Security

SonicWall's VPN Boxes Are Under Attack Again, and This Time It's a CVSS 10

Two chained zero-days let an attacker skip the login screen entirely on SonicWall's SMA1000 appliances, and SonicWall says the attacks started before the patch existed.

BiDev TechUpdated September 8, 20262 min read

SonicWall disclosed two zero-day vulnerabilities in its SMA1000 series appliances on September 1, 2026, and said both were already being exploited before a fix existed. Chained together, they let an attacker with no credentials at all reach remote code execution on the box that's supposed to be guarding the network's front door.

What the two bugs actually do

CVE-2026-83548 is a pre-authentication server-side request forgery flaw in the SMA1000 Appliance Work Place interface, and it carries the maximum CVSS score: 10.0. An attacker doesn't need to log in. They just need the appliance reachable, and SSRF lets them reach internal functionality they were never supposed to touch.

CVE-2026-83549 is an OS command injection bug in the Appliance Management Console, rated 7.8. On its own it needs an authenticated administrator session. That's the catch, and the danger: chain it with the SSRF flaw first, and an attacker can reach the management console's command injection path without ever authenticating, landing on full remote code execution on a fully patched-looking appliance.

Confirmed exploitation, not just a theoretical bug

This isn't a "responsible disclosure before anyone notices" story. SonicWall confirmed active exploitation against SMA1000 6210, 7210, and 8200v models before it shipped a fix. CISA added both CVEs to its Known Exploited Vulnerabilities catalog on September 2, one day after disclosure, and set a remediation deadline of September 5 for federal agencies, an unusually tight three-day window that signals how seriously CISA is treating it.

Coverage from multiple security outlets, including SecurityWeek and Help Net Security, frames this as at least the third exploited zero-day chain to hit the SMA1000 line since December. SonicWall's SMA appliances, remote access VPN gateways sitting at the network edge, have become a recurring target precisely because that's what they're for: internet-facing, always-on, and holding the keys to whatever's behind them.

What to do about it

SonicWall's fix ships as platform hotfixes 12.4.3-03526 and 12.5.0-02952, or a newer supported hotfix for your specific model. If you're running SMA1000 hardware and haven't patched since September 1, treat this as urgent, not routine. Given that exploitation predated the patch, a straightforward update isn't necessarily enough on its own. Anyone running these appliances should also be checking logs for signs of prior compromise, not just applying the fix and moving on.

The verdict

A CVSS 10 pre-auth bug on an internet-facing VPN appliance is about as bad as this category of vulnerability gets, and the fact that it's the third such chain on this product line in under a year says the underlying design keeps producing this class of bug. If your organization runs SMA1000 hardware, patch today and assume the worst about anything internet-facing until you've confirmed otherwise.

PrivacyZero-Day
Share this story

The BiDev Tech briefing

The stories that matter in AI, hardware, and big tech — once a week, no noise.