SonicWall has warned that attackers are exploiting serious security vulnerabilities in its SMA1000 series secure remote access appliances. These devices help employees connect to company networks and applications from outside the office. One of the vulnerabilities, tracked as CVE-2026-83548, received the maximum severity score of 10.0 out of 10. The company confirmed active exploitation and released security updates to address the issue.
The critical vulnerability is a type of security weakness known as Server-Side Request Forgery (SSRF). It affects the Appliance WorkPlace interface and allows attackers to send requests through the vulnerable device without logging in. This could give them unauthorised access to sensitive internal functions and allow them to perform operations they should not be able to access. The flaw was linked to an unintended access path in the appliance.
Another vulnerability, tracked as CVE-2026-83549, has a severity score of 7.8 and affects the Appliance Management Console. It involves operating system command injection, which could allow an authenticated attacker to execute unauthorised commands with administrator privileges. When the two vulnerabilities are used together, attackers can potentially achieve remote code execution. This could give them significant control over a vulnerable appliance.
The affected devices include the SonicWall SMA1000 models 6210, 7210 and 8200v. The vulnerabilities affect firmware versions 12.4.3-03453 and earlier, as well as 12.5.0-02835 and earlier. SonicWall confirmed that the flaws were being exploited in real-world attacks, making the situation particularly serious for organisations relying on these appliances for remote access. The vulnerabilities do not affect the SMA100 Series or SSL-VPN running on SonicWall firewalls.
SonicWall has released security updates to fix both vulnerabilities and urged customers to upgrade their affected devices immediately. The fixed versions are 12.4.3-03526 and 12.5.0-02952. Organisations should also contact SonicWall technical support to check for possible signs of compromise. If evidence of a breach is found, the company recommends rebuilding affected appliances, changing user and administrator passwords, and resetting time-based one-time password tokens.
This incident highlights the risks of leaving internet-facing remote access systems unpatched. Attackers often target these devices because they provide a pathway into corporate networks and sensitive business systems. Organisations should review their firmware versions, apply the recommended security updates and investigate suspicious activity. It is also important to note that a separate maximum-severity SMA1000 vulnerability, CVE-2026-102255, was disclosed in October 2026, but SonicWall reported no evidence of its exploitation at the time of that advisory.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news