SonicWall discloses third SMA1000 zero-day exploit chain of 2026
The network security vendor confirmed active exploitation of two new flaws in its remote-access appliances, the third such emergency involving the same product line since June.

SonicWall said on Tuesday that attackers are actively exploiting two previously unknown vulnerabilities in its SMA1000 series of remote-access appliances, the third time this year the company has had to warn customers of live attacks against the same product line. The company's Product Security Incident Response Team said it had investigated a confirmed case of exploitation and urged customers to install emergency patches immediately.
The flaws sit in hardware and virtual appliances that many midsize and large organizations use as a gateway for remote employees, letting them authenticate once and reach internal systems without a traditional VPN client. That role, sitting at the perimeter with access to session data and directory credentials, is what makes the appliances an attractive target and explains why security researchers describe compromise of the box as effectively compromise of the authentication layer behind it. Remote-access gateways of this kind, sold by SonicWall and several competitors, have become one of the most consistently targeted categories of enterprise hardware in recent years precisely because a single successful exploit can hand an intruder a foothold inside a corporate network without the need to steal an individual employee's password first.
The scope of the flaws
The advisory, published as SonicWall's SNWLID-2026-0016 security bulletin, describes two distinct bugs. The first, tracked as CVE-2026-83548 in the CVE Program's public record, is a server-side request forgery flaw in the appliance's Work Place interface that carries the maximum possible severity score of 10.0 out of 10 and requires no authentication to exploit. The second, CVE-2026-83549, is an operating-system command-injection bug in the Appliance Management Console rated 7.8, which an attacker with administrative credentials can use to run arbitrary commands. SonicWall and outside researchers say the two can be chained together, turning an anonymous network request into full remote code execution on the device.
The bugs affect SMA1000-series 6210, 7210 and 8200v appliances running platform-hotfix builds 12.4.3-03453 or earlier, or 12.5.0-02835 or earlier; SonicWall has shipped fixes in versions 12.4.3-03526 and 12.5.0-02952. The company said its SMA 100 series and the SSL VPN feature built into its firewalls are not affected. According to reporting by BleepingComputer, which cited data from the scanning group Shadowserver, more than 400 SMA1000 appliances remain reachable from the open internet worldwide, though some may already carry the patch.
A pattern of breaches
Tuesday's disclosure is the third emergency involving SonicWall's SMA1000 line this year. In mid-July, the company disclosed a nearly identical pair of flaws, CVE-2026-15409 and CVE-2026-15410, also chainable for unauthenticated code execution, which it said in a separate PSIRT bulletin had already been exploited in multiple confirmed cases. Reporting at the time tied that campaign to a threat cluster tracked as UTA0533, which researchers said had been using the bugs since late June to install custom malware on compromised appliances.
Those July vulnerabilities did not stay confined to a single intrusion set. By August, the flaws were being used more broadly, and the Cybersecurity and Infrastructure Security Agency ordered federal civilian agencies to patch within three days after adding them to its Known Exploited Vulnerabilities catalog. A follow-up BleepingComputer report said the security firm Resecurity had linked some of that activity to an affiliate of the INC ransomware operation.
"This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise," the Cybersecurity and Infrastructure Security Agency said of the July SonicWall flaws when it added them to its exploited-vulnerabilities catalog.
As of Tuesday, the newly disclosed CVE-2026-83548 and CVE-2026-83549 had not yet been added to that federal catalog, according to SecurityWeek's account of the disclosure, which also noted that CISA's catalog already lists 17 separate SonicWall vulnerabilities that have been exploited in the wild across the company's product lines.
Who is affected, and how they are reacting
SonicWall's SMA1000 customers skew toward organizations with sizable remote workforces: mid-market and large enterprises, government bodies and managed security service providers that rely on the appliance to broker access for employees and contractors working outside the corporate network. SonicWall has not published indicators of compromise or details of the confirmed intrusion that prompted Tuesday's advisory, a gap that coverage from The Hacker News noted leaves defenders with limited forensic guidance beyond the patch itself. The company's public advice is direct: apply the hotfix immediately, and if there is any suspicion a device was already compromised, treat it as a full breach of the authentication system, meaning administrators should re-image the appliance, rotate all associated passwords and reissue multifactor authentication seeds rather than assume a software update alone restores trust in the box.
Independent security outlets covering the advisory, including Help Net Security's writeup of the bulletin, have echoed that guidance while noting SonicWall discovered the exploitation internally rather than through a customer report or an outside researcher, a detail that distinguishes this disclosure from July's, which followed reports from multiple incident-response firms.
What happens next
The immediate test is how quickly the roughly 400 internet-facing SMA1000 appliances Shadowserver has identified get patched, since each additional day of exposure gives attackers more opportunity to compromise devices before defenders act. Given the trajectory of the July flaws, security researchers expect CISA to add the new CVEs to its Known Exploited Vulnerabilities catalog in the coming days, which would trigger a mandatory patch deadline for federal agencies and likely prompt a fresh round of scanning by both defenders and opportunistic attackers. SonicWall has not said whether the September bugs share any code-level relationship with the July pair, and the company's advisory offers no timeline for a broader security audit of the product line, even as the repeated incidents raise questions among customers about the appliance's design and SonicWall's development practices for the software.
Beyond the federal deadline, a KEV listing tends to carry weight well outside government: cyber-insurance underwriters, managed-service providers and corporate security teams routinely treat the catalog as a de facto patch-priority list even when they have no legal obligation to follow it, which means a listing for the September SonicWall flaws would likely accelerate remediation across the roughly 400 exposed devices Shadowserver has counted. For now, the burden falls on SonicWall's customers to verify their own exposure, since the company's advisory, unlike the fuller technical writeups that followed July's disclosure, contains no indicators of compromise for defenders to search their logs against.
EU designates ChatGPT a search engine, subjecting it to strictest online-safety rules

Anthropic reverses enterprise data retention policy after client backlash
Microsoft 365 Limps Back After Daylong Outage Tied to Authentication Failure
