← Back to blog

SonicWall SMA 1000 Devices Targeted in Active Exploitation Campaigns

Attackers are exploiting critical SonicWall SMA 1000 vulnerabilities to deploy reverse shells and crypto miners. CISA and SonicWall confirm active exploitation and urge immediate patching.

TL;DR

  • CISA adds CVE-2026-83548 to its KEV catalog due to active exploitation.
  • SonicWall confirms pre-authentication SSRF flaw in SMA 1000 series used in zero-day attacks.
  • Exploits enable remote unauthenticated access, leading to reverse shell and crypto miner deployments.
  • Organizations should immediately apply SonicWall security updates.
  • Both advisories highlight the same high-severity vulnerability affecting VPN appliances.

Threat actors are actively exploiting a critical server-side request forgery (SSRF) vulnerability in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. The flaw, tracked as CVE-2026-83548, allows remote unauthenticated attackers to gain system access, which has been leveraged to deploy reverse shells and cryptocurrency mining payloads.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling widespread abuse. SonicWall has also issued patches after identifying the issue internally, confirming that the flaw was being exploited in real-world attacks prior to mitigation availability.

Vulnerability Details

  • CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) vulnerability affecting SonicWall SMA 1000 appliances.
  • It carries a maximum CVSS score of 10.0, indicating critical severity.
  • The flaw enables remote unauthenticated attackers to send crafted requests and potentially execute arbitrary code.
  • Successful exploitation can lead to full system compromise including data theft, lateral movement, and persistent backdoors.

Observed Threat Activity

  • Attackers have deployed reverse shells and crypto miners following successful exploitation.
  • CISA reports that threat actors are chaining CVE-2026-83548 into broader intrusion campaigns.
  • No authentication required makes this an attractive target for automated scanning tools.
  • Indicators suggest ongoing scanning and exploitation attempts across exposed devices globally.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

SonicWall SMA 1000 Devices Targeted in Active Exploitation Campaigns — Agent Breach Blog | Agent Breach