<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex" -->

---
title: SonicWall warns of actively exploited SMA1000 zero-day flaws
description: SonicWall disclosed two actively exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances: a maximum-severity command injection flaw...
canonical: https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: SonicWall warns of actively exploited SMA1000 zero-day flaws | daily.dev
og:description: SonicWall disclosed two actively exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances: a maximum-severity command injection flaw...
og:url: https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex
og:image: https://api.daily.dev/og/posts/svllMj7EX.png
og:image:alt: SonicWall warns of actively exploited SMA1000 zero-day flaws
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# SonicWall warns of actively exploited SMA1000 zero-day flaws

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

SonicWall disclosed two actively exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances: a maximum-severity command injection flaw (CVE-2026-83548) in the WorkPlace interface stemming from an SSRF weakness, and a second command injection bug (CVE-2026-83549) in the Management Console exploitable by an admin-privileged attacker to run arbitrary OS commands. The flaws affect SMA1000 6210, 7210, and 8200v models, not the SMA 100 series or firewall SSL-VPN. SonicWall urges immediate hotfix upgrades, re-imaging, password resets, and TOTP token resets if compromise indicators are found. Over 400 SMA1000 appliances remain exposed online per Shadowserver. This follows a string of recent SonicWall SMA1000 incidents, including a July zero-day chain used to deploy custom malware, subsequent ransomware exploitation confirmed by CISA, and a December zero-day used for root privilege escalation.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws>

## Questions this post answers

### What are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000?

They are two actively exploited zero-day vulnerabilities being chained for remote code execution. CVE-2026-83548 is a maximum-severity command injection flaw in the SMA1000 Appliance WorkPlace interface caused by an SSRF weakness, while CVE-2026-83549 is a command injection vulnerability in the Appliance Management Console exploitable by attackers with admin privileges to run arbitrary OS commands.

_Teams running SonicWall SMA1000 gear can track fast-moving exploit chains like this one on daily.dev._

### Which SonicWall SMA1000 models are affected by the September 2026 zero-day chain and what should admins do?

The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN on SonicWall firewalls or the SMA 100 Series. SonicWall urges customers to upgrade to the hotfix release immediately, and if indicators of compromise are found, to re-image appliances, change all user and administrator passwords, and reset TOTP tokens.

_Admins patching exposed remote access appliances can follow evolving SonicWall advisories via daily.dev._

### How many SonicWall SMA1000 appliances are exposed online and vulnerable to exploitation?

Shadowserver tracks over 400 SMA1000 appliances exposed online, though some may already be patched against this exploit chain. This follows a pattern of repeated SMA1000 zero-days, including a July chain used to push custom malware that ransomware gangs later began abusing, and a December zero-day exploited to gain root privileges.

_Security teams gauging real-world exposure of internet-facing appliances can follow updates like this on daily.dev._

---

Tags: [#security](https://daily.dev/tags/security), [#vpn](https://daily.dev/tags/vpn), [#zero-day](https://daily.dev/tags/zero-day)

[View this post on daily.dev](https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"SonicWall warns of actively exploited SMA1000 zero-day flaws","url":"https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex"},"datePublished":"2026-09-03T05:31:33.525Z","dateModified":"2026-09-13T21:49:15.814Z","description":"SonicWall disclosed two actively exploited zero-day vulnerabilities in its SMA1000 secure remote access appliances: a maximum-severity command injection flaw...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cb8e25c5ccb13f1fce1892948a4974d9?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/cb8e25c5ccb13f1fce1892948a4974d9?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,vpn,zero-day","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"SonicWall warns of actively exploited SMA1000 zero-day flaws"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws-svllmj7ex#faq","mainEntity":[{"@type":"Question","name":"What are CVE-2026-83548 and CVE-2026-83549 in SonicWall SMA1000?","acceptedAnswer":{"@type":"Answer","text":"They are two actively exploited zero-day vulnerabilities being chained for remote code execution. CVE-2026-83548 is a maximum-severity command injection flaw in the SMA1000 Appliance WorkPlace interface caused by an SSRF weakness, while CVE-2026-83549 is a command injection vulnerability in the Appliance Management Console exploitable by attackers with admin privileges to run arbitrary OS commands. Teams running SonicWall SMA1000 gear can track fast-moving exploit chains like this one on daily.dev."}},{"@type":"Question","name":"Which SonicWall SMA1000 models are affected by the September 2026 zero-day chain and what should admins do?","acceptedAnswer":{"@type":"Answer","text":"The vulnerabilities affect SMA1000 6210, 7210, and 8200v models, but not SSL-VPN on SonicWall firewalls or the SMA 100 Series. SonicWall urges customers to upgrade to the hotfix release immediately, and if indicators of compromise are found, to re-image appliances, change all user and administrator passwords, and reset TOTP tokens. Admins patching exposed remote access appliances can follow evolving SonicWall advisories via daily.dev."}},{"@type":"Question","name":"How many SonicWall SMA1000 appliances are exposed online and vulnerable to exploitation?","acceptedAnswer":{"@type":"Answer","text":"Shadowserver tracks over 400 SMA1000 appliances exposed online, though some may already be patched against this exploit chain. This follows a pattern of repeated SMA1000 zero-days, including a July chain used to push custom malware that ransomware gangs later began abusing, and a December zero-day exploited to gain root privileges. Security teams gauging real-world exposure of internet-facing appliances can follow updates like this on daily.dev."}}]}
```

