SonicWall has warned customers about two new zero-day vulnerabilities affecting its SMA 1000 Series secure remote access appliances. The company confirmed that both vulnerabilities are being actively exploited in the wild, making the issue an urgent security concern. The flaws are tracked as CVE-2026-83548 and CVE-2026-83549, with the first rated critical at CVSS 10.0. SonicWall has released fixes and is urging organizations running affected systems to upgrade immediately.

The first vulnerability, CVE-2026-83548, is a pre-authentication server-side request forgery, or SSRF, flaw in the SMA 1000 Appliance WorkPlace interface. Because it does not require authentication, a remote attacker can potentially abuse the vulnerable functionality to reach sensitive services and perform unauthorized operations. SonicWall has given this vulnerability the maximum CVSS score of 10.0 because of its serious security impact. The second flaw, CVE-2026-83549, affects the Appliance Management Console and is a post-authentication operating system command injection vulnerability.

Although the second vulnerability requires authentication, security researchers have warned that the two weaknesses can be chained together to achieve unauthenticated remote code execution. In a successful attack, the first flaw can provide access to functionality that should normally be protected, while the second vulnerability can then be used to execute operating system commands. This combination turns what appear to be separate security problems into a much more serious attack path. The risk is particularly important because SMA 1000 appliances are remote access gateways that can sit directly at the edge of enterprise networks.

The affected products include SonicWall SMA 1000 models 6210, 7210 and 8200v running vulnerable firmware versions. SonicWall lists versions 12.4.3-03453 and 12.5.0-02835 as affected, along with older versions of those releases. The company has released fixed versions 12.4.3-03526 and 12.5.0-02952. Organizations using these appliances are advised to install the appropriate hotfix as quickly as possible rather than waiting for normal maintenance schedules.

SonicWall is also asking customers to check their appliances for possible signs of compromise because exploitation has already been confirmed. If indicators of compromise are discovered, the company recommends re-imaging physical appliances or re-deploying virtual appliances. It also advises organizations to change all user and administrator passwords and reset TOTP tokens. These additional steps are important because simply installing a patch may not remove an attacker who has already gained access to an affected appliance.

The latest incident also comes after earlier zero-day attacks against SonicWall SMA 1000 appliances during the summer, showing that these remote access systems continue to attract attackers. Security researchers previously documented another pair of SMA 1000 vulnerabilities that were actively exploited and could also be chained for remote code execution. With the newest flaws now being exploited, organizations using SMA 1000 should treat the situation as an active security incident, apply the fixed firmware, review their systems for compromise and follow SonicWall’s recovery guidance where necessary.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news