SonicWall’s SMA1000 boxes under active attack again
SonicWall has confirmed that attackers are actively exploiting two chained zero-day vulnerabilities to compromise its SMA1000 series appliances, which enterprises use to secure remote access and VPN connections. Because these gateways sit at the edge of corporate networks, a successful compromise can give attackers a foothold into the wider organisation, prompting SonicWall to urge customers to apply hotfixes immediately, as no workarounds exist. NHS England has also issued its own advisory, warning that edge devices are highly attractive targets and assessing further exploitation as "almost certain."
The first flaw, CVE-2026-83548, is a maximum-severity (CVSS 10.0) pre-authentication server-side request forgery bug allowing unauthenticated attackers to access sensitive functionality. The second, CVE-2026-83549, is a post-authentication OS command injection vulnerability in the Appliance Management Console, rated 7.8, which lets an authenticated administrator run arbitrary commands. The flaws affect SMA 6210, 7210 and 8200v appliances; SonicWall advises checking for compromise and, if found, reimaging affected devices, changing all passwords and resetting TOTP tokens. This marks the second such SSRF-plus-command-injection pairing disclosed since July, continuing a troubled year for the product line that has also seen CISA flag a related flaw as exploited in ransomware attacks.
- SonicWall SMA1000 gateways under active attack via two chained zero-days
- Flaws let attackers bypass authentication, then run arbitrary commands
- NHS England warns further exploitation of edge devices is "almost certain"