SonicWall Urges Immediate Patch for Exploited Zero-Day Vulnerabilities in SMA1000 Series

September 2, 2026
SonicWall Urges Immediate Patch for Exploited Zero-Day Vulnerabilities in SMA1000 Series
  • SonicWall is urging customers to patch two chained zero-day vulnerabilities in the SMA1000 series—CVE-2026-83548 and CVE-2026-83549—that have been exploited in active attacks to take over remote-access gateways used by midsize and large enterprises.

  • These flaws affect SMA 1000 devices including 6210, 7210, and 8200v, and can be exploited to gain unauthenticated or highly privileged access, enabling remote code execution on affected systems.

  • The exploitation is active in the wild, with attackers chaining the two vulnerabilities, and security researchers note the risk of full compromise of remote-access appliances.

  • The public advisory from SonicWall does not list indicators of compromise or other attack details.

  • Rapid7 notes that the two CVEs can be chained to achieve unauthenticated remote code execution, though no public proof-of-concept or IoCs were identified at publication.

  • SonicWall says SSL-VPN products are not affected by these vulnerabilities.

  • While the full scope of ongoing attacks isn’t known, active exploitation is underway against SMA1000 devices.

  • NHS England warns that internet-facing gateways are high-risk targets and anticipates near-certain future exploitation of edge devices.

  • The flaws affect both physical and virtual SMA 1000 models (6210, 7210, 8200v); SMA 100 and SonicWall firewalls are not affected.

  • CVE-2026-83549 requires prior authentication to execute attacker-controlled code after access is gained.

  • SecurityWeek notes these vulnerabilities are frequently exploited in the wild, including ransomware campaigns, and some flaws remain unpatched for weeks.

  • Exploitation of both vulnerabilities has been observed, indicating attackers are chaining the flaws in active campaigns.

Summary based on 6 sources


Get a daily email with more Tech stories

Sources


SonicWall's SMA1000 boxes under active attack again



More Stories