Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.
Permission granted by SonicWall
Security researchers warn that hackers are chaining a maximum-severity vulnerability in the SonicWall SMA1000 appliances with a high-severity flaw to achieve remote code execution.
A critical server-side request forgery flaw in the Appliance Work Place interface, tracked asCVE-2026-83548, allows an attacker to access sensitive functions and perform unauthorized actions. The vulnerability has a severity score of 10, the maximum on the scale.
That vulnerability is being chained withCVE-2026-83549, a high-severity OS command-injection vulnerability in the Appliance Management Console. The vulnerability has a severity score of 7.8.
SonicWall on Tuesdayconfirmed the flaws are being exploited in the wildand urged all users to upgrade to the latest hotfix.
TheCybersecurity and Infrastructure Security Agencyon Wednesday added CVE-2026-83548 and CVE-2026-84549 to the Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have until Saturday to mitigate the vulnerabilities.
Rapid7 researchers noted thatSonicWall SMA appliancesare often used in environments where workers and other authorized parties have secure access to internal applications and resources. Appliance Work Place applications are often exposed to the public internet in these environments.
The current exploitation activity comes less than two months after SonicWall SMA1000 appliances were targeted in July.Researchers at Volexitytraced exploitation of CVE-2026-15409 and CVE-2026-15410 to threat activity that began in June.
Volexity researchers tracked that activity to an actor it identified as UTA0533. Researchers have not linked the current activity to a specific threat group.
