SonicWall is urging customers of its SMA1000 series secure remote access gateway and SSL-VPN appliance to patch two new zero-day vulnerabilities that have been exploited in the wild.
According to an advisory published by SonicWall on Tuesday, the vulnerabilities and their exploitation were discovered internally.
One of the flaws, tracked as CVE-2026-83548 with a CVSS score of 10, has been described as a pre-authentication SSRF issue in the Appliance Work Place interface of SMA1000 appliances. An attacker can exploit it remotely without authentication to access sensitive functionality and conduct unauthorized operations.
The second vulnerability, tracked as CVE-2026-83549 with a CVSS score of 7.8, is an OS command injection issue in the Appliance Management Console (AMC) component.
An authenticated attacker can exploit it to execute arbitrary OS commands, potentially resulting in remote code execution.
SonicWall noted in its advisory that it has observed exploitation of both vulnerabilities, which suggests they have been chained in attacks.
SMA1000 models 6210, 7210, and 8200v are affected by the zero-days. Hotfixes 12.4.3-03526, 12.5.0-02952, and higher versions patch the vulnerabilities. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected.
No details appear to be available on the attacks exploiting CVE-2026-83548 and CVE-2026-83549, and the vendor’s public advisory does not include indicators of compromise (IoCs).
SonicWall product vulnerabilities are regularly exploited in the wild, including in ransomware attacks. Some security holes are exploited for weeks before they are patched.
CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 17 SonicWall product flaws; CVE-2026-83548 and CVE-2026-83549 have not yet been added.
Related: SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform
Related: Palo Alto Networks, SonicWall Patch High-Severity Vulnerabilities
Related: SonicWall Urges Immediate Patching of Firewall Vulnerabilities
