SonicWall has warned customers that attackers are actively exploiting two SonicWall SMA1000 zero-days in a chain that can enable remote code execution on vulnerable appliances.

The company urges organisations to install the latest hotfix immediately and investigate any signs of compromise.

Two flaws allow command execution

The attack chain includes CVE-2026-83548, a maximum-severity command injection flaw in the SMA1000 Appliance WorkPlace interface.

SonicWall said the weakness stems from a server-side request forgery issue. Attackers can use it alongside CVE-2026-83549, another command injection flaw in the SMA1000 Appliance Management Console.

The second flaw requires administrator privileges, but it allows attackers to run arbitrary operating-system commands on affected devices.

SonicWall’s product security team said it has investigated a case that indicates active exploitation of the vulnerabilities.

SMA1000 appliances require urgent patching

The SonicWall SMA1000 zero-days affect the SMA1000 6210, 7210 and 8200v models.

They do not affect SSL-VPN services running on SonicWall firewalls or the SMA 100 Series product line.

Shadowserver currently tracks more than 400 SMA1000 appliances exposed to the internet. Some may already have received the hotfix, but internet-facing appliances remain particularly attractive targets.

SonicWall recommends that customers update both physical and virtual SMA1000 appliances to the latest hotfix release as soon as possible.

Organisations should check for compromise

If administrators find indicators of compromise, SonicWall recommends re-imaging the affected appliance, changing all administrator and user passwords, and resetting time-based one-time password tokens.

The company has not yet shared technical details about the active attacks or indicators of compromise.

SMA1000 devices provide secure remote access for large enterprises, government bodies and critical-infrastructure organisations. That role makes successful exploitation especially serious.

Attackers have repeatedly targeted SonicWall SMA1000 vulnerabilities. Earlier zero-days were used to install custom malware, and CISA later confirmed that ransomware groups had begun exploiting some of those flaws.


0 responses to “SonicWall Warns of Actively Exploited SMA1000 Zero-Days”