HackMyIP
← Back to News
2026-09-02 SecurityWeek

SonicWall SMA1000 Zero-Days Exploited in the Wild: Patch Now

Zero-DayVulnerability

SonicWall is urging customers to immediately patch two zero-day vulnerabilities in its SMA1000 secure remote access gateway that the company confirmed are being actively exploited in attacks. The flaws were discovered internally and disclosed in a Tuesday advisory, with the vendor noting that chaining the two bugs enables attackers to gain deeper access to affected appliances. Affected models include the SMA1000 6210, 7210, and 8200v, and remediation is available through hotfixes 12.4.3-03526 and 12.5.0-02952 (and higher).

The first vulnerability, tracked as CVE-2026-83548, carries a maximum CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) flaw in the Appliance Work Place interface. A remote, unauthenticated attacker can exploit it to reach sensitive internal functionality and perform unauthorized operations, making it the more dangerous of the two bugs. The second flaw, CVE-2026-83549 (CVSS 7.8), is an OS command injection vulnerability in the Appliance Management Console (AMC) component that allows an authenticated attacker to execute arbitrary operating system commands, potentially leading to full remote code execution. Administrators can validate the SSL posture of their SSL-VPN endpoints with an SSL/TLS checker while preparing for patch deployment.

SonicWall product vulnerabilities have long been a favored target for ransomware operators and other threat actors, and 17 SonicWall flaws currently appear in CISA's Known Exploited Vulnerabilities catalog, though the two new CVEs have not yet been added. The vendor has not published indicators of compromise, and no technical details of in-the-wild attacks have been disclosed, leaving defenders to rely on patching and post-exploit hardening. SSL-VPN on SonicWall firewalls and SMA100 series appliances are confirmed unaffected, narrowing the scope of exposure. Defenders should also enforce strong credential hygiene on management interfaces — a quick password checker review of admin and AMC accounts is a sensible precaution given the authenticated path required by CVE-2026-83549 — and monitor appliance logs for anomalous requests to the Appliance Work Place interface that could indicate CVE-2026-83548 probing.

Source: SecurityWeek →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →