Skip to main content
Emerging ThreatsMalware & Ransomware

Attackers Exploit Zero-Days in SonicWall SMA 1000 Appliances

Network equipment rack with a VPN device in a data center.

"Please stop us if you’ve heard this one before: Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another unauthenticated path to complete compromise," Jake Knott, head of threat intelligence at watchTowr, wrote in an email.

The zero-days: CVE-2026-83548 and CVE-2026-83549

SonicWall disclosed and released patches for two actively exploited zero-day vulnerabilities — CVE-2026-83548 and CVE-2026-83549 — in its SMA 1000 appliances in a security advisory on Tuesday. The company said the defects were already being exploited in the wild. The Cybersecurity and Infrastructure Security Agency added the pair to its known exploited vulnerabilities (KEV) catalog on Wednesday.

How the flaws can be combined to gain unauthenticated access

Rapid7 researchers characterized the two weaknesses as a "max-severity pre-authentication server-side request forgery vulnerability" (CVE-2026-83548) and a "high-severity OS command injection vulnerability" (CVE-2026-83549). Rapid7 said those defects can be chained together to achieve unauthenticated remote-code execution against vulnerable appliances.

SonicWall's guidance, and what the vendor did not disclose

SonicWall's advisory released patches and urged customers to contact technical support for assistance in reviewing indicators of compromise (IOCs) and hunting for signs of intrusion. The company recommended that, if compromise is detected, customers reimage or redeploy the appliance, change all user and administrator passwords and reset tokens. The advisory did not include indicators of compromise.

The vendor did not say how many customers have been directly impacted by active exploitation or when the first known instance of exploitation occurred. SonicWall did not respond to a request for comment, according to the reporting.

A pattern of recurring incidents and high-value targeting

The newly disclosed pair joins a string of vulnerabilities and incidents that customers have faced over recent months and years. Attackers have "consistently exploited newly discovered zero-days and years-old defects" in SonicWall products to breach victim environments, the reporting states. Last year, an attack allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer, and in late July Huntress researchers observed an attack spree that compromised 30 SonicWall customers in less than two days.

Earlier in the same month, SonicWall acknowledged another pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects. Ransomware groups, including INC ransomware and Akira, have shown "a special interest in SonicWall." Ten of the 19 SonicWall defects added to CISA’s KEV catalog since late 2021 are known to be used in ransomware campaigns, and the five defects added to CISA’s KEV most recently, since just mid-December 2025, all impact SonicWall SMA 1000 appliances.

What this means for technologists, CISA, and affected enterprises

  • Technologists and security teams: The advisory and Rapid7's analysis imply a high urgency to apply the patches. SonicWall's own mitigation guidance includes reimaging or redeploying appliances and resetting credentials if compromise is found, and teams are being asked to contact vendor support for IOC assistance.
  • The Cybersecurity and Infrastructure Security Agency (CISA): By adding these CVEs to its KEV catalog, CISA has signaled the defects should be prioritized for mitigation by organizations tracking KEV listings.
  • Affected enterprises and procurement leaders: The string of incidents and the repeated KEV additions tied to SMA 1000 appliances underscore ongoing exposure at the network edge and may influence decisions on risk tolerance, vendor management, and accelerated patch windows.

Jake Knott's critique in the reporting highlights another operational tension: SonicWall stated the vulnerabilities were internally discovered while also investigating a case indicating active exploitation, a combination that left defenders without clear timing or attribution. The company also chose not to publish IOCs in its advisory, directing customers to contact tech support instead.

For organizations that operate SonicWall SMA 1000 appliances, the immediate tasks are concrete and familiar: apply the vendor patches released Tuesday, hunt for signs of compromise with vendor assistance, and follow SonicWall's remediation steps if evidence of exploitation is found. The broader record in this reporting — repeated zero-days, prior mass exfiltration of configurations, and ransomware campaigns tied to multiple KEV-listed SonicWall defects — raises persistent questions about exposure at the network edge and about how and when vendors disclose both discovery and exploitation details. SonicWall has not disclosed how many customers were affected or when exploitation first began.

Original story: https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/