HackMyIP
← Back to News
2026-09-02 The Hacker News

SonicWall SMA 1000 Zero-Days Exploited in Active Attack Chain

Zero-DayVulnerabilityThreat Intel

SonicWall has released emergency patches for two critical vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances that are being actively exploited as a chained attack. The flaws—CVE-2026-83548 with a maximum CVSS score of 10.0 and CVE-2026-83549 scoring 7.8—were discovered internally by researchers William Perry and Adam Babis and could allow attackers to achieve unauthenticated remote code execution on vulnerable devices.

The first flaw, CVE-2026-83548, is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance Work Place interface, enabling remote unauthenticated attackers to access sensitive functionality. The second, CVE-2026-83549, is a post-authentication OS command injection in the Appliance Management Console (AMC) that, when chained, allows an authenticated administrator to execute arbitrary commands. SonicWall confirmed it "investigated a case indicating the active exploitation of the vulnerabilities," signaling a live attack chain in the wild. The flaws affect SMA 1000 models 6210, 7210, and 8200v running versions 12.4.3-03453 or earlier, and 12.5.0-02835 or earlier, with fixes shipped in 12.4.3-03526 and 12.5.0-02952 hotfix builds.

SonicWall is urging customers to immediately upgrade to the patched hotfix versions, audit systems for indicators of compromise (IoCs), and—if evidence of intrusion is found—re-image or re-deploy the appliances, rotate all user and administrator credentials, and reset Time-based One-Time Password (TOTP) secrets. Administrators are also advised to validate external exposure of their VPN gateways using a port scanner to confirm only intended services are reachable, and to verify the integrity of appliance certificates with an SSL/TLS checker. Any newly issued credentials should be tested for strength and prior exposure via a password checker before deployment.

The disclosure follows a related campaign from July 2025 in which the threat actor tracked as UTA0533 exploited two earlier SMA 1000 flaws—CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2)—to deploy the KNUCKLEBALL credential-harvesting backdoor. SonicWall has not attributed the current activity to any specific group or shared IoCs publicly, leaving defenders reliant on forensic analysis of appliance logs and behavior. With chained pre-auth and post-auth zero-days now confirmed in active use, organizations running SMA 1000 appliances should treat the patching window as urgent and assume attempted probing until mitigations are applied.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Browser Fingerprint →Privacy Checkup →VPN & Proxy Detector →

Related Guides

Learn the background behind this story:

What is a VPN? →How websites track you →Browser fingerprinting explained →