SonicWall SMA1000 Faces Critical Zero-Day Exploitation

SonicWall SMA1000 Faces Critical Zero-Day Exploitation

First seen 2 Sep 2026, 15:44 UTC News.SophosNcsa.QaGround.NewsRescanawww.heise.de+19 80.8

Article Content

Browse articles
ThreatCluster

SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability rated 10.0 on the CVSS scale, allowing unauthenticated attackers to access sensitive functionality. CVE-2026-83549 is a post-authentication OS command injection flaw rated 7.8, enabling attackers with admin access to execute arbitrary commands. Both vulnerabilities can be chained for unauthenticated remote code execution (RCE). Affected models include the SMA1000 series 6210, 7210, and 8200v, with SonicWall urging immediate patching to versions 12.4.3-03526 or 12.5.0-02952. The vulnerabilities were confirmed as being exploited in the wild as of September 1, 2026. Organizations are advised to review their systems for signs of compromise and reset credentials if any indicators are found.

Key Points: • Two critical vulnerabilities in SonicWall SMA1000 appliances are actively exploited. • CVE-2026-83548 allows unauthenticated access, while CVE-2026-83549 enables command execution. • Immediate patching is required to mitigate risks associated with these vulnerabilities.

Timeline

2024-02-21
CVE-2024-1708 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-21
CVE-2024-1709 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-17
CVE-2025-40602 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-07-14
CVE-2026-15410 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15409 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
SonicWall discloses two critical vulnerabilities
SonicWall confirmed CVE-2026-83548 and CVE-2026-83549 are actively exploited, urging immediate patching.
Techtimes
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CISA adds vulnerabilities to KEV catalog
CVE-2026-83548 and CVE-2026-83549 were added to the CISA Known Exploited Vulnerabilities list.
Csoonline
2026-09-02
SonicWall releases patches
SonicWall issued hotfixes for the affected SMA1000 models to address the vulnerabilities.
Darkreading