Ethical Hacking News
SonicWall has patched two critical zero-day flaws in its SMA 1000 VPN appliances, which are actively being exploited in the wild. The vulnerabilities allow attackers to achieve arbitrary code execution, and customers are urged to upgrade to the hotfix release as soon as possible to remediate the vulnerability.
SonicWall has patched two critical zero-day flaws in its SMA 1000 VPN appliances, CVE-2026-83548 and CVE-2026-83549.The vulnerabilities allow attackers to achieve arbitrary code execution on vulnerable appliances.The first vulnerability is a pre-authentication SSRF flaw, and the second is a post-authentication operating system command injection flaw.SonicWall's researchers discovered the vulnerabilities and confirmed they are being exploited in the wild.Customers are urged to upgrade to the hotfix release as soon as possible to remediate the vulnerability.This is the second recent security incident affecting the SMA product line in a month.Regular software updates and patch management are crucial in preventing zero-day attacks.
SonicWall, a leading provider of cybersecurity solutions, has recently patched two critical zero-day flaws in its SMA 1000 VPN appliances. The vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, have been actively exploited in the wild, with attackers chaining the two flaws to achieve arbitrary code execution on vulnerable appliances.
The first vulnerability, CVE-2026-83548, is a pre-authentication SSRF (Server-Side Request Forgery) flaw in the Appliance Work Place interface. This allows a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations. The second vulnerability, CVE-2026-83549, is a post-authentication operating system command injection flaw in the Appliance Management Console (AMC). This allows a remote attacker, authenticated as an administrator, to execute arbitrary commands and achieve remote code execution under specific conditions.
SonicWall's researchers, William Perry and Adam Babis, discovered the vulnerabilities and confirmed that they are being exploited in the wild. The company's investigation suggests that attackers may be chaining the two flaws to compromise vulnerable appliances.
SonicWall has released security updates for the affected appliances, which include models 6210, 7210, and 8200v running 12.4.3-03453 or earlier and 12.5.0-02835 or earlier. Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.
The vulnerabilities were first discovered by Volexity, a cybersecurity firm that conducted an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, tracked as UTA0533, chained two vulnerabilities to achieve root-level access on the devices before patches existed.
This is the second recent security incident affecting the SMA product line in a month, with SonicWall previously patching two other flaws, CVE-2026-15409 and CVE-2026-15410. These vulnerabilities highlight the importance of regular software updates and patch management in preventing zero-day attacks.
SonicWall has not disclosed technical details of the attack or identified the attacker, but the company has taken steps to address the vulnerabilities and provide guidance to customers on remediation.
In addition to the SMA 1000 VPN appliances, the vulnerabilities also affect other SonicWall products, including the SMA 6000 series. Customers are advised to check the SonicWall website for updates and guidance on remediation.
The incident serves as a reminder of the importance of cybersecurity awareness and the need for organizations to stay vigilant in the face of evolving threats. As the threat landscape continues to evolve, it is essential for organizations to prioritize cybersecurity and stay up-to-date with the latest security patches and best practices.
Related Information:
https://www.ethicalhackingnews.com/articles/SonicWall-Patches-Critical-Zero-Day-Flaws-in-SMA-1000-VPN-Appliances-ehn.shtml
https://securityaffairs.com/198303/security/sonicwall-patches-two-new-actively-exploited-zero-days-in-sma-1000-vpns.html
https://nvd.nist.gov/vuln/detail/CVE-2026-83548
https://www.cvedetails.com/cve/CVE-2026-83548/
https://nvd.nist.gov/vuln/detail/CVE-2026-83549
https://www.cvedetails.com/cve/CVE-2026-83549/
https://nvd.nist.gov/vuln/detail/CVE-2026-15409
https://www.cvedetails.com/cve/CVE-2026-15409/
https://nvd.nist.gov/vuln/detail/CVE-2026-15410
https://www.cvedetails.com/cve/CVE-2026-15410/
Published: Wed Sep 2 12:09:33 2026 by llama3.2 3B Q4_K_M