Skip to main content
Emerging ThreatsMalware & Ransomware

SonicWall SMA1000 boxes targeted in active zero-day attacks

Network administrator's hands on rack of SonicWall SMA1000 boxes in dimly lit data center.

"A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations," SonicWall said.

SonicWall: two chained zero-days under active exploitation

SonicWall warned that attackers are actively exploiting a pair of chained zero-day vulnerabilities in its Secure Mobile Access (SMA) Series 1000 appliances. The vendor described the first flaw as CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) vulnerability assigned a maximum CVSS v3 score of 10.0. The second, CVE-2026-83549, is a post-authentication operating-system command injection vulnerability in the SMA1000 Appliance Management Console (AMC) with a CVSS v3 rating of 7.8.

The company said the two issues are being used in combination to take over SMA1000 gateways, which provide remote access and VPN connections for midsize and large enterprises. SonicWall emphasized there are no workarounds and urged administrators to apply the vendor’s hotfixes immediately.

Affected appliances, hotfixes and incident steps

SonicWall identified the impacted models as the SMA 6210, 7210, and 8200v appliances and has released hotfixes for those devices. The vendor advised customers to contact its technical support team for assistance identifying indicators of compromise. For appliances that appear to have been compromised, SonicWall’s guidance is to reimage or redeploy the device, change all passwords, and reset TOTP tokens.

Because the chain begins with a pre-authentication SSRF and can escalate to command execution in the AMC, SonicWall portrayed the risk as one that can yield privileged control over an appliance and thereby provide an attacker with a route into corporate networks.

NHS England flags edge-device threat as 'almost certain'

NHS England published its own advisory alongside the vendor notice and framed the issue in the wider context of internet-facing gateways. "Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers," NHS England wrote, adding that "there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers."

The NHS England National CSOC assessed that future exploitation of these vulnerabilities is "almost certain," underscoring the agency’s view that edge-device flaws are high-priority risks for operational security teams.

Recurring problems for SMA1000: a pattern of SSRF and command‑injection

The disclosures continue a run of problems for SonicWall’s SMA1000 line that stretches back through 2025. In July, SonicWall disclosed an eerily similar pair of vulnerabilities: a pre-authentication SSRF in the SMA1000 Appliance WorkPlace interface and a post-authentication OS command injection in the AMC. That SSRF was also assigned a maximum CVSS v3 score of 10.0, with the corresponding command injection rated in the sevens.

Federal tracking has reflected operational impact: CISA added CVE-2026-15409 to its Known Exploited Vulnerabilities catalog and marked it as known to have been used in ransomware campaigns. Throughout 2025, SonicWall patched a succession of SMA1000 vulnerabilities, including OS command injection and privilege escalation flaws, while investigating zero-days linked to ransomware attacks.

What this means for technologists, affected enterprises, and public-sector SOCs

  • Technologists and security teams: The message is immediate — apply the vendor hotfixes without relying on mitigations. SonicWall itself states there are no workarounds, and its remediation checklist includes reimaging or redeploying compromised appliances and resetting credentials and TOTP tokens.
  • Affected enterprises and procurement leaders: Organizations that deploy SMA1000 gateways should inventory exposed appliances (SMA 6210, 7210, 8200v), engage SonicWall technical support for indicators of compromise, and consider the operational impact of taking edge gateways offline for reimaging or replacement.
  • Public-sector SOCs and NHS England-type operations centers: National CSOC-level warnings have classified further exploitation as "almost certain," reinforcing the need for prioritized patching and active monitoring of internet-facing edge devices that attackers find attractive.

The practical fact at the heart of this advisory is stark: two linked zero-days — a pre-authentication SSRF with a 10.0 score and a post-authentication command-injection rated 7.8 — are being used in the wild against appliances that sit at organizations’ network edge. SonicWall has issued hotfixes for the SMA 6210, 7210 and 8200v and says there are no workarounds; compromised units should be reimaged or redeployed. Given the product line’s recent history of similar flaws and prior exploitation tied to ransomware, the vendor notices and NHS England’s "almost certain" assessment together make patching and forensic review an immediate operational priority.

Source: https://www.theregister.com/security/2026/09/02/sonicwalls-sma1000-boxes-under-active-attack-again/5293969