SonicWall SMA1000 Faces Third Zero-Day Exploitation in 2026

SonicWall SMA1000 Faces Third Zero-Day Exploitation in 2026

First seen 2 Sep 2026, 15:44 UTC News.SophosNcsa.QaGround.NewsRescanawww.heise.de+7 80.8

Article Content

Browse articles
ThreatCluster

SonicWall's SMA1000 VPN appliances are under active exploitation due to two newly discovered zero-day vulnerabilities, CVE-2026-83548 and CVE-2026-83549, which were confirmed on September 1, 2026. The first vulnerability, an SSRF flaw with a CVSS score of 10.0, allows unauthenticated attackers to gain unauthorized access to sensitive functionalities. The second vulnerability, an OS command injection flaw with a CVSS score of 7.8, requires administrator-level access but can lead to arbitrary command execution. Attackers are chaining these vulnerabilities to achieve full compromise of affected systems, which include models 6210, 7210, and 8200v. SonicWall has released patches for these vulnerabilities, urging affected organizations to upgrade immediately. The ongoing exploitation has raised significant concerns among enterprise and government organizations relying on these VPN appliances. Previous incidents involving the same product line indicate a troubling trend of repeated vulnerabilities and exploitation.

Key Points: • SonicWall SMA1000 appliances face active exploitation of two critical vulnerabilities. • CVE-2026-83548 (CVSS 10.0) allows unauthenticated access, while CVE-2026-83549 (CVSS 7.8) requires admin access. • SonicWall has issued patches and urges immediate action from affected organizations.

Timeline

2024-02-21
CVE-2024-1708 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2024-02-21
CVE-2024-1709 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-12-17
CVE-2025-40602 added to CISA KEV
CISA flagged the vulnerability as actively exploited in the wild and added it to the Known Exploited Vulnerabilities catalog.
CISA KEV
2026-07-14
CVE-2026-15409 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-14
CVE-2026-15410 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
SonicWall discloses two zero-day vulnerabilities
SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549, urging immediate patching.
Securityaffairs.Co
2026-09-01
CVE-2026-83549 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-83548 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-02
CISA adds vulnerabilities to KEV catalog
CVE-2026-83548 and CVE-2026-83549 were added to the CISA KEV catalog due to confirmed exploitation.
Techtimes
2026-09-02
SonicWall releases patches
SonicWall issued security updates for the vulnerabilities, urging users to upgrade their systems immediately.
Ground.News