SonicWall has warned that attackers are actively chaining two zero-day vulnerabilities in its SMA1000 remote-access appliances to execute commands on affected systems.
The company said its Product Security Incident Response Team had investigated an incident indicating that the flaws were being exploited in attacks, and urged customers to install the latest hotfix without delay.
One of the vulnerabilities, tracked as CVE-2026-83548, is a maximum-severity command-injection flaw in the SMA1000 Appliance WorkPlace interface. It is linked to a server-side request forgery weakness, which can allow attackers to make unauthorised requests from the appliance.
The second flaw, CVE-2026-83549, affects the SMA1000 Appliance Management Console. An attacker who already has administrative access can exploit it to run arbitrary operating-system commands on the device.
“SonicWall PSIRT has investigated a case indicating the active exploitation of the vulnerabilities described in this advisory,” the company said in a Tuesday security notice. “Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability.”
Which SonicWall appliances are affected?
The vulnerabilities affect the SMA1000 6210, 7210 and 8200v models, in both physical and virtual deployments. SonicWall said they do not affect SSL-VPN services running on its firewalls or the SMA 100 Series product range.
Internet monitoring organisation Shadowserver is currently tracking more than 400 SMA1000 appliances exposed online, although the total may include devices that have already been updated and are no longer vulnerable.
SonicWall has advised administrators to upgrade all affected appliances to the newest hotfix. Where signs of compromise are found, it recommends re-imaging the appliance, changing user and administrator passwords, and resetting time-based one-time password tokens.
The company has not yet published details of the attacks or a list of indicators of compromise identified during its investigation. The lack of that information means organisations will need to rely on their own monitoring and incident-response checks while applying the fix.
The warning follows a series of attacks against SonicWall’s SMA1000 platform, which provides secure remote access for large businesses, government bodies and critical infrastructure organisations.
In July, two other SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were exploited for weeks to install custom malware on vulnerable appliances. The US Cybersecurity and Infrastructure Security Agency confirmed last month that ransomware groups had begun using those flaws in attacks.
SonicWall also disclosed in December that hackers had exploited another SMA1000 zero-day, CVE-2025-40602, to obtain root privileges. The company has separately linked state-backed attackers to a September breach involving customer firewall configuration backups, after researchers reported more than 100 SonicWall SSL-VPN accounts had been compromised using stolen credentials.
