Circuit Wire — a daily news update from the Circuit.
SonicWall warned customers on Tuesday, September 2, that attackers are chaining two newly disclosed vulnerabilities in its SMA1000 remote access appliances to run code on the devices, BleepingComputer reported. The company said its product security team confirmed active exploitation and urged customers to install a hotfix as soon as possible.
The first flaw, CVE-2026-83548, is a maximum-severity server-side request forgery issue scored 10 out of 10 in the SMA1000 Work Place interface. A remote attacker can exploit it without logging in to reach sensitive functions. The second, CVE-2026-83549, is an operating-system command injection flaw scored 7.8 in the Appliance Management Console that an authenticated attacker can use to run commands. Chained together, the two allow unauthenticated remote code execution, SecurityWeek reported.
The vulnerabilities affect SMA1000 models 6210, 7210 and 8200v. SonicWall released hotfix versions 12.4.3-03526 and 12.5.0-02952 to address them, and said the SSL-VPN feature on its firewalls and the SMA 100 series are not affected. The advisory is tracked as SNWLID-2026-0016.
The internet-scanning group Shadowserver counts more than 400 SMA1000 appliances exposed online, though some may already be patched. SonicWall has not released indicators of compromise or details about the attacks. It advised administrators to reimage appliances, change all user and administrator passwords and reset access tokens if they find signs of intrusion.
The SMA1000 is a secure remote access gateway used by large enterprises, government agencies and critical-infrastructure operators, which makes it a frequent target. In July, two other SMA1000 flaws were exploited as zero-days to plant custom malware, and the U.S. Cybersecurity and Infrastructure Security Agency later confirmed that ransomware gangs had abused them. The two new flaws had not been added to the agency's Known Exploited Vulnerabilities catalog, which already lists 17 SonicWall bugs.
The warnings extend a difficult run for the vendor. Over the past year SonicWall has disclosed a series of exploited flaws and a breach that exposed customers' firewall configuration backup files, which it linked to state-backed hackers.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

