CVE Tools

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

SecurityWeekBy Eduard Kovacs

Reported exploitedSMA1000

Our summary

SonicWall has identified active exploitation of two zero-day vulnerabilities affecting its SMA1000 secure remote access gateways. The critical flaw, CVE-2026-83548, allows unauthenticated attackers to execute unauthorized operations via a server-side request forgery vulnerability in the Appliance Work Place interface. This is often paired with CVE-2026-83549, an authenticated OS command injection issue that can lead to full remote code execution within the management console.

SMA1000 models 6210, 7210, and 8200v are susceptible to these attacks. Administrators should apply hotfixes 12.4.3-03526 or 12.5.0-02952 immediately to mitigate the risk.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store