CVE Tools

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

Dark ReadingBy Alexander Culafi

Reported exploitedSonicWall SMA 1000

Our summary

Attackers are actively exploiting two zero-day vulnerabilities in specific SonicWall SMA 1000 models, allowing for unauthenticated remote code execution when the flaws are chained together. The issues include a critical pre-authentication server-side request forgery vulnerability (CVE-2026-83548, CVSS 10.0) and a post-authentication OS command injection flaw (CVE-2026-83549, CVSS 7.8).

SonicWall advises customers running versions 12.4.3-03453 or 12.5.0-02835 on models 6210, 7210, and 8200v to immediately update to firmware versions 12.4.3-03526 or 12.5.0-02952. Organizations should also monitor for indicators of compromise and consider reimaging or redeploying appliances if breaches are detected.

Read at Dark Reading

Dark Reading publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store