SonicWall Warns Of Active CVE-2026-83548 Exploit Chain On SMA1000 VPN Gateways

SonicWall is warning SMA1000 customers to patch two new zero-days (CVE-2026-83548 and CVE-2026-83549) that attackers are chaining for unauthenticated remote code execution — the second SSRF-to-injection zero-day round on the platform in seven weeks.

SonicWall Warns Of Active CVE-2026-83548 Exploit Chain On SMA1000 VPN Gateways

SonicWall on September 2 warned customers to patch two new zero-day vulnerabilities in its SMA1000 secure remote-access appliances, saying threat actors are already chaining the flaws for unauthenticated remote code execution in the wild.

Two flaws, one exploit chain

The first issue, CVE-2026-83548, is a maximum-severity CVSS 10 pre-authentication server-side request forgery (SSRF) bug in the SMA1000 Appliance WorkPlace interface. The second, CVE-2026-83549 with a CVSS score of 7.8, is an operating-system command-injection flaw in the SMA1000 Appliance Management Console (AMC). Attackers who reach admin privileges through the SSRF can pivot into the AMC and drop arbitrary OS commands on the box — an end-to-end unauthenticated RCE chain.

"SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible," the company said in a Tuesday advisory published on its PSIRT portal. Affected models are the SMA1000 6210, 7210, and 8200v; the SMA 100 Series and SSL-VPN running on SonicWall firewalls are not affected.

Second SMA1000 zero-day chain in seven weeks

Internet-exposed SonicWall SMA1000 appliances tracked by Shadowserver

The disclosure lands just weeks after SonicWall's July SMA1000 zero-days (CVE-2026-15409 and CVE-2026-15410) were exploited to push custom malware, then quickly picked up by ransomware operators after a CISA warning. The new chain reuses the same SSRF-to-injection pattern — a bad sign for defenders relying on the assumption that July's patch cycle had cleaned the exposure surface.

Internet security watchdog Shadowserver currently tracks more than 400 SMA1000 appliances exposed on the open internet, though some may already be patched against the newest chain. The remote-access gateway is widely used by large enterprises, government agencies, and critical-infrastructure operators — the same target profile ransomware crews have exploited in previous SonicWall waves.

What to do now

SonicWall is urging every SMA1000 operator to upgrade virtual and physical appliances to hotfix 12.4.3-03526, 12.5.0-02952, or higher. If an appliance shows any indicators of compromise, the vendor advises re-imaging the device, rotating every user and administrator password, and resetting TOTP tokens. SonicWall has not yet published IOCs or attribution for the ongoing attacks.

The back-to-back SMA1000 exploitation cycles echo other SonicWall episodes over the past year, including a wave of CVSS 10 flaws in enterprise platforms and vendor-level intrusions such as the ShinyHunters extortion campaign — reinforcing the pattern of edge appliances being turned into initial-access footholds.

Reporting based on coverage from BleepingComputer and SonicWall PSIRT advisory SNWLID-2026-0016.

Category: Cyber Security

Tags: Cybersecurity Zero-Day

Related Articles