SonicWall SMA 1000 under attack: critical zero-day enables complete compromise without authentication
SonicWall and authorities urge upgrading to the hotfix release.

Image by Cybernews.
- CISA warns that attackers are actively exploiting two SonicWall SMA1000 vulnerabilities.
- The most severe flaw lets unauthenticated attackers access sensitive gateway functions remotely.
- SonicWall says no workaround exists; affected customers should install the latest hotfix.
- ShadowServer sees at least 420 SMA 1000 devices exposed to the public internet.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Cyber authorities are ringing alarm bells over a “perfect” 10/10 zero-day vulnerability affecting the SonicWall SMA1000. Attackers can compromise enterprise-grade gateways without any authentication.
SonicWall alerted on the 1st of September to 2 critical vulnerabilities affecting SMA1000 Series Appliances – one of them carries a 10 out of 10 severity rating and enables remaining attackers to gain unauthorized access without any authentication.
The US Cybersecurity and Infrastructure Security Agency (CISA) flagged the newly disclosed vulnerabilities as actively exploited and added them to its Known Exploited Vulnerabilities catalog.
CISA told federal agencies to patch the affected models within 72 hours – SonicWall’s advisory leaves no workarounds other than upgrading to the latest hotfix version.
SonicWall’s SMA (Secure Mobile Access) 1000 Series appliances are gateways that let remote employees safely connect to corporate networks. These devices are at the edge of the corporate network and often reachable from the public internet.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The pre-authentication flaw, tracked as CVE-2026-83548, is a server-side request forgery (SSRF) vulnerability, meaning that attackers can specially craft a request or a URL that causes the vulnerable server to make an internal network request to a destination chosen by the attacker. This may include internal systems that aren’t intended to be accessible from the internet.
“A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations,” the vulnerability description reads.
The high-impact cyberattack can be carried out over a network, it is low-complexity, requires no privileges or user interaction, and exploitation can affect resources beyond the vulnerable component itself.
The second bug, CVE-2026-83549, is a post-authentication remote code execution vulnerability in the SMA1000 Appliance Management Console (AMC). Once authenticated access is obtained, a remote attacker can exploit it to execute arbitrary OS commands as an administrator.
Check if your data has been leaked
Both vulnerabilities were zero-days at the time of disclosure – SonicWall itself detected an ongoing active exploitation.
“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate this vulnerability,” the advisory reads.
The affected SMA 1000 models include 6210, 7210, and 8200v.
According to ShadowServer scans, at least 420 devices identified as SMA 1000 are reachable from the public internet.