Threat Advisories

Active Exploitation of SonicWall SMA1000 Zero-Day Vulnerabilities

Written by Integrity360 | Sep 2, 2026, 12:23:50 PM

SonicWall has released emergency security updates for two vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series appliances after confirming evidence of active exploitation in the wild. The vulnerabilities can potentially be chained together to achieve remote code execution on vulnerable systems.

The flaws consist of a pre-authentication Server-Side Request Forgery (SSRF) vulnerability and a post-authentication operating system command injection vulnerability. SonicWall's investigation determined that threat actors are actively exploiting these vulnerabilities, with indications that both vulnerabilities may be used together as part of an attack chain.

Successful exploitation could result in complete compromise of affected appliances, unauthorized access, credential theft, and potential lateral movement into internal networks.

Vulnerability Details

CVE-2026-83548

Type: Command Injection via SSRF
Severity: Critical (Maximum Severity)

A command injection vulnerability exists within the SMA1000 Appliance WorkPlace interface. The flaw originates from a Server-Side Request Forgery (SSRF) weakness that can be leveraged as part of an exploit chain.

CVE-2026-83549

Type: Command Injection
Severity: Critical

A second command injection vulnerability affects the SMA1000 Appliance Management Console. Attackers with administrative privileges can exploit this flaw to execute arbitrary operating system commands on the appliance.

Exploitation

SonicWall has stated that it investigated a case demonstrating active exploitation of these vulnerabilities and confirmed that threat actors are chaining the flaws in attacks

Affected Products

The vulnerabilities impact the following SonicWall SMA1000 platforms:

  • SMA 6210
  • SMA 7210
  • SMA 8200v

The following products are not affected:

  • SonicWall SSL-VPN running on SonicWall firewalls
  • SonicWall SMA 100 Series appliances

Recommendations

Organisations using SMA1000 appliances should:

  1. Apply the latest SonicWall hotfix release immediately.
  2. Review authentication and administrative access logs for suspicious activity.
  3. Validate appliance integrity and investigate signs of unauthorized configuration changes.
  4. Restrict management interface exposure where operationally feasible.

 

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.