SonicWall SMA 1000 Hit by Another Pair of Actively Exploited Zero-Days

Two newly disclosed vulnerabilities in SonicWall SMA 1000 appliances can be chained for unauthenticated remote code execution, and exploitation was already underway before patches dropped.

AI-generated illustration depicting vulnerability for the story: SonicWall SMA 1000 Hit by Another Pair of Actively Exploited Zero-Days

Summary

  • SonicWall has disclosed CVE-2026-83548 and CVE-2026-83549 affecting SMA 1000 appliances, both confirmed as actively exploited at the time of disclosure.
  • The vulnerabilities — a max-severity pre-authentication SSRF and a high-severity OS command injection — can be chained to achieve unauthenticated remote code execution.
  • CISA added both flaws to its Known Exploited Vulnerabilities catalogue; they are the fifth and sixth SMA 1000 defects added since mid-December 2025.
  • SonicWall did not publish indicators of compromise, did not name the threat actors involved, and did not clarify when exploitation first began.
  • Ten of the 19 SonicWall vulnerabilities in CISA’s KEV since late 2021 are linked to ransomware campaigns, with INC ransomware and Akira among known operators.

Another Patch, Another Active Exploit

SonicWall has disclosed two new zero-day vulnerabilities in its SMA 1000 series appliances — CVE-2026-83548 and CVE-2026-83549 — confirming in its security advisory that both were already being exploited in the wild when the patches were released. CISA followed up the next day, adding both flaws to its Known Exploited Vulnerabilities catalogue. For organisations running SMA 1000 devices, this means the window between the start of exploitation and the availability of a patch was measured in an unknown quantity of days — SonicWall has not disclosed when the first exploitation occurred.

What the Vulnerabilities Do

Researchers at Rapid7 identified that the two flaws can be combined into a single attack chain. CVE-2026-83548 is a maximum-severity pre-authentication server-side request forgery vulnerability; CVE-2026-83549 is a high-severity OS command injection flaw. Used together, they provide an unauthenticated attacker with a path to remote code execution on the appliance — no credentials required. For network edge devices like the SMA 1000, which are by design exposed to external traffic, that is about as serious an exposure as exists.

A Disclosure That Raises Questions

The vendor’s advisory stated the vulnerabilities were internally discovered, while simultaneously noting it had investigated a case indicating active exploitation. Jake Knott, head of threat intelligence at watchTowr, pointed out the contradiction publicly. “SonicWall says these vulnerabilities were internally discovered, while also saying it investigated a case indicating active exploitation. Please pick one, or, at minimum, explain how both are true,” Knott said. He added that without that context, “the disclosure leaves defenders guessing about when and how the vulnerabilities were actually identified.” SonicWall did not respond to a request for comment from CyberScoop, and the advisory did not include indicators of compromise. Customers needing IOC assistance were directed to contact SonicWall technical support.

Part of a Sustained Pattern

These disclosures do not exist in isolation. Since mid-December 2025 alone, five SonicWall SMA 1000 defects have been added to CISA’s KEV — the two disclosed this week included. Looking further back, of the 19 SonicWall vulnerabilities added to that catalogue since late 2021, ten are known to have been used in ransomware campaigns. Ransomware groups INC ransomware and Akira have both shown a particular interest in SonicWall products.

Recent History Adds Urgency

The pattern of exploitation has been consistent and accelerating. In late July, Huntress researchers documented an attack campaign that compromised 30 SonicWall customers in under two days. Earlier in the same month, SonicWall acknowledged another pair of zero-days that had been actively exploited for three weeks prior to public disclosure and patching. And in a separate incident last year, a state-sponsored threat group was able to extract the firewall configurations of every SonicWall customer — an incident that illustrated the potential for appliance compromise to cascade into broader network exposure.

Why it matters

SMA 1000 appliances sit at the network perimeter and handle remote access — making them high-value targets that can serve as initial access points into an organisation’s broader environment. The ability to achieve unauthenticated remote code execution means an attacker does not need to phish credentials or bypass multi-factor authentication; they go straight to the device. For CISOs, the pattern here matters as much as the individual CVEs: this product line has been a recurring source of actively exploited zero-days, with a demonstrated interest from ransomware operators. Any organisation still running unpatched SMA 1000 appliances should treat this as an active incident risk, not a routine patch cycle item. The absence of IOCs in the public advisory, and the lack of clarity around the timeline of exploitation, makes it harder for defenders to rule out prior compromise without direct engagement with SonicWall support.

What to do now

  • Apply SonicWall’s patches for CVE-2026-83548 and CVE-2026-83549 to all SMA 1000 appliances immediately.
  • Contact SonicWall technical support to obtain indicators of compromise and conduct a retrospective hunt for signs of exploitation.
  • If signs of compromise are detected, follow SonicWall’s guidance: reimage or redeploy the affected appliance, change all user and administrator passwords, and reset tokens.
  • Review whether any SMA 1000 appliances patched for this or recent prior vulnerabilities warrant a broader network investigation given the unauthenticated RCE exposure.
  • Confirm your SMA 1000 assets are covered by your vulnerability management programme, given that five SMA 1000 flaws have reached CISA’s KEV since mid-December 2025 alone.

Sources