VMTech
Discuss a project

SonicWall fixes two actively exploited SMA 1000 vulnerabilities

SonicWall fixes two actively exploited SMA 1000 vulnerabilities

SonicWall has released hotfixes for two zero-day vulnerabilities in Secure Mobile Access (SMA) 1000 VPN appliances after investigating a case that indicated active exploitation. The issues are CVE-2026-83548, rated CVSS 10.0, and CVE-2026-83549, rated CVSS 7.8.

The affected appliance models are SMA 1000 6210, 7210 and 8200v. SonicWall said the evidence suggests threat actors may be chaining the two flaws to execute arbitrary code on susceptible devices, although it did not disclose the operators involved or further details of the activity.

Two flaws with different access requirements

CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could use it to gain unauthorised access to sensitive functionality and perform unauthorised operations.

CVE-2026-83549 is an operating-system command injection flaw in the Appliance Management Console, or AMC. It requires an authenticated administrator and, under specific conditions, can permit arbitrary command execution, leading to remote code execution.

The combination is significant because SonicWall’s investigation points to exploitation of both vulnerabilities together. The news also follows a broader pattern in which SonicWall, SaaS and DNS attacks documented attacks affecting SonicWall alongside SaaS and DNS targets, while internet-facing security infrastructure remains a high-priority patching concern.

Versions to patch and response actions

The vulnerable releases are version 12.4.3-03453 (platform-hotfix) and earlier, as well as version 12.5.0-02835 (platform-hotfix) and earlier. SonicWall has made fixes available in 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).

SonicWall recommends upgrading to the latest applicable hotfix and reviewing appliances for indicators of compromise. Where indicators are found, the company advises organisations to re-image or re-deploy the appliance, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) credentials.

Operational context for security teams

These fixes arrive more than a month after SonicWall patched two other exploited SMA 1000 issues, CVE-2026-15409 and CVE-2026-15410. Those flaws were exploited by a threat actor tracked as UTA0533 to deploy KNUCKLEBALL malware.

For businesses operating the affected SMA 1000 models, the practical priority is to identify exposed appliances, apply the relevant fixed hotfix, and treat any compromise indicator as a trigger for the full recovery and credential-reset actions specified by SonicWall.

#cybersecurity#sonicwall#vulnerability#vpnsecurity
Open analytics
On the site 0 views
min read 3 02.09.2026
Instagram

SonicWall fixes two actively exploited SMA 1000 vulnerabilities

Open the post on Instagram ↗