Vulnerabilities

SonicWall SMA 1000 Hit by a Third Exploited Zero-Day Chain Since December

SonicWall SMA 1000 Hit by a Third Exploited Zero-Day Chain Since December

Attackers are chaining two SonicWall SMA 1000 zero-days to execute code on enterprise VPN gateways without authenticating first. SonicWall confirmed the exploitation on Tuesday 1 September in advisory SNWLID-2026-0016. CISA added both flaws to its Known Exploited Vulnerabilities catalogue the next day and gave US federal civilian agencies until 5 September to remediate, a three-day window.

CVE-2026-83548 carries a CVSS score of 10.0, the maximum. It is a pre-authentication server-side request forgery flaw in the Appliance Work Place interface, the portal users see,and SonicWall traces it to an unintended alternate access path. CISA maps it to CWE-918 and CWE-441, unintended proxy or intermediary, the classic confused deputy pattern. CVE-2026-83549, CVSS 7.8, is an OS command injection flaw in the Appliance Management Console, the administrator portal and on its own needs an authenticated administrator. The first flaw supplies what the second one lacks.

SonicWall found the flaws and the exploitation internally, crediting its own engineers William Perry and Adam Babis. The advisory states that PSIRT investigated “a case indicating the active exploitation of the vulnerabilities described in this advisory”. In July, facing the previous pair, the company said it had investigated multiple cases. A SonicWall spokesperson told Dark Reading this week that the attacks are ongoing.

The TOTP Reset Instruction Is the Line to Read Twice

SonicWall’s remediation guidance runs to three steps, upgrade to the current hotfix, review the appliance for indicators of compromise and if any are found, re-image or re-deploy it, change every user and administrator password and reset the Time-based One-Time Password seeds.

That last item is not boilerplate. When the same product line was attacked in July, Rapid7 documented attackers pulling credentials, active session databases and TOTP MFA seed configurations off compromised appliances. A stolen seed keeps producing valid six-digit codes long after every password has been rotated. Volexity attributed the pre-disclosure exploitation in that campaign to a cluster it tracks as UTA0533 and dated it to 22 June 2026, three weeks before SonicWall shipped fixes in mid-July. The implants it recovered were ROOTRUN, KNUCKLEBALL and ORANGETAIL. CISA later updated both July entries to record use in ransomware campaigns.

Nobody has tied the September pair to UTA0533 or to any other actor and the two chains are technically distinct. The appliance still holds the same secrets it held in July, though and SonicWall’s own remediation list concedes as much. Treating the hotfix as the end of the job repeats the mistake that made the July campaign so durable.

SonicWall Is Asking Customers to Hunt Indicators It Has Not Published

The advisory contains no indicators of compromise. SecurityWeek flagged the omission on Tuesday and Rapid7 reported finding no public proof-of-concept, no IoCs and no attribution for the current activity. Asking customers to review appliances for indicators while publishing none of them is not an instruction anyone can act on.

Until forensic signatures exist, the pessimistic assumption is the defensible one. Any internet-facing SMA 1000 still running a vulnerable build this week is a candidate for compromise, not a device with a clean bill of health. Verify its file system against a known-good baseline rather than asking the running appliance to report on itself.

Affected Models and Builds

The flaws affect the SMA 1000 series in both physical and virtual form.

  • Models 6210, 7210 and 8200v
  • Vulnerable: 12.4.3-03453 (platform-hotfix) and older, 12.5.0-02835 (platform-hotfix) and older
  • Fixed: 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix)

SSL-VPN on SonicWall firewalls and the SMA 100 series are not affected, according to SecurityWeek’s reading of the advisory. Help Net Security describes the SMA 1000 line as standard equipment among mid-sized and large enterprises, government agencies and managed security service providers.

The CISA Deadline Falls on Saturday

  1. Upgrade to 12.4.3-03526 or 12.5.0-02952 or later. Both branches have a fix.
  2. Rotate administrator and user credentials, regenerate TOTP seeds and force MFA re-enrolment on any appliance that sat internet-facing and unpatched. A patch closes the door. It does not invalidate what was already taken.
  3. Verify appliance integrity against a known-good baseline. Where there is evidence of compromise, SonicWall’s instruction is to re-image or re-deploy the appliance rather than clean it in place.

CERT-SE published a Swedish-language advisory on the July pair on 15 July 2026. On CVE-2026-83548 and CVE-2026-83549 it has published nothing as of 3 September. Do not wait for one.

References

  1. SNWLID-2026-0016: SMA 1000 Series Affected by Multiple Vulnerabilities
  2. CISA Adds Seven Known Exploited Vulnerabilities to Catalog
  3. Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
  4. SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
  5. SonicWall Warns of Actively Exploited SMA1000 Zero-Day Flaws
  6. Critical SonicWall SMA 1000 Flaws Enable Unauthenticated RCE
  7. Kritiska sarbarheter i SonicWall SMA1000

This post is also available in: Svenska

Erik Berg

Erik Berg is CTO and Principal Security Architect at eBuilder Security, with more than a decade in blue team security operations across the private and public sectors, and a focus on emerging threats including the security risks that come with AI.