Skip to content
CVEvulnerabilityCritical Infrastructure

SonicWall SMA1000: third zero-day chain in seven weeks

2 min read
Share

What happened

SonicWall confirmed on September 2, 2026, that two previously undisclosed vulnerabilities in SMA 1000 appliances are being actively exploited in the wild. CISA added both flaws to its Known Exploited Vulnerabilities catalog the same day and set a remediation deadline of September 5 for federal civilian executive branch agencies.

The attack chain: SSRF into OS command injection

CVE-2026-83548 (CVSS 10.0) is an unauthenticated server-side request forgery flaw in the Work Place web interface of SMA1000 appliances. An attacker with no credentials can send a crafted request to the interface and gain unauthorized access to internal functionality that should be protected.

CVE-2026-83549 (CVSS 7.8) is an OS command injection flaw in the Appliance Management Console that normally requires admin authentication. By chaining CVE-2026-83548 first, an unauthenticated attacker can reach the vulnerable endpoint and achieve remote code execution on the appliance. The two flaws together form a complete unauthenticated RCE chain.

Third time in seven weeks

Sophos XOps documented this attack chain and noted that the SSRF-to-injection pattern is identical to the prior SMA1000 zero-day chain from seven weeks ago. This is the third exploitation campaign targeting SMA1000 devices in under two months. The pattern suggests organized threat actors are treating SMA1000 appliances as a primary access vector, likely because they sit at the network perimeter and are directly internet-exposed.

Affected and not affected

Affected models: SMA1000 6210, 7210, and 8200v. Not affected: SMA 100 Series appliances and SSL-VPN running on SonicWall firewalls. If your organization uses SMA 100 or firewall-based SSL-VPN, you are not exposed to this specific vulnerability chain.

What to do right now

  • Apply the SonicWall patch immediately. FCEB agencies must complete remediation by September 5, 2026.
  • Review Sophos XOps indicators of compromise and check your SMA1000 logs for exploitation attempts.
  • If patching immediately is not possible, restrict access to the Work Place interface and AMC to trusted IP ranges only.

The bigger lesson

Three zero-day chains on the same product line in under two months is not coincidence; it is a sustained targeting campaign. Organizations should treat perimeter-facing remote access appliances as highest-priority patching targets regardless of vendor, and should have network detection watching for unusual traffic from these devices.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you run SMA1000 appliances and want to discuss your exposure.