Feed›Vulnerability›SonicWall warns of actively exploited SMA1000 zero-day flaws...
VulnerabilityBleeping Computer
10.0 — CRITICAL

SonicWall warns of actively exploited SMA1000 zero-day flaws

📅 2 September 2026 at 06:39 UTC📰 Bleeping ComputerView original source ↗
SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

SonicWall has identified two actively exploited zero-day vulnerabilities in the SMA1000 appliance, chaining a command injection flaw and a server-side request forgery (SSRF) weakness, targeting large enterprises, government, and critical infrastructure organizations.

⚙️Technical Details
CVEs
CVE-2026-83548CVE-2026-83549CVE-2026-15409CVE-2026-15410CVE-2025-40602
Affected Systems
Sonicwall Sma6210Sonicwall Sma7210Sonicwall Sma8200V
Attack Vectors
LOCALNETWORK
💥Impact Assessment
Severity: CRITICAL
🛡️Recommended Actions
1Upgrade to the latest hotfix release as soon as possible
2Re-image appliances
3Change all user and administrator passwords, and reset TOTP tokens if indicators of compromise (IOCs) are detected
📦Affected Products
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200VSonicwall Sma6200Sonicwall Sma6200 FirmwareSonicwall Sma7200Sonicwall Sma7200 Firmware
🔐NVD Verified DataVERIFIED
CVE-2026-83549 ↗CVSS 7.8 — HIGH
Attack Vector
LOCAL
Complexity
LOW
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
CVE-2026-15409 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-918
Affected Products (CPE)
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200V
CVE-2026-15410 ↗CVSS 7.2 — HIGH
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-94
Affected Products (CPE)
Sonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7210Sonicwall Sma7210 FirmwareSonicwall Sma8200V
CVE-2025-40602 ↗CVSS 6.6 — MEDIUM
Attack Vector
NETWORK
Complexity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-862CWE-250
Affected Products (CPE)
Sonicwall Sma6200Sonicwall Sma6200 FirmwareSonicwall Sma6210Sonicwall Sma6210 FirmwareSonicwall Sma7200

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed