Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Two SonicWall SMA 1000 Zero-Days Exploited in Chaining Attack: What You Need to Know


Two previously unknown vulnerabilities in SonicWall's SMA 1000 series VPN appliances have been exploited in a zero-day attack chain, highlighting the importance of regular security updates and vigilance in the face of emerging threats.

  • Two previously unknown vulnerabilities in SonicWall's SMA 1000 series VPN appliances have been exploited in a zero-day attack chain.
  • CVES-2026-83548: Pre-authentication Security Service Request Forgery (SSRF) vulnerability in Appliance Work Place interface.
  • CVES-2026-83549: Post-authentication operating system command injection vulnerability in Appliance Management Console (AMC).
  • SonicWall has released security updates to address the issue, but threat actors are chaining the vulnerabilities to execute arbitrary code.
  • Impacted devices include SMA 1000 models 6210, 7210, and 8200v in specific versions.
  • Customers are recommended to upgrade to the latest hotfix version and take precautionary measures to mitigate the risk of exploitation.



  • A recent discovery has left the cybersecurity community on high alert, as two previously unknown vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances have been exploited in a zero-day attack chain. According to a report by The Hacker News (THN), the vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, were discovered internally by SonicWall's William Perry and Adam Babis, and were subsequently found to be actively exploited in a chained attack.

    The first vulnerability, CVE-2026-83548, is a pre-authentication Security Service Request Forgery (SSRF) vulnerability in the Appliance Work Place interface. This vulnerability allows a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. The second vulnerability, CVE-2026-83549, is a post-authentication operating system command injection vulnerability in the Appliance Management Console (AMC). This vulnerability allows a remote authenticated attacker as administrator to execute arbitrary commands under specific conditions, leading to remote code execution.

    SonicWall has acknowledged the vulnerability and has released security updates to address the issue. The updates, which include versions 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix), are intended to patch the two vulnerabilities and prevent further exploitation. However, the company has also warned that threat actors are chaining together both vulnerabilities to execute arbitrary code on susceptible devices.

    The impacted devices are the SMA 1000 models 6210, 7210, and 8200v in versions 12.4.3-03453 (platform-hotfix) and older versions, as well as 12.5.0-02835 (platform-hotfix) and older versions. SonicWall is recommending that customers upgrade to the latest hotfix version, review the system for indicators of compromise (IoCs), and take other precautionary measures to mitigate the risk of exploitation.

    In a statement, SonicWall has confirmed that it has investigated a case indicating the active exploitation of the vulnerabilities and has taken steps to address the issue. However, the company has not shared any specifics about the nature of the exploitation activity or who is behind it.

    The discovery of these two vulnerabilities highlights the importance of regular security updates and the need for organizations to stay vigilant in the face of emerging threats. As the cybersecurity landscape continues to evolve, it is essential for organizations to stay informed and take proactive steps to protect themselves against emerging threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Two-SonicWall-SMA-1000-Zero-Days-Exploited-in-Chaining-Attack-What-You-Need-to-Know-ehn.shtml

  • https://thehackernews.com/2026/09/attackers-exploit-two-sonicwall-sma.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-83548

  • https://www.cvedetails.com/cve/CVE-2026-83548/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-83549

  • https://www.cvedetails.com/cve/CVE-2026-83549/


  • Published: Wed Sep 2 06:57:50 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us