started · updated
SonicWall SMA 1000 appliances targeted by active zero-day exploits
SonicWall has confirmed that attackers are actively exploiting two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances. The flaws affect physical and virtual models 6210, 7210, and 8200v.
The first vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery (SSRF) with a critical CVSS rating of 10.0. It allows unauthenticated remote attackers to gain unauthorized access to sensitive functions. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability (CVSS 7.8) in the Appliance Management Console that can lead to remote code execution.
Security researchers suggest that attackers may be chaining these two vulnerabilities to fully compromise devices. SonicWall has released hotfixes for the affected firmware versions and strongly urges customers to apply them immediately. For devices suspected of being compromised, the company recommends re-imaging or re-deploying the appliances, changing all administrative and user passwords, and resetting time-based one-time password (TOTP) tokens.
Entities
Adam Babis · CVE-2026-83548 · CVE-2026-83549 · SonicWall · William Perry
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] SonicWall confirmed that two zero-day vulnerabilities in its SMA 1000 series appliances are being actively exploited. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more
- [● 2 SOURCES] Attackers may be chaining the two flaws to achieve remote code execution. securityaffairs.com · www.theregister.com
- [● 3 SOURCES] The vulnerabilities affect SMA 1000 models 6210, 7210, and 8200v. cybernoz.com · securityaffairs.com · www.theregister.com
- [● 4 SOURCES] Compromised customers are advised to re-image appliances, change all passwords, and reset TOTP tokens. www.csoonline.com · cybernoz.com · securityaffairs.com · www.theregister.com
- [● 6 SOURCES] CVE-2026-83549 is a post-authentication OS command injection vulnerability with a CVSS severity rating of 7.8. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more
- [● 3 SOURCES] SonicWall has released hotfixes to address the vulnerabilities. cybernoz.com · securityaffairs.com · www.theregister.com
- [● 6 SOURCES] CVE-2026-83548 is a pre-authentication SSRF vulnerability with a CVSS severity rating of 10.0. www.csoonline.com · cybernoz.com · www.it-boltwise.de · securityaffairs.com · www.networkworld.com · +1 more