Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall customers are grappling with yet another pair of actively exploited zero-day vulnerabilities in SonicWall SMA 1000 appliances, a product that’s been besieged with recurring defects and attacks over the past nine months.
The vendor disclosed and released patches for the defects — CVE-2026-83548 and CVE-2026-83549 — and noted both were already actively exploited in the wild in a security advisory Tuesday. The Cybersecurity and Infrastructure Security Agency added the defects to its known exploited vulnerabilities (KEV) catalog Wednesday.
SonicWall customers have confronted a barrage of actively exploited vulnerabilities in SonicWall devices for years. Attackers have consistently exploited newly discovered zero-days and years-old defects in the vendor’s products to break into victim environments.
Rapid7 researchers said the new zero-days — a max-severity pre-authentication server-side request forgery vulnerability and a high-severity OS command injection vulnerability — can be chained together to achieve unauthenticated remote-code execution.
SonicWall did not say how many customers have been directly impacted by active exploitation or when the first known instance of exploitation occurred. The company did not respond to a request for comment.
“Please stop us if you’ve heard this one before: Another appliance sitting at the edge of the network, another pair of vulnerabilities chained together, and another unauthenticated path to complete compromise,” Jake Knott, head of threat intelligence at watchTowr, said in an email.
“SonicWall says these vulnerabilities were internally discovered, while also saying it investigated a case indicating active exploitation. Please pick one, or, at minimum, explain how both are true,” Knott added. “Those statements may be technically accurate, but without that context, the disclosure leaves defenders guessing about when and how the vulnerabilities were actually identified.”
The vendor’s security advisory did not include indicators of compromise. It urged customers to contact tech support for assistance in reviewing IOCs and hunting for potential signs of compromise, and if detected, to reimage or redeploy the appliance, change all user and administrator passwords and reset tokens.
SonicWall did not attribute the known exploits to a specific threat group or describe the attacker’s motivations.
The freshly disclosed pair of vulnerabilities are the latest in a series of security issues confronting the vendor’s customers, including actively exploited zero-days, previously disclosed defects, and an attack last year that allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer.
In late July, Huntress researchers spotted an attack spree that compromised 30 SonicWall customers in less than two days. Earlier that month, the company acknowledged another pair of zero-days that were exploited for three weeks before the vendor disclosed and patched the defects.
Ransomware groups, including INC ransomware and Akira, have taken a special interest in SonicWall. Ten of the 19 SonicWall defects added to CISA’s KEV catalog since late 2021 are known to be used in ransomware campaigns.
The five defects added to CISA’s KEV most recently, since just mid-December 2025, all impact SonicWall SMA 1000 appliances.