Critical SonicWall SMA Zero-Days: Attack Chain Already in Motion

SonicWall has patched two zero-day vulnerabilities in its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in the wild. The flaws, both discovered internally, enable attackers to combine them in sequence to gain full remote code execution.

What Went Wrong

The vulnerabilities in question are CVE-2026-83548 and CVE-2026-83549. The first is a pre-authentication SSRF (Server Side Request Forgery) in the Appliance Work Place interface, carrying a maximum severity score of 10.0. It could allow someone with no credentials to access sensitive functionality and carry out unauthorized operations. The second is a post-authentication OS command injection issue located in the Appliance Management Console (AMC), rated 7.8. In certain scenarios, an authenticated admin user could run arbitrary commands—which combined with the SSRF could lead to full remote code execution. SonicWall indicates that both bugs are being chained together in active attacks.

Which Devices Are Affected & How to Respond

The flaws affect multiple models in the SMA 1000 series—specifically, the 6210, 7210, and 8200v appliances—running version 12.4.3-03453 or earlier (platform hotfix) and versions 12.5.0-02835 or earlier. SonicWall has released fixes in versions 12.4.3-03526 and 12.5.0-02952 to address the problems.

Administrators are urged to upgrade immediately to the patched hotfix versions. Also recommended: search systems for indicators of compromise (IoCs). If any are found, re-image or redeploy affected appliances, reset all user and admin passwords, and reset Time-based One-Time Passwords (TOTP) to ensure security.

Background & Related Risks

These two new zero-days aren’t SonicWall’s first recent issue. About a month earlier, two other critical vulnerabilities (CVE-2026-15409 and CVE-2026-15410) were fixed after being exploited by a threat actor known as UTA0533. That attack led to deployment of KNUCKLEBALL malware, showing how quickly unknown flaws can turn into serious compromises. With this latest discovery, it appears that chained exploits are becoming an increasingly popular tactic—amplifying risk.

So far, SonicWall has shared minimal details about who’s behind these attacks or how broadly they’ve been used. But the severity scores, combined with built-in attack chaining, mean any vulnerable device is at real risk.

This marks a significant warning for anyone relying on VPN appliances for remote access. When attackers can exploit a flaw without credentials and then escalate privilege internally, the boundary between external threat and internal foothold disappears. It underscores the importance of timely patching, strong credential hygiene, and monitoring for unusual behavior at every layer of the stack.

What this means: these vulnerabilities reveal a persistent problem in network perimeter devices—they’re highly attractive targets and hard to secure once compromised. Watch for whether these patches hold up under further attack, whether attack details emerge, and how vendors offer transparency around zero-day incidents going forward.