← All articles

Attackers chain two SonicWall VPN zero-days for unauthenticated remote code execution

SonicWall warned that attackers are actively exploiting two zero-day flaws in its SMA 1000 series remote-access VPN appliances, which can be chained for unauthenticated remote code execution. The first, CVE-2026-83548, scored 10.0, is a pre-authentication server-side request forgery flaw in the user-facing portal that lets an unauthenticated attacker abuse the appliance as a proxy and reach sensitive functions. The second, CVE-2026-83549, is a command-injection flaw in the admin console. SonicWall confirmed active exploitation and shipped hotfixes with no workarounds. Because these gateways aggregate remote users' credentials and tie into directory services, compromising one means compromising the authentication system itself. It is the third SMA 1000 zero-day campaign in under a year.

Check
Apply the SonicWall SMA 1000 hotfixes immediately since there are no workarounds and exploitation is active, then hunt the appliance for compromise, including rogue sessions, credential theft, and unexpected outbound requests.
Affected
Organizations running SonicWall SMA 1000 models 6210, 7210, or 8200v on affected versions (CVE-2026-83548, CVE-2026-83549); the flaws chain to unauthenticated remote code execution on an appliance that holds credentials and session state.
Fix
Patch to the fixed hotfix releases now, treat any exposed unpatched appliance as compromised, rotate credentials and session secrets it handled, review logs for exploitation, and limit portal exposure to the internet.