Vulnerabilities

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution.

SonicWall vulnerability

SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild. 

According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally. 

One of the flaws, tracked as CVE-2026-83548 with a CVSS score of 10, has been described as a pre-authentication SSRF issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit it remotely without authentication to access sensitive functionality and conduct unauthorized operations.

The second vulnerability, tracked as CVE-2026-83549 with a CVSS score of 7.8, is an OS command injection issue in the Appliance Management Console (AMC) component.

An authenticated attacker can exploit it to execute arbitrary OS commands, potentially resulting in remote code execution. 

SonicWall noted in its advisory that it has observed exploitation of both vulnerabilities, which suggests they have been chained in attacks. 

Advertisement. Scroll to continue reading.

SMA1000 models 6210, 7210, and 8200v are affected by the zero-days. Hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions patch the vulnerabilities. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected.

No details appear to be available on the attacks exploiting CVE-2026-83548 and CVE-2026-83549, and the vendor’s public advisory does not include indicators of compromise (IoCs).

SonicWall product vulnerabilities are regularly exploited in the wild, including in ransomware attacks. Some security holes are exploited for weeks before they are patched. 

CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 17 SonicWall product flaws; CVE-2026-83548 and CVE-2026-83549 have not yet been added.

Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform

Related: Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities

Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities

Related Content

Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

Artificial Intelligence

Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely.

Vulnerabilities

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure.

Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Vulnerabilities

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Endpoint Security

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

Vulnerabilities

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

Vulnerabilities

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version