SonicWall SMA1000 hotfix advisory
Advisory/Mitigation
Summary
Hide ▲
Show ▼
SonicWall told SMA1000 customers to install the latest hotfix immediately after confirming active exploitation of two zero-days that can enable remote code execution. The guidance covers SMA1000 6210, 7210, and 8200v appliances and adds re-imaging, password changes, and TOTP resets if compromise indicators appear. The advisory centers on CVE-2026-83548 and CVE-2026-83549, which SonicWall says are being chained in attacks.
Related Happenings
SonicWall SMA1000 command injection flaws (multiple vulnerabilities)
Vulnerability
H score57
First: 02.09.2026 09:39
Last: 02.09.2026 09:39
Sources 1
How related:
The second zero day is CVE-2026-83549: a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console, which has a CVSS score of 7.8.
About this happening:
SonicWall SMA1000 devices are exposed to an actively exploited zero-day chain involving CVE-2026-83548 and CVE-2026-83549, creating remote code execution risk...
SonicWall SMA1000 command injection flaws (multiple vulnerabilities)
VulnerabilityHow related: The second zero day is CVE-2026-83549: a post-authentication remote code execution (RCE) vulnerability in the SMA1000 Appliance Management Console, which has a CVSS score of 7.8.
About this happening: SonicWall SMA1000 devices are exposed to an actively exploited zero-day chain involving CVE-2026-83548 and CVE-2026-83549, creating remote code execution risk...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation Wave
H score24
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
About this happening:
SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
SonicWall SMA1000 zero-day exploitation wave (CVE-2026-15409, CVE-2026-15410)
Exploitation WaveAbout this happening: SonicWall SMA1000 is in an active exploitation wave involving CVE-2026-15409 and CVE-2026-15410, with unauthenticated access to restricted services and root esca...
INC Ransomware campaign expands across multiple victims
Campaign
H score43
First: 03.08.2026 13:39
Last: 03.08.2026 13:39
Sources 1
About this happening:
The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
INC Ransomware campaign expands across multiple victims
CampaignAbout this happening: The INC Ransomware operation has accelerated its SonicWall SMA1000 exploitation and leak-site pressure, expanding impact across multiple victims in several countri...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector Action
H score34
First: 15.07.2026 08:30
Last: 15.07.2026 08:30
Sources 1
About this happening:
CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
CISA KEV catalog addition for SonicWall SMA 1000 flaws
Public Sector ActionAbout this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026,...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
Vulnerability
H score48
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
SonicWall SMA1000 SSRF and code injection flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: SonicWall SMA1000 vulnerabilities CVE-2026-15409 and CVE-2026-15410 were exploited as zero-days against Secure Mobile Access VPN appliances, with SonicWall rel...
Latest development: 03.08.2026 13:39
SonicWall patched CVE-2026-15409 and CVE-2026-15410 on July 14, 2026, and CISA added both flaws to the Known Exploited Vulnerabilities (KEV) catalog the same day after the SMA1000 issues had already been abused in the wild.
Timeline
-
02.09.2026 09:39 1 articles · 2h ago
SonicWall confirms active exploitation of chained SMA1000 zero-days
Initial DisclosureSonicWall said threat actors are chaining CVE-2026-83548, a maximum-severity command injection flaw in the SMA1000 Appliance WorkPlace interface stemming from an SSRF weakness, with CVE-2026-83549 in the SMA1000 Appliance Management Console to achieve remote code execution on SMA1000 6210, 7210, and 8200v devices.
Show sources
- SonicWall warns of actively exploited SMA1000 zero-day flaws — www.bleepingcomputer.com — 02.09.2026 09:39
-
02.09.2026 09:39 3 articles · 2h ago
SonicWall urges SMA1000 customers to install the latest hotfix
Mitigation Patch UpdateSonicWall urged customers to upgrade virtual or physical SMA1000 appliances to the latest hotfix version and advised re-imaging appliances, changing all user and administrator passwords, and resetting TOTP tokens if indicators of compromise are detected.
Show sources
- SonicWall warns of actively exploited SMA1000 zero-day flaws — www.bleepingcomputer.com — 02.09.2026 09:39
- SonicWall warns of actively exploited SMA1000 zero-day flaws — www.bleepingcomputer.com — 02.09.2026 09:39
- Hackers Chain Two New SonicWall Zero-Day Vulnerabilities — www.infosecurity-magazine.com — 02.09.2026 12:00