SonicWall SMA 1000 Series Hit by New Zero-Day Exploits
SonicWall has issued urgent security updates for its Secure Mobile Access (SMA) 1000 series VPN appliances, addressing two critical zero-day vulnerabilities. These flaws, actively exploited in the wild, could allow remote unauthenticated attackers to gain unauthorized access and execute arbitrary code on vulnerable devices.

**SonicWall** has released crucial security updates to mitigate two zero-day vulnerabilities impacting its **Secure Mobile Access (SMA) 1000** series VPN appliances. These flaws have been actively exploited, posing significant risks to organizations utilizing these devices.
### The Vulnerabilities Identified
The vulnerabilities, discovered internally by **SonicWall** researchers William Perry and Adam Babis, are detailed as follows:
* **CVE-2026-83548** (CVSS score: 10.0): A pre-authentication Server-Side Request Forgery (SSRF) vulnerability within the Appliance Work Place interface. This critical flaw could enable a remote, unauthenticated attacker to gain unauthorized access to sensitive functionality and perform illicit operations.
* **CVE-2026-83549** (CVSS score: 7.8): A post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC). This allows a remote, authenticated administrator to execute arbitrary commands under specific conditions, potentially leading to remote code execution.
**SonicWall** has confirmed active exploitation, suggesting that threat actors are likely chaining these two vulnerabilities together to achieve arbitrary code execution on susceptible devices.
### Affected Versions and Remediation
The zero-day flaws impact specific models and versions of the SMA 1000 series:
* Models: 6210, 7210, and 8200v
* Versions: 12.4.3-03453 (platform-hotfix) and older, as well as 12.5.0-02835 (platform-hotfix) and older.
Patches are available in versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix).
**SonicWall** strongly recommends the following actions for affected customers:
1. **Upgrade** to the latest hotfix version immediately.
2. **Review** systems for any indicators of compromise (IoCs).
3. If IoCs are detected, **re-image or re-deploy** the appliances, **change all user and administrator passwords**, and **reset Time-based One-Time Password (TOTP)** credentials.
### Ongoing Threat Landscape
While **SonicWall** has not disclosed specifics regarding the nature of the exploitation or the identity of the threat actors, this incident follows closely on the heels of previous vulnerabilities in the same product line. Just over a month ago, **SonicWall** addressed **CVE-2026-15409** (CVSS score: 10.0) and **CVE-2026-15410** (CVSS score: 7.2), which were exploited by a threat actor identified as **UTA0533** to deploy **KNUCKLEBALL** malware.
Organizations using **SonicWall SMA 1000** series appliances should prioritize these updates and follow the recommended security measures to protect their networks from potential compromise.