SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Reported exploitedSMA1000Our summary
SonicWall has identified active exploitation of two zero-day vulnerabilities affecting its SMA1000 secure remote access gateways. The critical flaw, CVE-2026-83548, allows unauthenticated attackers to execute unauthorized operations via a server-side request forgery vulnerability in the Appliance Work Place interface. This is often paired with CVE-2026-83549, an authenticated OS command injection issue that can lead to full remote code execution within the management console.
SMA1000 models 6210, 7210, and 8200v are susceptible to these attacks. Administrators should apply hotfixes 12.4.3-03526 or 12.5.0-02952 immediately to mitigate the risk.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.