SonicWall Patches Two Zero-Day Vulnerabilities in SMA 1000 VPN After Active Exploitation Confirmed
485/69 Friday, September 4, 2026
SonicWall has released security updates to address two zero-day vulnerabilities in SMA 1000 VPN appliances after confirming that the flaws have been exploited in attacks. The first vulnerability, CVE-2026-83548, has a CVSS score of 10.0 and is a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the Appliance WorkPlace interface. It could allow a remote attacker without valid credentials to access sensitive functions and perform unauthorized actions. The second vulnerability, CVE-2026-83549, has a CVSS score of 7.8 and is a post-authentication Operating System Command Injection vulnerability in the Appliance Management Console (AMC). Under specific conditions, an attacker with administrator privileges could exploit the flaw to execute arbitrary commands, potentially leading to remote code execution.
SonicWall stated that both vulnerabilities were discovered by its researchers, William Perry and Adam Babis. SonicWall PSIRT’s investigation found cases indicating that the vulnerabilities had been exploited in real-world attacks, and it is possible that attackers chained the two flaws to execute code on vulnerable appliances. The vulnerabilities affect models 6210, 7210, and 8200v running versions 12.4.3-03453 or earlier and 12.5.0-02835 or earlier. SonicWall fixed the vulnerabilities in versions 12.4.3-03526 and 12.5.0-02952, and urged customers to install the hotfix as soon as possible.
SonicWall recommends that administrators install the latest hotfix and inspect systems for signs of compromise. If indicators of compromise (IoCs) are found, affected appliances should be re-imaged or redeployed. Administrators should also change all user and administrator passwords and reset Time-based One-Time Password (TOTP) credentials. SonicWall has not disclosed technical details of the attacks or identified the threat actor behind the activity. This incident is another significant case affecting the SMA product line in recent months, following SonicWall’s earlier fixes for CVE-2026-15409, with a CVSS score of 10.0, and CVE-2026-15410, with a CVSS score of 7.2. Volexity previously reported that SonicWall SMA 1000 Series VPN appliances had been targeted in zero-day attacks since June 22, 2026, and linked the activity to UTA0533, which chained vulnerabilities to gain root-level access to appliances and install a malicious Python script named KNUCKLEBALL.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.