Skip to main content

Exploitation of Zero-Day Vulnerabilities in SonicWall SMA1000 Series Appliances

Two zero-day vulnerabilities could be chained together to allow an unauthenticated attacker to perform RCE

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Two zero-day vulnerabilities could be chained together to allow an unauthenticated attacker to perform RCE


Threat details

Exploitation of CVE-2026-83548 and CVE-2026-83549

SonicWall has stated that it has investigated a case indicating the active exploitation of these vulnerabilities. SonicWall strongly urges customers to update to the relevant hotfix release as soon as possible to remediate these vulnerabilities.

Firewalls and other edge devices are internet-facing by design and are highly attractive targets to attackers, and there is an increasing number of edge device vulnerabilities disclosed each year that are rapidly exploited by attackers. Organisations are strongly encouraged to follow NCSC's vulnerability management guidance, including patching edge devices as soon as possible if a critical vulnerability is identified.

The NHS England National CSOC assesses future exploitation of these vulnerabilities as almost certain.


Introduction

SonicWall has released a security advisory to address two zero-day vulnerabilities affecting SMA1000 series appliances. 

  • CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability with a CVSSv3 score of 10.0. A remote unauthenticated attacker could exploit this vulnerability to gain unauthorised access to sensitive functionality and perform unauthorised operations.
  • CVE-2026-83549 is a command injection vulnerability with a CVSSv3 score of 7.8. A remote attacker authenticated as administrator could exploit this to execute arbitrary OS commands, resulting in remote code execution (RCE).

Remediation advice

Affected organisations must review SonicWall's security advisory SNWLID-2026-0016 and apply the relevant updates as soon as possible. 

If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. 


Remediation steps

Type Step
Patch

Required: Organisations must patch to a fixed version:

  • 12.4.3-03526 (platform-hotfix) and higher versions

  • 12.5.0-02952 (platform-hotfix) and higher versions


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016
Guidance

Recommended: Contact SonicWall Technical Support for assistance reviewing the system for indicators of compromise (IoCs).

If IOCs are detected on the system, SonicWall recommends that organisations:

  • Re-image (hardware) or re-deploy (virtual) appliances
  • Change all user & administrator passwords
  • Reset TOTP tokens

If evidence of compromise is detected, organisations must immediately report this to the NHS England National Cyber Security Operations Centre (CSOC) by calling 0300 303 5222 or emailing [email protected]. 


https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0016


Last edited: 2 September 2026 10:41 am