# SonicWall SMA1000 Appliances Face New Security Threats

*Published September 4, 2026*
*Source: [https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/](https://cyberscoop.com/sonicwall-sma1000-zero-days-actively-exploited/)*

## Executive Summary

SonicWall SMA1000 appliances have been targeted by attackers exploiting two new zero-day vulnerabilities, leading to potential unauthorized remote code execution. The company has issued patches, but ongoing security challenges persist, highlighting the need for vigilance among customers.

## Article

SonicWall customers are once again facing security challenges with the discovery of two new zero-day vulnerabilities in the SMA 1000 appliances. These vulnerabilities, identified as CVE-2026-83548 and CVE-2026-83549, have been actively exploited, allowing unauthorized remote code execution and posing a significant risk of network compromise. SonicWall has released patches to address these issues, but the company has not specified how many customers have been affected or when the first known instance of exploitation occurred. This follows a history of similar security issues with SonicWall products, which have been frequently targeted by attackers exploiting both new and old vulnerabilities.

The Cybersecurity and Infrastructure Security Agency has added these latest defects to its catalog of known exploited vulnerabilities, highlighting their severity. Rapid7 researchers have indicated that the combination of these vulnerabilities can be particularly dangerous, enabling attackers to achieve complete system compromise without authentication. Although SonicWall claims these vulnerabilities were discovered internally, there is a lack of clarity on when they were identified and the context of their exploitation. The vendor's security advisory advises customers to work with tech support to review potential indicators of compromise and take necessary actions like reimaging appliances and resetting passwords if a breach is detected.

These latest incidents are part of a broader pattern of security issues affecting SonicWall customers, including previous zero-day exploits and an attack by a state-sponsored group that targeted firewall configurations. The ongoing issues have drawn the attention of ransomware groups such as INC and Akira, which have utilized SonicWall vulnerabilities in their campaigns. With five defects added to CISA’s catalog affecting SMA 1000 appliances since December 2025, SonicWall customers must remain vigilant and proactive in addressing these security challenges.
