SonicWall warns: two zero-days exploited in RCE attacks
SonicWall has reported active attacks combining two new zero-day vulnerabilities in SMA1000 devices, enabling remote code execution. The first is a command injection flaw (CVE-2026-83548) with maximum severity, stemming from a server-side request forgery (SSRF) weakness in the WorkPlace interface. The second (CVE-2026-83549) is a command injection vulnerability in the SMA1000 management console, exploitable by attackers with administrative privileges.
Quick Response
- Vulnerabilities CVE-2026-83548 and CVE-2026-83549 are exploited in active attacks
- Affects SMA1000 6210, 7210, and 8200v models
- SonicWall recommends immediate update to the hotfix version
- More than 400 SMA1000 devices are exposed online
- The vulnerabilities do not affect SSL-VPN on SonicWall firewalls or the SMA 100 Series product line
Technical details of the vulnerabilities
The CVE-2026-83548, rated with a CVSS score of 10.0, allows the execution of arbitrary commands via SSRF. The CVE-2026-83549, with a CVSS score of 9.1, requires administrative privileges but enables OS command execution on vulnerable devices. Both vulnerabilities are chained together to maximize the impact of attacks.
Affected devices and available patches
The vulnerabilities specifically affect SMA1000 6210, 7210, and 8200v models. SonicWall has released a hotfix to address the flaws, urging customers to update both virtual and physical appliances. The company also advises re-imaging devices, changing all user and administrator passwords, and resetting TOTP tokens if signs of compromise are detected.
of the attacks
SonicWall has confirmed the existence of active exploitation cases for these vulnerabilities but has not yet shared specific details about ongoing attacks or a list of indicators of compromise (IOC). The sensitive nature of SMA1000 devices, used for secure remote access by large enterprises, government agencies, and critical infrastructures, makes them attractive targets for attackers.
Recent history of SonicWall vulnerabilities
This is not the first time SMA1000 appliances have been targeted. In July, two other vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were exploited as zero-days for weeks to install custom malware. Recently, CISA confirmed that ransomware gangs are exploiting these vulnerabilities in wild attacks.
Security implications
The combination of these vulnerabilities poses a serious threat to corporate environments using SMA1000. Once initial access is gained, attackers can execute arbitrary commands, potentially allowing malware installation, data theft, or ransomware. The SSRF nature of CVE-2026-83548 adds an additional level of danger, enabling attackers to bypass internal security controls.
Recommended mitigation measures
In addition to immediate updating to patched versions, SonicWall recommends:
- Re-imaging all SMA1000 devices
- Changing all user and administrator passwords
- Resetting all TOTP tokens
- Close monitoring for any signs of compromise
Attack monitoring
Internet security watchdog Shadowserver is currently tracking over 400 SMA1000 appliances exposed online, although some of these devices may have already been patched against this exploit chain. The presence of still-vulnerable devices poses a significant security risk for corporate environments using them.
Implications for corporate environments
The critical nature of SMA1000 devices makes them primary targets for attackers. Compromising these devices can have devastating consequences for organizations, including the loss of sensitive data, operational disruption, and reputational damage. Recent breaches demonstrate that attackers are becoming increasingly sophisticated in their zero-day vulnerability exploitation approach.
Preparation for future attacks
System administrators should consider implementing additional security measures to protect their environments from similar attacks. This could include network segmentation, advanced firewall configuration, and the implementation of intrusion detection and response solutions. Additionally, it is crucial to keep all devices and applications updated with the latest security patches.
Additional resources
For more information on vulnerabilities and mitigation measures, administrators can consult SonicWall's security advisory and resources provided by organizations such as CISA. It is also advisable to stay informed about the latest threats and best practices through regular updates and industry publications.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.
In the Crypto sector, every investment involves risks: readers are advised to always inform themselves independently before making any decisions.