SonicWall Warns of New Zero-Day Chain Actively Exploited in SMA1000 Appliances
**SonicWall** has issued an urgent warning to customers regarding active exploitation of two new zero-day vulnerabilities in its **SMA1000** secure remote access appliances. Threat actors are chaining these flaws to achieve remote code execution, posing a significant risk to affected organizations. Users are strongly advised to apply the hotfix immediately.
Cybersecurity vendor **SonicWall** has alerted customers to an ongoing threat involving two previously unknown vulnerabilities within its **SMA1000** series of secure mobile access appliances. These zero-days are being actively exploited in the wild, allowing attackers to achieve remote code execution.
The first vulnerability, identified as **CVE-2026-83548**, is a maximum-severity command injection flaw found in the **SMA1000 Appliance WorkPlace** interface. This vulnerability is rooted in a server-side request forgery (SSRF) weakness.
The second flaw in this exploit chain is another command injection vulnerability, **CVE-2026-83549**, present in the **SMA1000 Appliance Management Console**. Attackers who possess administrative privileges can leverage this vulnerability to execute arbitrary operating system commands on compromised devices.
"**SonicWall PSIRT** has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability," the company stated in its advisory.
These critical security flaws specifically impact **SMA1000** models 6210, 7210, and 8200v. It's important to note that **SSL-VPN** running on **SonicWall** firewalls and the **SMA 100 Series** product line are not affected.
Internet security watchdog **Shadowserver** currently reports over 400 **SMA1000** appliances exposed online, though some may have already been patched.

**SonicWall** has urged all customers to update their virtual or physical **SMA1000** appliances to the latest hotfix version. The company also recommends re-imaging appliances, changing all user and administrator passwords, and resetting **TOTP** tokens if indicators of compromise (**IOCs**) are detected. However, specific details about the ongoing attacks or a comprehensive list of **IOCs** have not yet been released.
**SMA1000** appliances are widely used by large enterprises, government entities, and critical infrastructure organizations, making them attractive targets for threat actors.
This isn't the first time **SonicWall**'s **SMA1000** series has been targeted by zero-day exploits. In July, two other flaws (**CVE-2026-15409** and **CVE-2026-15410**) were exploited for weeks to deploy custom malware on vulnerable **VPN** appliances. Last month, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** confirmed that ransomware groups began leveraging these two vulnerabilities. Previously, in December, **SonicWall** also warned customers about another **SMA1000** zero-day (**CVE-2025-40602**) that hackers were chaining to gain root privileges.
In a related incident, **SonicWall** linked state-backed hackers to a September security breach that exposed customers' firewall configuration backup files. This followed earlier warnings about over 100 **SonicWall SSLVPN** accounts being compromised using stolen credentials.