Live Cybersecurity News Ticker | Codekeeper

Chained Zero-Days in SonicWall's SMA 1000 Enable Unauthenticated RCE

Written by Content Team | Sep 4, 2026, 1:01:53 PM

SonicWall confirmed on Tuesday, September 1, that attackers are actively exploiting two zero-days in its SMA 1000 remote-access appliances. CVE-2026-83548 (SSRF, CVSS 10.0) hits the user-facing Workplace portal; CVE-2026-83549 (OS command injection, CVSS 7.8) sits behind the admin console. Chained, the first supplies the authentication the second needs — unauthenticated remote code execution.

Models 6210, 7210, and 8200v are affected on 12.4.3-03453 or 12.5.0-02835 and older. Upgrade to 12.4.3-03526 or 12.5.0-02952. Patching isn't the end of it: SonicWall says compromised appliances need re-imaging or redeployment, every user and admin password changed, and TOTP tokens reset.

There is little to check against, though: Rapid7 found no public proof-of-concept, no published indicators of compromise, and no attribution — so a verdict runs through SonicWall's support team rather than a threat feed.

This is the second such pair on the SMA 1000 in two months. July's CVE-2026-15409 was the same shape — pre-auth SSRF plus post-auth command injection — and CISA later flagged it as used in ransomware campaigns. NHS England rates further exploitation as almost certain.

Source: Dark Reading