CVE Tools

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

The Hacker NewsBy The Hacker News

Reported exploitedSonicWall SMA 1000 Series

Our summary

SonicWall has released patches for two zero-day vulnerabilities affecting its Secure Mobile Access (SMA) 1000 series, confirming active exploitation in the wild where attackers may be chaining the flaws together. The issues include a critical pre-authentication SSRF vulnerability, CVE-2026-83548 (CVSS score: 10.0), and a post-authentication command injection flaw, CVE-2026-83549 (CVSS score: 7.8), both of which can lead to unauthorized access or remote code execution. Users running versions prior to 12.4.3-03526 or 12.5.0-02952 on SMA 6210, 7210, and 8200v models are urged to upgrade immediately and check for indicators of compromise.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store