CVE Tools

SonicWall warns of actively exploited SMA1000 zero-day flaws

BleepingComputerBy Sergiu Gatlan

Reported exploitedSMA1000

Our summary

SonicWall has issued an urgent advisory stating that threat actors are actively exploiting a pair of zero-day vulnerabilities in its SMA1000 secure remote access appliances. The attack campaign chains a maximum-severity command injection flaw (CVE-2026-83548), caused by a server-side request forgery weakness, with a second command injection vulnerability (CVE-2026-83549) accessible to administrators with valid credentials. This combination allows attackers to achieve remote code execution on affected devices.
The vulnerabilities impact SMA1000 models 6210, 7210, and 8200v, while SSL-VPN services on other SonicWall firewalls and the SMA 100 Series remain unaffected. SonicWall strongly urges customers to apply the available hotfix release immediately to mitigate these risks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store