprises, government agencies, critical infrastructure operators and managed service providers.

  • Affected models: SMA1000 6210, 7210 and 8200v, physical and virtual.
  • Not affected: SMA 100 series appliances and SSL-VPN on SonicWall firewalls.
  • Affected builds: platform hotfix 12.4.3-03453 and earlier, 12.5.0-02835 and earlier.
  • More than 400 SMA1000 appliances were visible online in Shadowserver data cited by BleepingComputer.

What SonicWall is telling customers

SonicWall's guidance is short and unusually direct. Upgrade every physical or virtual SMA1000 appliance to the latest platform hotfix, available through MySonicWall. Contact SonicWall Technical Support for help reviewing the system for indicators of compromise. If compromise is confirmed, re-image the hardware or redeploy the virtual appliance, change all user and administrator passwords, and reset TOTP tokens.

That last set of steps deserves attention. Resetting passwords and TOTP seeds only makes sense if you assume credentials and second-factor secrets stored on the box were readable to the attacker. Treat a compromised SMA1000 as a credential store that leaked, not just a device that needs a patch.

The gap in the response is detection. Without published IoCs, customers can't self-check with any confidence, which is why the advisory routes them to support instead.

  • SonicWall says there's no workaround. Patching is the only fix.
  • Compromise response: re-image or redeploy, rotate all passwords, reset TOTP tokens.
  • No public IoC list, so compromise assessment runs through SonicWall Technical Support.

What to do now

Patch first, investigate second, and don't reverse the order. An actively exploited pre-auth chain on an internet-facing appliance doesn't leave room for a normal change window.

  1. Identify every SMA1000 in the estate, including virtual 8200v instances that may not be in the hardware inventory.
  2. Record the current platform hotfix build, then upgrade to the fixed build for your branch as listed in SNWLID-2026-0016.
  3. Pull and preserve appliance logs before the upgrade, so you keep evidence of any pre-patch activity.
  4. Open a case with SonicWall Technical Support for a compromise review rather than waiting for an IoC list.
  5. If anything looks wrong, re-image or redeploy, then rotate every user and admin credential and reset TOTP tokens.
  6. Review whether the appliance needs to be internet-facing at all, and keep management interfaces off the public internet.

No workaround exists

SonicWall hasn't published a mitigation short of patching. If an appliance can't take the hotfix today, remove its internet exposure until it can.

For MSPs, the inventory step is the one that bites. A single unpatched client appliance is enough to make the rest of the fleet work irrelevant.

  • No workaround exists, so patching is mandatory rather than optional.
  • Preserve logs before upgrading, since the hotfix won't tell you whether you were hit.

Why SMA1000 keeps showing up in exploitation reports

This is not the first SMA1000 emergency of the year. In July 2026, BleepingComputer reported that CVE-2026-15409 and CVE-2026-15410 had been exploited as zero-days for weeks to install custom malware on vulnerable appliances. In August, per the same outlet, CISA confirmed ransomware crews had picked up the pair. Before that, in December 2025, SonicWall warned about CVE-2025-40602, another SMA1000 zero-day being chained to reach root.

The wider run of SonicWall incidents adds context. In November 2025 the company linked state-backed hackers to a September 2025 breach that exposed customer firewall configuration backups, following reports of more than 100 SonicWall SSL-VPN accounts compromised with stolen credentials.

The pattern isn't unique to SonicWall. Edge appliances run vendor code you can't inspect, terminate encrypted sessions, and hold credentials. That combination keeps them near the top of the target list.

  • July 2026: CVE-2026-15409 and CVE-2026-15410 exploited as zero-days to deploy custom malware.
  • August 2026: CISA confirmed ransomware gangs abusing those two flaws.
  • December 2025: CVE-2025-40602 chained by attackers to gain root privileges.

What to watch next

Three things will shape how bad this gets. The first is CISA's Known Exploited Vulnerabilities catalogue. As of SecurityWeek's reporting on 2 September, neither CVE had been added, though the catalogue already listed 17 SonicWall flaws. A KEV entry would put a federal remediation deadline on the clock and give private-sector teams a yardstick.

The second is indicators of compromise. SonicWall hasn't shared any, and without them nobody outside the vendor can hunt properly. Watch for a follow-up advisory or a write-up from an incident response firm.

The third is who's behind it. The July flaws moved from targeted zero-day use to ransomware within weeks. If that pattern repeats, exposure counts matter more than the initial victim list, and the window for quiet patching closes fast.

  • Neither CVE was in CISA KEV as of 2 September 2026, per SecurityWeek.
  • CISA KEV already lists 17 SonicWall product vulnerabilities.

Timeline

SonicWall warns of an earlier SMA1000 zero-dayDecember 2025: SonicWall told customers to patch CVE-2025-40602, an SMA1000 flaw attackers were chaining to reach root privileges.
Two SMA1000 flaws exploited as zero-days for weeksJuly 2026: CVE-2026-15409 and CVE-2026-15410 were used in zero-day attacks to install custom malware on vulnerable appliances.
CISA links the July flaws to ransomware activityAugust 2026: the US Cybersecurity and Infrastructure Security Agency confirmed ransomware crews had started abusing the two July vulnerabilities.
Sep 1, 2026
SonicWall publishes SNWLID-2026-0016The vendor discloses CVE-2026-83548 and CVE-2026-83549, says its PSIRT investigated a case indicating active exploitation, and urges customers onto the hotfix.
Sep 2, 2026
Exposure figures and coverage followSecurity press reports the advisory. Shadowserver data cited by BleepingComputer shows more than 400 SMA1000 appliances reachable from the internet.

Impact & actions

Any unpatched, internet-facing SMA1000 6210, 7210 or 8200v appliance can be taken over remotely without credentials by chaining CVE-2026-83548 and CVE-2026-83549. Because the appliance holds VPN user credentials and TOTP seeds, a successful compromise turns into an identity problem as well as a device problem.

Security: An attacker who lands on the appliance gains a foothold at the network boundary, with the trust that position carries and limited monitoring in most environments. Stored credentials and TOTP seeds should be treated as exposed.

Privacy: Not established. SonicWall hasn't reported data access or exfiltration in these attacks.

Recommended actions · Immediate urgency

  1. 1Inventory all SMA1000 appliances, including virtual 8200v instances.
  2. 2Upgrade to the fixed platform hotfix build for your branch, per SNWLID-2026-0016.
  3. 3Preserve appliance logs before upgrading so pre-patch activity stays available for review.
  4. 4Open a case with SonicWall Technical Support for a compromise review.
  5. 5If compromise is confirmed, re-image or redeploy, rotate all user and admin passwords, and reset TOTP tokens.
  6. 6Remove management interfaces from the public internet and reassess whether the appliance needs internet exposure at all.

Technical details

CVEs
CVE-2026-83548, CVE-2026-83549
CVSS
10
Exploitation
Exploited in the wild
Attack vector
Network. Remote, unauthenticated access to the Appliance Work Place interface via SSRF (CVE-2026-83548), chained with OS command injection in the Appliance Management Console (CVE-2026-83549).
Affected versions
SMA1000 platform hotfix 12.4.3-03453 and earlier, SMA1000 platform hotfix 12.5.0-02835 and earlier
Patched versions
12.4.3-03526 or later, 12.5.0-02952 or later

Mitigations

  • Upgrade physical and virtual SMA1000 appliances to the latest platform hotfix via MySonicWall.
  • Re-image hardware appliances or redeploy virtual appliances where compromise is confirmed.
  • Change all user and administrator passwords after a confirmed compromise.
  • Reset TOTP tokens after a confirmed compromise.

Response

Vendor

SonicWall's PSIRT says it investigated a case indicating active exploitation of both vulnerabilities and strongly urges customers to move to the hotfix release as soon as possible.

Customer guidance

Upgrade every physical or virtual SMA1000 appliance to the latest platform hotfix from MySonicWall. Contact SonicWall Technical Support to review the system for indicators of compromise. Where compromise is confirmed, re-image or redeploy the appliance, change all user and administrator passwords, and reset TOTP tokens.

Patch / advisory

Updates

Sep 2, 2026Initial draft

First version, based on SonicWall advisory SNWLID-2026-0016 and same-day reporting. No IoCs published and neither CVE listed in CISA KEV at time of writing.

Sep 2, 2026Post-publication sourcing pass

Added per-section key facts and related sources, restored the supportsClaims mapping on every source, and updated source notes. Build numbers now have a second independent secondary source. The SonicWall advisory page still cannot be read directly, so the publication date, build numbers and PSIRT wording remain unconfirmed against the primary source.

FAQ

Which SonicWall products are affected by CVE-2026-83548 and CVE-2026-83549?

The SMA1000 6210, 7210 and 8200v models, in both physical and virtual form. SonicWall states that SMA 100 series appliances and SSL-VPN running on SonicWall firewalls aren't affected by these two vulnerabilities.

Is there a workaround if I can't patch immediately?

No. SonicWall hasn't published a workaround, so upgrading to the fixed platform hotfix is the only remediation. If an appliance can't be patched right away, the practical fallback is removing its internet exposure until it can be.

How do I tell whether my SMA1000 has been compromised?

SonicWall hasn't released indicators of compromise for these attacks. Its advisory directs customers to contact SonicWall Technical Support for a compromise review. Preserve appliance logs before you upgrade, because the hotfix won't tell you what happened beforehand.

What should I do if I find signs of compromise?

Follow SonicWall's guidance: re-image the hardware appliance or redeploy the virtual one, change all user and administrator passwords, and reset TOTP tokens. Treat credentials and second-factor seeds stored on the appliance as exposed.

Are these vulnerabilities in the CISA KEV catalogue?

Not as of 2 September 2026, according to SecurityWeek, though the catalogue already lists 17 SonicWall product vulnerabilities. Check the KEV catalogue directly, since entries are added as agencies confirm exploitation.

The bottom line

SonicWall disclosed two SMA1000 zero-days on 1 September 2026 and confirmed both are being chained in real attacks. CVE-2026-83548 needs no authentication and scores 10.0; CVE-2026-83549 turns that access into command execution. A hotfix is out and there's no workaround.

What happens next

Watch for a CISA KEV listing, published indicators of compromise, and any incident response write-up that names the activity. The July 2026 SMA1000 flaws went from targeted zero-day use to ransomware within weeks.

What to do

Inventory your SMA1000 appliances and upgrade to the fixed platform hotfix build today.

Reader reviews

Rate this articleBe the first to rate
No written reviews yetRate the article above, or be the first to share your experience.

Related articles