SonicWall zero-day flaws let attackers hijack firewalls

Published September 2, 2026

SonicWall SMA1000 remote-access gateways have two bugs attackers are already exploiting together. One lets an outsider with no login reach hidden internal functions, and the other lets a logged-in attacker run their own commands on the device.

Severity
Not scoredNo CVSS score recorded
Fix
Not confirmed
Affects
SonicWall SMA1000
Exploited
Not confirmedNo confirmation recorded

How it works

  • The first flaw is a hidden, unintended path into the Work Place login interface that lets the appliance be tricked into making unauthorized internal requests without any password.
  • The second lets someone who already has a valid account sneak extra operating-system commands into input the Management Console processes, so the device runs them.

What to do

Check your SMA1000's platform-hotfix version in the management console against 12.4.3-03453 and 12.5.0-02835. If it is or below either build on models 6210, 7210, or 8200v, you are affected.

Upgrade to the latest SonicWall SMA1000 hotfix immediately, then contact SonicWall Technical Support to check for indicators of compromise. If any are found, re-image or re-deploy the appliance, change every user and admin password, and reset TOTP tokens.

Technical details

CVE-2026-83548 is a pre-authentication SSRF in the SMA1000 Work Place interface, caused by an unintended alternate access path, CVSS 10.0. CVE-2026-83549 is a post-authentication OS command injection in the SMA1000 Management Console, CVSS 7.8, letting an authenticated admin-level attacker run arbitrary OS commands under specific conditions. SonicWall disclosed both as actively exploited zero-days on September 1, 2026, affecting platform-hotfix builds 12.4.3-03453 and 12.5.0-02835 and earlier on the 6210, 7210, and 8200v models.