← All security news

SonicWall SMA1000 Zero-Days Under Active Attack

A remote-access appliance icon with two cracked padlocks labelled CVSS 10.0 and CVSS 7.8, one arrow chaining them together into an open shell prompt, representing attackers chaining two SonicWall SMA1000 zero-day flaws for unauthenticated remote code execution

SonicWall's product security team has confirmed that attackers are actively exploiting two previously unknown flaws in its SMA1000 line of remote-access appliances — the boxes many organisations use to let staff and contractors connect securely into the office network from anywhere. The first, CVE-2026-83548, scores a maximum 10.0 on the CVSS scale: it lets an attacker reach the appliance's Workplace login interface without any credentials at all and misuse it as a proxy into internal systems. The second, CVE-2026-83549, needs an admin-level login but then allows arbitrary commands to be run on the device. Chained together, the two give an outside attacker a path to full remote code execution on an appliance with no valid account.

The affected models are the SMA 6210, 7210 and 8200v, running platform-hotfix builds up to 12.4.3-03453 or 12.5.0-02835. SonicWall has shipped fixed builds (12.4.3-03526 and 12.5.0-02952) and is telling customers who find signs of compromise to go further than a normal patch: re-image the appliance (or redeploy the virtual one from scratch), reset every user and administrator password, and reset TOTP multi-factor tokens too, since a fully compromised appliance can't be trusted to tell you its MFA seeds weren't also taken. Internet-scanning group Shadowserver had already counted several hundred SMA1000 units still reachable from the public internet as the advisory went out.

What this means for your business

If any device on your network handles remote access — a VPN gateway, a secure-access appliance, an SSO gateway — check this week whether it's a SonicWall SMA1000 and, if so, whether it's already on the fixed build. Even if you don't run this specific product, treat it as a prompt to ask your IT provider a broader question: who is responsible for tracking security advisories on our remote-access hardware, and how fast do we normally patch it? These appliances sit at the front door of your network by design, which is exactly why they're a favourite target — a flaw here bypasses everything else you've invested in behind it. If your team ever suspects a remote-access box has been touched by an attacker, don't stop at applying the patch: rotating passwords and resetting MFA tokens matters just as much, because the point of compromising this kind of device is often to walk straight past the multi-factor login it was supposed to enforce.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News, SecurityWeek, Help Net Security