SonicWall pushes urgent fixes for exploited SMA 1000 flaw pair

SonicWall confirms attackers are chaining two new SMA 1000 zero-days into remote code execution and urges immediate hotfixes.

CSBadmin
1 Min Read

SonicWall rushed hotfixes for two vulnerabilities in its Secure Mobile Access (SMA) 1000 series after confirming active exploitation that appears to chain the bugs into full remote code execution on unpatched appliances.

The first, CVE-2026-83548 (CVSS 10.0), is a pre-authentication server-side request forgery in the Appliance Work Place interface. The second, CVE-2026-83549 (CVSS 7.8), is a post-authentication OS command injection in the Appliance Management Console that requires administrator access. Chained together they let a remote attacker run arbitrary commands, and SonicWall says it investigated a case showing the pair under active exploitation. Both were discovered internally by researchers William Perry and Adam Babis.

Affected SMA 1000 models 6210, 7210, and 8200v are patched in platform hotfixes 12.4.3-03526 and 12.5.0-02952. Customers who find indicators of compromise should re-image hardware appliances or redeploy virtual ones, rotate all user and administrator passwords, and reset time-based one-time password tokens.

The SMA 1000 line has been a repeat target. In June and July, attackers used the earlier pair CVE-2026-15409 and CVE-2026-15410 to deliver KNUCKLEBALL malware in campaigns tied to the actor tracked as UTA0533. SonicWall has not said who is behind the latest wave or published indicators of compromise.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.