SonicWall has warned customers that attackers are chaining two newly disclosed SMA1000 zero-day vulnerabilities to conduct remote code execution attacks against vulnerable appliances.
The first vulnerability, tracked as CVE-2026-83548, is a maximum-severity command injection flaw in the WorkPlace interface of the SMA1000. The vulnerability is caused by a server-side request forgery (SSRF) issue.
The active exploitation campaign also targets CVE-2026-83549, a command injection vulnerability in the SMA1000 management console. An attacker with administrative privileges could exploit the flaw to execute arbitrary operating system commands on an affected device.
“SonicWall PSIRT has investigated an incident indicating active exploitation of the vulnerability described in this advisory. Customers are strongly encouraged to upgrade to the hotfix release as soon as possible to remediate this vulnerability,” the company warned in a Tuesday advisory.
The two security flaws affect the SonicWall SMA1000 6210, 7210, and 8200v models. They do not affect SSL-VPN services running on SonicWall firewalls or the SMA 100 product line.
Internet security organization Shadowserver is currently tracking more than 400 SMA1000 appliances that are publicly accessible online. Some of these devices may already have been updated to protect against the exploit chain.

SonicWall is urging customers to upgrade physical and virtual SMA1000 appliances to the latest available hotfix as soon as possible.
The company also recommends reimaging affected appliances, changing passwords for all users and administrators, and resetting TOTP tokens if indicators of compromise (IOCs) are discovered. SonicWall has not yet released technical details about the attacks or a list of IOCs identified during its investigation.
The SMA1000 is a secure remote access platform used by large enterprises, government agencies, and critical infrastructure organizations. Because these appliances provide remote access to sensitive networks, vulnerabilities in the product are attractive targets for threat actors.
In July, attackers exploited two other SonicWall SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, in zero-day attacks that lasted several weeks and involved the installation of custom malware on vulnerable VPN devices. Last month, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware groups had begun exploiting the flaws.
In December, SonicWall also urged customers to patch another SMA1000 zero-day, CVE-2025-40602, which hackers exploited to gain root privileges on vulnerable devices.
A month ago, SonicWall linked state-backed hackers to a September security breach that exposed customer firewall configuration backup files. The disclosure followed researchers’ warnings that more than 100 SonicWall SSL-VPN accounts had been compromised using stolen credentials.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



