SonicWall reported finding two zero-day vulnerabilities in SonicWall SMA1000 appliances that can be exploited remotely and are being chained to achieve remote code execution.
Vulnerabilities Affect SMA1000 Appliances
The vulnerabilities affect SonicWall SMA1000 6210, 7210, and 8200v models. The affected software versions are 12.4.3-03453 platform-hotfix and older versions and 12.5.0-02835 platform-hotfix and older versions. The vulnerabilities have no impact on SSL-VPN working on SonicWall firewalls or SonicWall SMA 100 Series products.
Vulnerability CVE-2026-83548 involves a pre-authentication server-side request forgery affecting the Appliance Work Place interface. The vulnerability allows command injection and has a CVSS v3.1 severity score of 10. Successful exploitation permits a threat actor to access sensitive functions and carry out unauthorized actions remotely.
Vulnerability CVE-2026-83549 is an OS command injection vulnerability in the Appliance Management Console. It has a CVSS v3.1 severity score of 7.8. Attackers with administrator privileges can exploit the vulnerability to execute OS commands. The vulnerability results from improper neutralization of special elements used in an OS command.
Vulnerabilities Are Being Chained
SonicWall PSIRT investigated a case involving a threat actor who chained the two vulnerabilities during an attack on a customer. The vulnerabilities are being used together to achieve remote code execution. SMA1000 appliances are used for secure remote access and VPN connections and are commonly exposed to the Internet. Approximately 400 SMA1000 devices are currently exposed online worldwide, with the majority located in the United States.
The extent of exploitation is not mentioned in the reports but the latest attacks occurred two months after a different pair of vulnerabilities in SMA1000 appliances had been exploited to install malware that enabled ransomware attacks.
CISA Adds Vulnerabilities to KEV Catalog
The Cybersecurity and Infrastructure Security Agency has added both CVE-2026-83548 and CVE-2026-83549 to its Known Exploited Vulnerability Catalog. Federal civilian Executive Branch agencies were given until Saturday to upgrade to the latest hotfix.
Threat actors actively target vulnerabilities in remote access and VPN devices. CISA advised users of vulnerable devices to upgrade to the latest hotfix as soon as possible.
Affected Devices and Software Versions
SonicWall identified the following affected devices: SMA1000 6210, 7210, and 8200v appliances. SonicWall SMA 100 Series products or SSL-VPN running on SonicWall firewalls seem not to be affected by the vulnerabilities.
The affected software versions identified include the following:
- 12.5.0-02835 platform-hotfix and older versions
- 12.4.3-03453 platform-hotfix and older versions
There is no mention in the reports whether exploitation of these vulnerabilities has resulted in a HIPAA breach, unauthorized access to ePHI, or a reportable breach involving a healthcare organization.
Image credit: 2162574878 – Add Win, AdobeStock / SMA100©SonicWall









