SonicWall Patched Two Zero-Days. Then the Replacement Builds Were Exploited Too.
SonicWall has disclosed two more SMA1000 vulnerabilities under active exploitation. CVE-2026-83548 is a pre-authentication server-side request forgery flaw in the Appliance WorkPlace interface with a CVSS score of 10.0. It allows a remote unauthenticated attacker to reach sensitive functionality and perform unauthorised operations through unintended forward-proxy behaviour.
Update, 2 September 2026: the replacement builds were exploited too
CVE-2026-83549 is an operating-system command-injection flaw in the Appliance Management Console. It requires an authenticated administrator, but successful exploitation can execute arbitrary commands. SonicWall says both vulnerabilities have been exploited. Their prerequisites make a chain from the unauthenticated WorkPlace flaw into command execution plausible, although the vendor has not published the attack sequence.
The new advisory affects SMA1000 models 6210, 7210 and 8200v running platform hotfix 12.4.3-03453 or 12.5.0-02835. Those are the same builds this article previously identified as fixes for the July flaws. The new fixed releases are 12.4.3-03526 and 12.5.0-02952. SonicWall has not published indicators in the advisory and tells customers to contact support for compromise review. If indicators are found, the vendor recommends re-imaging or redeploying the appliance, changing every user and administrator password, and resetting TOTP tokens.
This is a separate pair of flaws from CVE-2026-15409 and CVE-2026-15410. It also changes the operational meaning of the July patch line. Customers that stopped at 12.4.3-03453 or 12.5.0-02835 are again exposed and should move to the September releases immediately.
CISA added CVE-2026-83548 and CVE-2026-83549 to its Known Exploited Vulnerabilities catalogue on 2 September. Federal civilian agencies have until 5 September 2026 to complete remediation. CISA lists ransomware use as unknown and has not published campaign details. The catalogue provides dates but no publication time.
Update sources: SonicWall product notice SNWLID-2026-0016 (published and updated 1 September 2026; no publication time provided) and SecurityWeek (published 2 September 2026 at 01:04 ET).
SonicWall found two vulnerabilities under active exploitation in the same remote-access appliance: an unauthenticated server-side request forgery flaw in the user-facing Work Place interface and a command-injection flaw available to an authenticated administrator. The company did not say that attackers chained them, but the response guidance makes the stakes clear. If compromise indicators are present, applying the hotfix is not enough.
SonicWall disclosed CVE-2026-15409 and CVE-2026-15410 on 14 July 2026. Its investigation covered multiple cases indicating that both vulnerabilities were being exploited. CISA added them to the Known Exploited Vulnerabilities catalogue the same day and gave US federal civilian agencies three days to remediate them.
Two flaws cross different boundaries
CVE-2026-15409 is a critical server-side request forgery vulnerability in the SMA1000 Work Place interface. A remote attacker does not need to authenticate before causing the appliance to make requests to unintended locations. SonicWall assigned it a CVSS score of 10.0.
CVE-2026-15410 affects the Appliance Management Console. Under specific conditions, an attacker who is already authenticated as an administrator can inject code and execute arbitrary operating-system commands. Its prerequisites are stronger, reflected in a CVSS score of 7.2, but the capability gained is control of an appliance positioned at the network edge.
Both flaws were exploited, according to the vendor. That does not prove that one campaign chained the unauthenticated SSRF into the administrator-only command injection. CERT-FR highlighted the same evidentiary limit. Defenders should investigate both paths without turning a plausible chain into a confirmed one.
The affected product line is narrowly defined
The advisory covers SonicWall SMA1000 models 6210, 7210 and the virtual 8200v. Affected releases include the listed 12.4.3 platform hotfix builds through 12.4.3-03434 and the listed 12.5.0 builds through 12.5.0-02800. Fixed releases are 12.4.3-03453 or later and 12.5.0-02835 or later.
SonicWall said the issues do not affect SSL VPN services running on its firewalls or the separate SMA 100 Series. There is no workaround for the affected SMA1000 appliances.
Compromise changes the recovery plan
SonicWall published concrete indicators that distinguish this advisory from a routine patch notice. Administrators should review extraweb_access.log for successful requests to /__api__/login or /__api__/logout, and for /wsproxy requests with suspicious host parameters and HTTP 101 responses. They should also inspect ctrl-service.log for hotfix rollbacks using path-traversal-style names.
Routes for /__api__/login or /__api__/logout in /var/lib/unit/conf.json are not part of a legitimate configuration. If any of these indicators appear, SonicWall recommends re-imaging a hardware appliance or redeploying a virtual one, changing every user and administrator password, and resetting time-based one-time-password tokens.
That guidance reveals the real risk. An exploited access appliance can hold more than vulnerable code. It sits on authentication paths, stores sensitive configuration, and participates in the creation of trusted sessions. A patch can close the original entry point, but it cannot revoke credentials, remove an implanted route, or prove that the operating system is still trustworthy.
What defenders should do now
- Inventory SMA1000 6210, 7210 and 8200v appliances, including dormant disaster-recovery systems and externally managed instances.
- Upgrade to 12.4.3-03526, 12.5.0-02952 or a later supported release. The July hotfixes 12.4.3-03453 and 12.5.0-02835 are affected by the September flaws.
- Review the vendor’s indicators across retained logs and configuration files before treating patch completion as incident closure.
- Restrict management access and investigate unexpected administrator sessions, configuration changes and outbound requests from the appliance.
- If indicators are present, rebuild or redeploy the appliance and rotate user passwords, administrator credentials and TOTP tokens.
The useful distinction is simple: exposure requires urgent patching, while evidence of compromise requires recovery. For an internet-facing device that decides who may enter the network, those are not interchangeable tasks.
Sources: SonicWall security advisory SNWLID-2026-0008 (initially published and updated 14 July 2026; no publication time provided), CERT-FR alert CERTFR-2026-ALE-006 (15 July 2026; no publication time provided), NHS England Digital cyber alert CC-4813 (15 July 2026 at 11:04), and CISA Known Exploited Vulnerabilities catalogue.


