News

SonicWall patches SMA 1000 zero-days under active attack

SonicWall confirmed two SMA 1000 flaws under active exploitation and shipped hotfixes 12.4.3-03526 and 12.5.0-02952. One is a pre-auth SSRF rated CVSS 10.0. The pair is not yet in CISA KEV.

SonicWall patches SMA 1000 zero-days under active attack

SonicWall on September 1 published a product notice, SNWLID-2026-0016, confirming that two flaws in its SMA 1000 series remote-access appliances are under active exploitation. This is the vendor's own PSIRT advisory, not a third-party writeup, and it ships fixes rather than just a warning.

The more severe bug is CVE-2026-83548, a pre-authentication server-side request forgery caused by an unintended forward-proxy in the Appliance Work Place interface, rated CVSS 10.0 Critical. The second, CVE-2026-83549, is a post-authentication remote code execution and OS command injection flaw in the Appliance Management Console, rated 7.8 High. SonicWall says it investigated a case indicating exploitation of the described vulnerabilities in the wild.

Who is exposed, and who is not

The notice names SMA 1000 models 6210, 7210 and 8200v, physical and virtual, on firmware in the 12.4.3-03453 and 12.5.0-02835 build lines. Two products people often confuse with these are explicitly out of scope: SSL-VPN running on SonicWall firewalls is not affected, and the SMA 100 series is not affected. If your remote-access box is an SMA 1000, this is yours; if it is a firewall or an SMA 100, this particular advisory is not.

The fixed builds

The number that actually ends the incident is the patched version. SonicWall says the fixes are hotfix builds 12.4.3-03526 and 12.5.0-02952, or later, available from mysonicwall.com. Upgrading to one of those is the first and non-negotiable step.

This is also the second SSRF-to-injection pattern to hit the SMA 1000 line in roughly seven weeks, after a chain disclosed in July, which is worth noting for anyone weighing whether this platform belongs on the public internet at all. Internet-facing remote-access gear keeps drawing the same treatment, as the run of exploited Citrix NetScaler flaws and the Fire Ant campaign against Cisco IOS XR routers this year both showed.

What operators should do now

Beyond patching, SonicWall's own guidance is direct: contact its Technical Support to review appliances for indicators of compromise, and if any are found, treat the box as breached. That means re-imaging physical hardware or redeploying the virtual appliance from clean media, changing every user and admin password, and resetting TOTP tokens. Rotating credentials matters because a post-auth command-injection foothold outlives a simple reboot.

One caveat to plan around: as of the advisory, SonicWall has not published a public list of indicators of compromise, so detection still leans on vendor support rather than a drop-in IOC feed. The pair is also not yet listed in CISA's Known Exploited Vulnerabilities catalog, even though 17 other SonicWall flaws already are, so federal patch deadlines have not attached to these two CVEs yet.

Do not wait for the KEV entry or a public IOC list to move. Patch the SMA 1000 fleet to the hotfix builds today, then open a support case to check for compromise, because a CVSS 10.0 pre-auth bug that is already being exploited is the kind that gets scanned at internet scale within days.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free