SonicWall fixes two critical vulnerabilities that hackers are already using to attack VPNs

September 3, 2026  14:38

SonicWall has urgently released updates for its SMA 1000 series VPN appliances after learning that two vulnerabilities are being exploited in real-world attacks. One of them allows an attacker to gain access to sensitive device functions without prior authorization, and the second — after obtaining administrative access — allows executing arbitrary commands on it.

What makes the situation particularly dangerous is that these two flaws can presumably be used not separately, but as a single attack chain, writes The Hacker News.

The first vulnerability allows starting an attack without authorization

The first issue received the identifier CVE-2026-83548 and a maximum severity score of 10.0 out of 10 on the CVSS scale. This is a server-side request forgery (SSRF) vulnerability. It was discovered in the Appliance Work Place interface.

The core of the problem is that a remote attacker who does not require an account on the target device can, under certain conditions, force the system to perform unauthorized requests. This opens up access to sensitive device functions and allows performing operations that a user without appropriate rights should not perform.

For a VPN gateway, such a flaw is especially dangerous: the device sits at the perimeter of the corporate network and directly processes remote connections from employees and other users.

The second flaw turns access into code execution

The second vulnerability — CVE-2026-83549 — received a score of 7.8. It was discovered in the Appliance Management Console (AMC) and is related to OS command injection. Unlike the first flaw, exploiting it requires an attacker to authenticate and obtain administrator privileges.

Under certain conditions, this allows executing arbitrary commands in the device's operating system. In fact, this means the potential to achieve remote code execution — one of the most dangerous scenarios for network equipment. It is precisely the combination of the two vulnerabilities that causes special concern among experts.

Two flaws can form a single attack chain

SonicWall reported that it investigated an incident indicating active exploitation of both vulnerabilities. The company did not disclose technical details of the attack, so it is not yet possible to say with certainty exactly how attackers are using the flaws.

However, the sequence of vulnerabilities suggests a possible scenario: the first issue is used for initial access and unauthorized actions, after which the second helps expand control over the device and achieve arbitrary command execution. If such a chain is indeed used in practice, this is no longer just about separate vulnerabilities, but about a full-fledged mechanism for compromising the VPN gateway.

Which devices are at risk

The issues affect SMA 1000 models 6210, 7210, and 8200v. Vulnerable versions are: 12.4.3-03453 (platform-hotfix) and earlier; 12.5.0-02835 (platform-hotfix) and earlier. SonicWall has already released fixes: 12.4.3-03526 (platform-hotfix); 12.5.0-02952 (platform-hotfix).

The company recommends that administrators install the relevant updates as soon as possible. SonicWall specifically advises checking devices for indicators of compromise (IoC). This is important because patching the vulnerability does not remove an attacker if they have already managed to penetrate the system.

If signs of a breach are found, SonicWall recommends recreating or redeploying the device, changing passwords for all users and administrators, and resetting TOTP settings — time-based one-time codes used for additional authentication.

Thus, organizations operating potentially vulnerable SMA 1000s need not only to install the fix, but also to check whether the device was used by attackers prior to the update.

Follow NEWS.am Tech on Facebook and Twitter