SonicWall fixes two actively exploited SMA 1000 vulnerabilities

SonicWall has released hotfixes for two zero-day vulnerabilities in Secure Mobile Access (SMA) 1000 VPN appliances after investigating a case that indicated active exploitation. The issues are CVE-2026-83548, rated CVSS 10.0, and CVE-2026-83549, rated CVSS 7.8.
The affected appliance models are SMA 1000 6210, 7210 and 8200v. SonicWall said the evidence suggests threat actors may be chaining the two flaws to execute arbitrary code on susceptible devices, although it did not disclose the operators involved or further details of the activity.
Two flaws with different access requirements
CVE-2026-83548 is a pre-authentication server-side request forgery vulnerability in the Appliance Work Place interface. A remote unauthenticated attacker could use it to gain unauthorised access to sensitive functionality and perform unauthorised operations.
CVE-2026-83549 is an operating-system command injection flaw in the Appliance Management Console, or AMC. It requires an authenticated administrator and, under specific conditions, can permit arbitrary command execution, leading to remote code execution.
The combination is significant because SonicWall’s investigation points to exploitation of both vulnerabilities together. The news also follows a broader pattern in which SonicWall, SaaS and DNS attacks documented attacks affecting SonicWall alongside SaaS and DNS targets, while internet-facing security infrastructure remains a high-priority patching concern.
Versions to patch and response actions
The vulnerable releases are version 12.4.3-03453 (platform-hotfix) and earlier, as well as version 12.5.0-02835 (platform-hotfix) and earlier. SonicWall has made fixes available in 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
SonicWall recommends upgrading to the latest applicable hotfix and reviewing appliances for indicators of compromise. Where indicators are found, the company advises organisations to re-image or re-deploy the appliance, change all user and administrator passwords, and reset Time-based One-Time Password (TOTP) credentials.
Operational context for security teams
These fixes arrive more than a month after SonicWall patched two other exploited SMA 1000 issues, CVE-2026-15409 and CVE-2026-15410. Those flaws were exploited by a threat actor tracked as UTA0533 to deploy KNUCKLEBALL malware.
For businesses operating the affected SMA 1000 models, the practical priority is to identify exposed appliances, apply the relevant fixed hotfix, and treat any compromise indicator as a trigger for the full recovery and credential-reset actions specified by SonicWall.

