# SonicWall SMA 1000 zero-day exploits

> Live situation record from CLSTR: https://clstr.news/situations/sonicwall-sma-1000-zero-day-exploits
> Updated: 2026-09-02T00:00:00.000Z. Sources: 8. Developments: 2.

SonicWall Secure Mobile Access (SMA) 1000 series appliances have been targeted by active zero-day exploits. Initial reports identified two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, which allow for remote code execution and unauthorized access. The cybercrime group INC Ransomware has been identified as a dominant actor using these flaws to exfiltrate data and deploy ransomware, employing a double-extortion model that includes direct pressure via phone calls and emails to victims across the United States, Australia, the United Arab Emirates, Colombia, and Switzerland.

Subsequent technical details identified specific vulnerabilities affecting physical and virtual models 6210, 7210, and 8200v. These include CVE-2026-83548, a critical pre-authentication server-side request forgery (SSRF) with a CVSS rating of 10.0, and CVE-2026-83549, a post-authentication OS command injection vulnerability. Researchers noted that attackers may chain these vulnerabilities to achieve full device compromise. SonicWall has released hotfixes and advised compromised users to re-image appliances and reset administrative credentials.

## Claims

- SonicWall confirmed that two zero-day vulnerabilities in its SMA 1000 series appliances are being actively exploited. (corroborated by 6 sources)
- CVE-2026-83548 is a pre-authentication SSRF vulnerability with a CVSS severity rating of 10.0. (corroborated by 6 sources)
- CVE-2026-83549 is a post-authentication OS command injection vulnerability with a CVSS severity rating of 7.8. (corroborated by 6 sources)
- Compromised customers are advised to re-image appliances, change all passwords, and reset TOTP tokens. (corroborated by 4 sources)
- The vulnerabilities affect SMA 1000 models 6210, 7210, and 8200v. (corroborated by 3 sources)
- SonicWall has released hotfixes to address the vulnerabilities. (corroborated by 3 sources)
- Attackers may be chaining the two flaws to achieve remote code execution. (corroborated by 2 sources)

## Timeline

### 2026-09-02: SonicWall SMA 1000 appliances targeted by active zero-day exploits

SonicWall is patching two actively exploited zero-day vulnerabilities in its SMA 1000 series appliances, including a critical CVSS 10.0 flaw that allows unauthenticated remote access.

8 sources. https://clstr.news/cluster/sonicwall-warns-of-active-exploitation-of-sma1000-vulnerabilities

### 2026-08-03: INC Ransomware exploits SonicWall SMA 1000 zero‑days, pressures victims

INC Ransomware exploits SonicWall SMA 1000 zero‑day flaws (CVE‑2026‑15409/15410) to breach networks, steal data and pressure victims with calls, affecting firms in the US, Australia, UAE and more.

10 sources. https://clstr.news/cluster/us-cisa-warns-water-utilities-of-plc-cyberattacks-as-inc-ransomware-targets-sonicwall-devices

---
Cite as: SonicWall SMA 1000 zero-day exploits. CLSTR, https://clstr.news/situations/sonicwall-sma-1000-zero-day-exploits
