SonicWall SMA1000 flaws chained for remote code execution

Two SonicWall SMA1000 vulnerabilities added to CISA's exploited catalog are being chained for remote code execution, prompting an urgent patch push.

MedRisk Staff
By
2 Min Read

SonicWall is warning that attackers are chaining two newly patched flaws in SMA1000 appliances to run commands on exposed devices, and US civilian agencies have been ordered to update by Saturday. The appliances provide secure remote access and VPN connections for thousands of organizations, including hospitals and clinics that rely on them for telework and vendor access.

The first bug, CVE-2026-83548, is a pre-authentication server-side request forgery in the Appliance Work Place interface with a maximum CVSS score of 10.0. It allows a remote attacker to reach sensitive functions without credentials. The second, CVE-2026-83549, is an OS command injection flaw rated 7.8 that needs administrator access to the Appliance Management Console. SonicWall’s PSIRT documented a real-world case where both were combined for remote code execution.

CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, triggering a binding operational directive that gives federal civilian agencies until Saturday, September 5 to apply the hotfix. Healthcare organizations are not bound by that federal deadline, but the confirmed exploitation and internet-facing nature of SMA1000 gear makes immediate patching the prudent move.

Hospitals running SMA1000 appliances should update to the latest hotfix, restrict management console access to trusted networks, and review logs for signs of the command injection chain. The appliance’s role as the gateway for remote clinical staff and business partners means a compromise there can expose the rest of the network to lateral movement. SonicWall has published detection guidance, and CISA’s advisory includes indicators of compromise for defenders to hunt.

Share This Article