Skip to content
SonicWall SMA 1000 Zero

SonicWall SMA 1000 Zero

Darkreading Alexander Culafi September 2, 2026

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

Attackers are exploiting two zero-day vulnerabilities affecting select SonicWall SMA 1000 perimeter devices, and customers are urged to patch immediately.

SonicWall disclosed two flaws on Tuesday: pre-authentication server-side request forgery (SSRF) vulnerability CVE-2026-83548 and post-authentication remote code execution (RCE) vulnerability CVE-2026-83549. The former is present in the SMA 1000 Appliance Work Place interface (the user facing portal) and the latter in the SMA 1000 Appliance Management Console (AMC), which is the administrator portal for SMA 1000 remote access gateways.

CVE-2026-83548, the SSRF bug, was designated the maximum CVSS 3.0 score of 10. SonicWall said in its advisory that the vulnerability is caused by an unintended alternate access path. "A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," the advisory read.

Related: Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

CVE-2026-83549 carries a score of 7.8. SonicWall referred to it as a "Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability"; specific conditions could enable an authenticated remote attacker to execute arbitrary OS commands leading to RCE.

In a blog post the flaws, Rapid7 wrote the vulnerabilities "can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances." Moreover, "No public proof-of-concept exploit, indicators of compromise (IOCs), or attribution for the current activity were identified in the research available at the time of publication."

SonicWall noted that the vendor's Product Security Incident Response Team (PSIRT) "investigated a case indicating the active exploitation of the vulnerabilities described in this advisory." The bugs were internally discovered by SonicWall's William Perry and Adam Babis.

The current exploitation activity follows attacks on two other SMA 1000 zero-days earlier this summer — CVE-2026-15409 and CVE-2026-15410 — which could similarly be chained together for RCE.

SMA 1000 models 6210, 7210, and 8200v are affected, specifically versions 12.4.3-03453/12.5.0-02835 (platform-hotfix) and older. The vendor urged customers to upgrade to 12.4.3-03526/12.5.0-02952 (platform-hotfix) and higher.

SMA 1000 Attacks Are Ongoing, Patch Now

A spokesperson for SonicWall tells Dark Reading that these attacks are ongoing.

"We have confirmed that these vulnerabilities are being actively exploited in the wild," SonicWall says. "Upon discovery, SonicWall promptly investigated and released fixed firmware. We are directing all customers running affected appliances to install the released firmware (12.4.3-03526 or 12.5.0-02952) immediately, review for indicators of compromise, and SonicWall technical support if any are found."

Related: The Vulnpocalypse Is Repricing the Bug Bounty Economy

If IOCs are detected, the customer should re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens.

Remote access gateways such as the SMA 1000 sit at the edge of enterprise networks and are frequently exposed directly to the internet, making them attractive targets for attackers. SonicWall's SMA 1000 appliances specifically have been hit with several zero-day attacks in recent years.

Rapid7 noted that the role of these systems as network edge devices makes successful exploitation particularly concerning. SonicWall's guidance that compromised customers re-image hardware appliances or re-deploy virtual appliances suggests the company views successful exploitation as potentially resulting in significant control over affected systems.

Senior News Writer, Dark Reading

Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.

At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.

He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.

Want more Dark Reading stories in your Google results?

The State of Cloud Security: The Latest Challenges

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

Essential News & Insights from Black Hat USA 2025

How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach

How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach

Cloud Incident Response: Forensics in Distributed Environments

Cloud Incident Response: Forensics in Distributed Environments

Beyond the Login: Key Considerations for Evaluating Identity Security

Beyond the Login: Key Considerations for Evaluating Identity Security

SASE Pivot and Trends 2026: A Gartner Keynote

SASE Pivot and Trends 2026: A Gartner Keynote

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

What Every Enterprise Should Know Securing Cloud Assets In the Age of AI

Cheap Hardware Module Bypasses AMD, Intel Memory Encryption

Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs

Microsoft Issues Emergency Patch for Critical Windows Server Bug

'ShadowLeak' ChatGPT Attack Allows Hackers to Invisibly Steal Emails