Particle.news

SonicWall: Two SMA1000 Zero‑Days Actively Exploited

The flaws let attackers reach admin functions or run operating‑system commands, creating urgent breach risk for exposed remote‑access gateways.

Overview

  • SonicWall said in a Sept. 1 advisory that it has observed active exploitation of two newly discovered zero‑day flaws and urged customers to apply hotfixes immediately.
  • The bugs are CVE‑2026‑83548, a pre‑authentication SSRF rated CVSS 10, and CVE‑2026‑83549, an OS command‑injection rated CVSS 7.8, which together can be chained to gain deeper control of devices.
  • Affected SMA1000 models are 6210, 7210, and 8200v and SonicWall released platform hotfixes (12.4.3‑03526, 12.5.0‑02952 and later) to patch the issues.
  • The vendor recommends immediate patching and, if indicators of compromise are found, re‑imaging appliances, changing all passwords, and resetting TOTP tokens; SonicWall has not published public IoCs or detailed attack telemetry.
  • Internet watchdogs report more than 400 SMA1000 appliances exposed online and security firms note these edge gateways are prized targets for state‑backed and ransomware actors due to the remote access they provide.