
SonicWall has launched safety updates to handle two safety flaws impacting its Safe Cell Entry (SMA) 1000 sequence VPN home equipment which have been exploited in zero-day assaults.
The vulnerabilities, found internally by SonicWall’s William Perry and Adam Babis, are listed beneath –
- CVE-2026-83548 (CVSS rating: 10.0) – A pre-authentication SSRF vulnerability within the Equipment Work Place interface that would permit a distant unauthenticated attacker to achieve unauthorized entry to delicate performance and carry out unauthorized operations.
- CVE-2026-83549 (CVSS rating: 7.8) – A post-authentication working system command injection vulnerability within the Equipment Administration Console (AMC) that would permit a distant authenticated attacker as administrator to execute arbitrary instructions beneath particular situations, resulting in distant code execution.
SonicWall stated it has “investigated a case indicating the energetic exploitation of the vulnerabilities,” suggesting that menace actors are chaining collectively each the bugs to execute arbitrary code on vulnerable units.
The issues affect the SMA 1000 fashions 6210, 7210, and 8200v within the following variations –
- 12.4.3-03453 (platform-hotfix) and older variations
- 12.5.0-02835 (platform-hotfix) and older variations
Fixes have been launched in variations 12.4.3-03526 (platform-hotfix) and 12.5.0-02952 (platform-hotfix). SonicWall is recommending that prospects carry out the actions outlined beneath –
- Improve to the most recent hotfix model
- Overview the system for indicators of compromise (IoCs)
- If IoCs are discovered, re-image or re-deploy the home equipment, change all person and administrator passwords, and reset Time-based One-Time Password (TOTP)
SonicWall has not shared any specifics in regards to the nature of the exploitation exercise or who’s behind it. The event comes greater than a month after it shipped fixes to handle two different flaws in the identical product – CVE-2026-15409 (CVSS rating: 10.0) and CVE-2026-15410 (CVSS rating: 7.2) – that have been exploited by a menace actor dubbed UTA0533 to deploy KNUCKLEBALL malware.

