(TLP:CLEAR) Vulnerability Notification – SonicWall SMA 1000 Zero-Day Chain Actively Exploited
Created: Thursday, September 3, 2026 - 14:14
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using SonicWall SMA 1000 series appliances (models 6210, 7210, and 8200v) for remote access. Utilities that outsource technology support may need to consult their service providers for assistance with remediation actions.
Summary: Two zero-day vulnerabilities affecting SonicWall Secure Mobile Access (SMA) 1000 series appliances are being actively exploited in the wild and can be chained together to achieve full, unauthenticated remote code execution. The more severe of the two, CVE-2026-83548 (CVSS 10.0), is a pre-authentication server-side request forgery (SSRF) flaw in the SMA 1000 Appliance Work Place interface, caused by an unintended alternate access path, that a remote, unauthenticated attacker could exploit to gain access to sensitive functionality and perform unauthorized operations. The second, CVE-2026-83549 (CVSS 7.8), is a post-authentication OS command injection flaw in the SMA 1000 Appliance Management Console that could, in specific conditions, allow a remote authenticated administrator to execute arbitrary OS commands. When chained together, the two vulnerabilities enable complete unauthenticated remote code execution against affected appliances, and there is no workaround. CISA added these vulnerabilities to its Known Exploited Vulnerabilities Catalog yesterday.
SMA 1000 appliances are internet-facing gateway devices that provide remote access to internal networks, making them attractive targets for both state-sponsored and ransomware actors seeking an initial foothold. A successful compromise could give attackers access to trusted network environments, potentially enabling lateral movement, credential theft, ransomware deployment, or access to systems supporting OT environments.
Analyst Note: This activity is unfolding during a period of heightened threat to critical infrastructure. Threat intelligence reporting notes that Iranian threat actors have a documented history of weaponizing VPN appliance zero-days, and that access-broker groups operating on that model may leverage this chain for initial access into U.S. critical infrastructure. Given confirmed active exploitation, the absence of a workaround, and the maximum severity of the primary flaw, WaterISAC considers this a high-priority patching item for any utility operating these appliances.
Affected Versions:
- SMA 1000 series (models 6210, 7210, 8200v) running firmware 12.4.3-03453 (platform-hotfix) and older versions
- SMA 1000 series (models 6210, 7210, 8200v) running firmware 12.5.0-02835 (platform-hotfix) and older versions
Note: These vulnerabilities do not affect SSL-VPN running on SonicWall firewalls or the SMA 100 series product line.
WaterISAC strongly encourages members to review SonicWall’s advisory, determine whether SMA 1000 appliances are deployed within their environment, and apply the vendor’s guidance immediately. SonicWall’s recommended actions include:
- Upgrade affected appliances to the latest hotfix version (12.4.3-03526 or 12.5.0-02952 or higher), available via mysonicwall.com.
- Contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IOCs).
- If IOCs are detected, re-image (hardware) or re-deploy (virtual) appliances, change all user and administrator passwords, and reset TOTP tokens.
Original Source: https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Additional Reading:
Related WaterISAC PIRs: 6, 7, 7.1, 8, 10, 12
