Utopia Tech
Healthcare2 min read

SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances

Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet. One of the vulnerabilities, tracked as CVE-2026-83548, is a crit

UT

Utopia Tech

September 4, 2026 · 2 min read

Share

Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet. One of the vulnerabilities, tracked as CVE-2026-83548, is a critical pre-authentication server-side request forgery issue in the Appliance Work Place interface that allows command injection.

The vulnerability has been assigned a maximum CVSS v 3. 1 severity score of 10. Successful exploitation allows a remote attacker to access sensitive functions and perform unauthorized actions.

The vulnerability is being chained with an exploit for a high-severity (CVSS v3. 1: 7. 8) OS command injection vulnerability – CVE-2026-83549 – in the Appliance Management Console.

Attackers with admin privileges can exploit the vulnerability and execute OS commands. The vulnerability is due to improper neutralization of special elements used in an OS command. The SonicWall PSIRT has investigated a case where the threat actor chained the two vulnerabilities in an attack on a customer.

The Cybersecurity and Infrastructure Security Agency (CISA) has added both vulnerabilities to its Known Exploited Vulnerability (KEV) Catalog, and federal civilian Executive Branch agencies have been given until Saturday to upgrade to the latest hotfix. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.

Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN running on SonicWall firewalls or SMA 100 Series products. The affected software versions are 12. 4.

3-03453 (platform-hotfix) and older versions, and 12. 5. 0-02835 (platform-hotfix) and older versions.

The extent to which the vulnerabilities are being exploited is unclear. The latest attack(s) come just two months after a different pair of vulnerabilities in SMA1000 appliances were exploited to install malware, enabling ransomware attacks. Since threat actors actively target vulnerabilities in remote access and VPN appliances, users of vulnerable devices are strongly advised to upgrade to the latest hotfix as soon as possible.

Currently, there are approximately 400 SMA1000 devices worldwide that are exposed online, the majority of which are in the United States. The post SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content