SonicWall warns of actively exploited SMA1000 zero-day flaws
Reported exploitedSMA1000Our summary
SonicWall has issued an urgent advisory stating that threat actors are actively exploiting a pair of zero-day vulnerabilities in its SMA1000 secure remote access appliances. The attack campaign chains a maximum-severity command injection flaw (CVE-2026-83548), caused by a server-side request forgery weakness, with a second command injection vulnerability (CVE-2026-83549) accessible to administrators with valid credentials. This combination allows attackers to achieve remote code execution on affected devices.
The vulnerabilities impact SMA1000 models 6210, 7210, and 8200v, while SSL-VPN services on other SonicWall firewalls and the SMA 100 Series remain unaffected. SonicWall strongly urges customers to apply the available hotfix release immediately to mitigate these risks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.