Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
- ID
- 20634
- Status
- summarized
- Published
- 02 Sep 2026, 6:53 PM
- Fetched
- 02 Sep 2026, 8:11 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 02 Sep 2026, 8:13 PM
- Tags
- Audience
- developers
What happened
SonicWall patched two actively exploited zero-days in its SMA 1000 series VPN appliances (models 6210, 7210, 8200v): CVE-2026-83548 (CVSS 10.0, pre-auth SSRF) and CVE-2026-83549 (CVSS 7.8, post-auth OS command injection). Attackers are likely chaining both to achieve remote code execution. Fixes are in platform-hotfix versions 12.4.3-03526 and 12.5.0-02952; older versions are vulnerable.
Why it matters
If your company or a client runs SonicWall SMA 1000 appliances on versions 12.4.3-03453 or older / 12.5.0-02835 or older, patch now and check for IoCs — SonicWall advises re-imaging the appliance, rotating all credentials, and resetting TOTP if compromise is found. This is the second zero-day cluster in the same product line in two months (prior flaws CVE-2026-15409/15410 were exploited by UTA0533 to deploy KNUCKLEBALL malware), so the product is a repeated target.
Discussion angle
Whether your org or clients use SonicWall SMA 1000 appliances specifically — if not, this is a monitoring note, not an action item; if yes, the repeated targeting of this product line warrants a conversation about whether to keep it internet-facing.