SonicWall warns of active exploitation of two new SMA1000 zero-day flaws
SonicWall reports that attackers are currently leveraging two chained zero-day vulnerabilities to compromise its SMA1000 remote-access appliances, and urges customers to apply the released hotfixes immediately.
SonicWall confirmed that threat actors are actively exploiting a pair of zero-day flaws in its Secure Mobile Access (SMA) Series 1000 line, targeting midsize and large enterprises that rely on these gateways for VPN and remote-access traffic. The first vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery with a maximum CVSS v3 rating of 10.0, while the second, CVE-2026-83549, is a post-authentication OS command injection scoring 7.8, both impacting the SMA 6210, 7210 and 8200v appliances.
SonicWall has released hotfixes for the affected models and advises customers to work with its technical support to identify indicators of compromise; compromised units should be reimaged or redeployed, passwords changed, and TOTP tokens reset. The company notes that no mitigation exists beyond applying the patches. NHS England echoed the warning, stating that internet-facing edge devices are prime targets and that the National CSOC expects exploitation of these flaws to be almost certain. This follows a series of SMA1000 vulnerabilities disclosed throughout 2025, including a similar SSRF/command-injection pair in July and several other bugs that have been linked to ransomware campaigns.
Why it matters
Enterprises using SonicWall SMA1000 devices face immediate risk of network breach if patches are not applied.
In this story
